syncfusion-wpf-spreadsheet-editor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates code snippets that utilize System.Diagnostics.Process.Start to launch local files (e.g., Sample.pdf, Sample.png) created during export processes. This is a standard developer practice for demonstrating output but involves executing commands on the host machine.
  • [DATA_EXPOSURE]: The skill includes code for accessing the local file system to open workbooks (e.g., spreadsheet.Open(@"C:\Data\Sample.xlsx")) and insert images from local paths. These operations are scoped to the intended functionality of a spreadsheet editor.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external Excel files and DataTables. While the agent is instructed to use only hardcoded reference snippets, the ingestion of external data without explicit boundary markers or sanitization represents a potential attack surface for indirect prompt injection.
  • Ingestion points: SfSpreadsheet.Open and ImportDataTable in references/getting-started.md.
  • Boundary markers: None identified in the reference snippets.
  • Capability inventory: File writing via SfSpreadsheet.SaveAs and process initiation via Process.Start.
  • Sanitization: No explicit sanitization or validation of cell content is present in the provided snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:02 AM
Security Audit — agent-trust-hub — syncfusion-wpf-spreadsheet-editor