syncfusion-vue-charts
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for rendering user-supplied data through the dataSource property. This documentation creates a surface for indirect prompt injection where malicious instructions could be embedded in the data processed for visualization. The API documentation indicates that the component's HTML sanitizer is available but disabled by default.
- Ingestion points: dataSource property in ChartComponent and SeriesDirective (documented in SKILL.md and references/getting-started.md).
- Boundary markers: No specific delimiters or safety warnings for handling untrusted data are provided in the skill instructions.
- Capability inventory: The component supports data visualization and chart export (PNG, PDF, SVG) but does not have direct access to sensitive filesystem or network operations within the agent's core context.
- Sanitization: The enableHtmlSanitizer property exists to mitigate XSS risks but is documented to default to false (references/api-reference.md).
Audit Metadata