syncfusion-vue-chat-ui
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official Syncfusion packages and styles from the NPM registry and well-known content delivery networks (CDNs). These are vendor-owned or well-known service resources and are considered safe.
- [INDIRECT_PROMPT_INJECTION]: The skill implements a chat interface that processes user input. The documentation includes explicit security best practices, such as using DOMPurify to sanitize content when rendering Markdown, which mitigates injection risks. Findings include: (1) Ingestion points: The ejs-chatui component and addMessage method in references/events-methods.md. (2) Boundary markers: Not explicitly enforced by the component, leaving delimitation to the implementer. (3) Capability inventory: UI rendering and bot service integration capabilities are present. (4) Sanitization: The use of DOMPurify is recommended and demonstrated in references/messages.md.
- [SAFE]: The skill includes guidance for secure credential management in bot integrations, recommending the use of environment variables and secure token servers instead of hardcoding secrets.
Audit Metadata