syncfusion-vue-common
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes instructions to install official packages from the @syncfusion scope via npm. It also references styles and scripts from well-known content delivery networks (CDNs) for component theming and prototyping.\n- [REMOTE_CODE_EXECUTION]: The documentation describes using
npx syncfusion-license activateto register the software license. This is a standard utility command provided by the vendor to validate and activate the library's license key.\n- [INDIRECT_PROMPT_INJECTION]:\n - Ingestion points: Several components shown in
SKILL.mdand reference files (e.g., Grid, ListView) ingest external data through the:dataSourceproperty.\n - Boundary markers: As the components typically handle structured data (JSON), specific natural language boundary markers are not applied in the examples.\n
- Capability inventory: Analysis of the provided files shows no dangerous capabilities such as arbitrary shell command execution, sensitive file system access, or network exfiltration logic.\n
- Sanitization: The skill's documentation in
references/advanced-features.mdhighlights security best practices and includes features for HTML sanitization to mitigate risks from untrusted content.
Audit Metadata