syncfusion-vue-linear-gauge
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documentation includes instructions for adding custom HTML content to gauge annotations. This creates a potential attack surface for indirect prompt injection if the agent populates these annotations with unsanitized data from external sources.
- Ingestion points: The
contentattribute within theannotationsarray for axis configuration (found inreferences/annotations-and-customization.md). - Boundary markers: The skill does not provide specific boundary markers or instructions to treat annotation content as untrusted data.
- Capability inventory: The linear gauge component is capable of rendering raw HTML strings in the browser; the agent using the skill might have access to other tools or sensitive file system operations.
- Sanitization: No sanitization or escaping guidelines are mentioned in the documentation for handling dynamic HTML strings.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of official Syncfusion packages and assets.
- Evidence: Instructions to run
npm install @syncfusion/ej2-vue-gaugesinreferences/getting-started.mdand imports from@syncfusion/ej2-cldr-datainreferences/advanced-features.md. - Note: Syncfusion is a well-known service and the resources are vendor-owned.
- [CREDENTIALS_UNSAFE]: The documentation contains a placeholder for a license key registration.
- Evidence: The
registerLicense('YOUR_LICENSE_KEY')call mentioned inreferences/troubleshooting.md. - Note: This is a standard configuration placeholder and does not involve the exfiltration or exposure of actual credentials.
Audit Metadata