syncfusion-vue-linear-gauge

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documentation includes instructions for adding custom HTML content to gauge annotations. This creates a potential attack surface for indirect prompt injection if the agent populates these annotations with unsanitized data from external sources.
  • Ingestion points: The content attribute within the annotations array for axis configuration (found in references/annotations-and-customization.md).
  • Boundary markers: The skill does not provide specific boundary markers or instructions to treat annotation content as untrusted data.
  • Capability inventory: The linear gauge component is capable of rendering raw HTML strings in the browser; the agent using the skill might have access to other tools or sensitive file system operations.
  • Sanitization: No sanitization or escaping guidelines are mentioned in the documentation for handling dynamic HTML strings.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of official Syncfusion packages and assets.
  • Evidence: Instructions to run npm install @syncfusion/ej2-vue-gauges in references/getting-started.md and imports from @syncfusion/ej2-cldr-data in references/advanced-features.md.
  • Note: Syncfusion is a well-known service and the resources are vendor-owned.
  • [CREDENTIALS_UNSAFE]: The documentation contains a placeholder for a license key registration.
  • Evidence: The registerLicense('YOUR_LICENSE_KEY') call mentioned in references/troubleshooting.md.
  • Note: This is a standard configuration placeholder and does not involve the exfiltration or exposure of actual credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 02:09 PM
Security Audit — agent-trust-hub — syncfusion-vue-linear-gauge