syncfusion-vue-maps

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documentation correctly guides users to use their own API keys for services like Bing Maps and Azure Maps, emphasizing security best practices such as not exposing keys in the frontend and caching them securely.
  • [SAFE]: External data sources, such as the GeoJSON world map, are fetched from the official vendor CDN (syncfusion.com), which is consistent with the skill's stated purpose and the author's identity.
  • [SAFE]: All identified Node.js dependencies are legitimate components of the Syncfusion Essential JS 2 library suite.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests GeoJSON and user-provided data sources for rendering maps.
  • Ingestion points: Data is provided via the shapeData and dataSource properties in LayerDirective (found in references/getting-started.md).
  • Boundary markers: Not explicitly defined as the component handles visualization internally.
  • Capability inventory: The component renders Scalable Vector Graphics (SVG) based on input data; it does not perform arbitrary command execution or network exfiltration from the data content.
  • Sanitization: Standard UI component library behavior which treats data as visual input.
  • [NO_CODE]: The skill provides documentation and implementation examples for a Vue.js UI component rather than executing arbitrary logic itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 02:09 PM
Security Audit — agent-trust-hub — syncfusion-vue-maps