syncfusion-vue-markdown-converter
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates rendering Markdown content as HTML, which creates an XSS (Cross-Site Scripting) vulnerability surface if the Markdown source is untrusted or contains malicious scripts.
- Ingestion points: The skill ingests user-provided text through
textarea.valueacross several Vue component examples inSKILL.md,references/tohtml-api.md,references/getting-started.md, andreferences/richtexteditor-integration.md. - Boundary markers: No explicit boundary markers or directives are provided to the agent or in the code snippets to delimit the untrusted Markdown content.
- Capability inventory: The skill examples use the
innerHTMLproperty and Vue'sv-htmldirective to render the converted output directly into the DOM, which allows for script execution in the browser environment. - Sanitization: While a text-only "Security note" in
references/tohtml-api.mdmentions the need for sanitization, all provided code implementations omit sanitization logic, leading to an unsafe default implementation for developers. - [EXTERNAL_DOWNLOADS]: The skill instructs the user to install multiple
@syncfusion/*packages from the NPM registry. These packages are official libraries belonging to the vendor (Syncfusion).
Audit Metadata