syncfusion-vue-progressbar

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes standard installation instructions for the vendor's package and its dependencies from the official npm registry.
  • Dependencies: @syncfusion/ej2-vue-progressbar, @syncfusion/ej2-base, @syncfusion/ej2-data, @syncfusion/ej2-svg-base, and @syncfusion/ej2-vue-base.
  • These are official resources provided by the skill author, Syncfusion Inc.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes functionality for rendering external or user-provided content within the component's UI, which could serve as a surface for indirect prompt injection if the inputs are untrusted.
  • Ingestion points: The content property of circular progressbar annotations (referenced in references/annotations-and-labels.md) and the text argument in textRender and tooltipRender events (referenced in references/api-reference.md).
  • Boundary markers: The documentation does not specify the use of boundary markers or delimiters when interpolating external data into these UI fields.
  • Capability inventory: The component is restricted to visual progress representation and event handling; it does not perform high-risk operations such as arbitrary code execution or network exfiltration.
  • Sanitization: No explicit mentions of HTML sanitization or input validation are provided in the guides for content rendered within annotations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 02:09 PM
Security Audit — agent-trust-hub — syncfusion-vue-progressbar