syncfusion-vue-scheduler

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for ingesting and rendering data from external sources (remote APIs, Google Calendar) which presents a vulnerability surface for indirect prompt injection if the processed data is attacker-controlled.
  • Ingestion points: Data enters the agent's context through dataSource configurations in references/data-binding.md and references/resources.md.
  • Boundary markers: The provided code examples do not specify boundary markers or instructions to ignore embedded commands within the data objects.
  • Capability inventory: The skill possesses capabilities to render raw HTML through Vue's v-html directive and direct DOM innerHTML manipulation (e.g., in references/customization.md and references/data-binding.md). It also performs network operations to fetch this data.
  • Sanitization: Code snippets in references/data-binding.md show the use of innerHTML to display server response fields (args.error.statusText), and references/customization.md uses v-html for cell templates. There is no evidence of sanitization or escaping of these external inputs before rendering, which could lead to script execution or agent manipulation if the server response is malicious.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:25 AM
Security Audit — agent-trust-hub — syncfusion-vue-scheduler