syncfusion-vue-scheduler
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for ingesting and rendering data from external sources (remote APIs, Google Calendar) which presents a vulnerability surface for indirect prompt injection if the processed data is attacker-controlled.
- Ingestion points: Data enters the agent's context through
dataSourceconfigurations inreferences/data-binding.mdandreferences/resources.md. - Boundary markers: The provided code examples do not specify boundary markers or instructions to ignore embedded commands within the data objects.
- Capability inventory: The skill possesses capabilities to render raw HTML through Vue's
v-htmldirective and direct DOMinnerHTMLmanipulation (e.g., inreferences/customization.mdandreferences/data-binding.md). It also performs network operations to fetch this data. - Sanitization: Code snippets in
references/data-binding.mdshow the use ofinnerHTMLto display server response fields (args.error.statusText), andreferences/customization.mdusesv-htmlfor cell templates. There is no evidence of sanitization or escaping of these external inputs before rendering, which could lead to script execution or agent manipulation if the server response is malicious.
Audit Metadata