syncfusion-vue-treemap
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents the dataSource property used for ingesting hierarchical data. While this represents a data processing surface common to visualization components, the skill provides no malicious instructions and lacks dangerous capabilities like shell execution or unauthorized network access.
- Ingestion points: dataSource field in SKILL.md and references/data-binding.md.
- Boundary markers: Not explicitly defined in documentation examples.
- Capability inventory: Limited to UI visualization and client-side event handling.
- Sanitization: Not explicitly discussed for the data source.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install official Syncfusion packages via npm and yarn, which are standard development workflows for this well-known software vendor.
- Evidence: npm install @syncfusion/ej2-vue-treemap in getting-started.md.
Audit Metadata