skills/syncfusion/winforms-ui-components-skills/syncfusion-winforms-ai-assistview/Gen Agent Trust Hub
syncfusion-winforms-ai-assistview
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents how to build conversational interfaces that ingest and process untrusted user input, creating a potential surface for indirect prompt injection attacks.
- Ingestion points: User input is captured via the
SfAIAssistView.PromptRequestevent, as shown inreferences/events.mdandreferences/openai-integration.md. - Boundary markers: The examples provided do not demonstrate the use of explicit delimiters or specific 'ignore embedded instructions' warnings when passing user messages to the
IChatCompletionService. - Capability inventory: The skill facilitates network operations to AI service endpoints (OpenAI/Azure) and demonstrates local file writing for chat logging in
references/events.md. - Sanitization: The documentation provides best practice examples for input validation, including checks for empty messages and a
ContainsProhibitedWordshelper method inreferences/events.mdto mitigate basic risks.
Audit Metadata