syncfusion-winui-avatar-view
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides the user to install the
Syncfusion.Core.WinUINuGet package. Syncfusion is an established and well-known software vendor, and the installation of their official packages via standard registries is a routine development activity. - [INDIRECT_PROMPT_INJECTION]: The skill describes a UI control that processes untrusted data to display user avatars, creating a surface for potential indirect prompt injection if the inputs are malicious.
- Ingestion points: The
AvatarNameproperty (used for initials generation) and theImageSourceproperty (used for profile pictures) inSfAvatarView, as documented inSKILL.mdandreferences/content-types.md. - Boundary markers: None; the component is a standard UI element and does not utilize natural language prompt delimiters.
- Capability inventory: The skill demonstrates UI rendering and layout; no dangerous system capabilities, subprocess executions, or network exfiltration operations are present in the provided implementation examples.
- Sanitization: The skill does not explicitly mention sanitization, relying on the underlying WinUI framework and Syncfusion's control implementation for handling string and URI inputs.
Audit Metadata