syncfusion-winui-avatar-view

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill guides the user to install the Syncfusion.Core.WinUI NuGet package. Syncfusion is an established and well-known software vendor, and the installation of their official packages via standard registries is a routine development activity.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a UI control that processes untrusted data to display user avatars, creating a surface for potential indirect prompt injection if the inputs are malicious.
  • Ingestion points: The AvatarName property (used for initials generation) and the ImageSource property (used for profile pictures) in SfAvatarView, as documented in SKILL.md and references/content-types.md.
  • Boundary markers: None; the component is a standard UI element and does not utilize natural language prompt delimiters.
  • Capability inventory: The skill demonstrates UI rendering and layout; no dangerous system capabilities, subprocess executions, or network exfiltration operations are present in the provided implementation examples.
  • Sanitization: The skill does not explicitly mention sanitization, relying on the underlying WinUI framework and Syncfusion's control implementation for handling string and URI inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:55 PM
Security Audit — agent-trust-hub — syncfusion-winui-avatar-view