syncfusion-winui-scheduler

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The SfScheduler control processes and renders appointment data from external sources, presenting a standard attack surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the application through the ItemsSource property and the QueryAppointments event as described in references/appointments.md and references/load-on-demand.md.
  • Boundary markers: There are no explicit boundary markers or instructions to the agent to disregard embedded content within appointment fields shown in the code examples.
  • Capability inventory: The skill provides UI rendering, date navigation, and appointment editing capabilities within the WinUI framework.
  • Sanitization: The documentation does not demonstrate methods for sanitizing or validating user-provided strings like 'Subject' or 'Notes' before they are processed by the control.
  • [EXTERNAL_DOWNLOADS]: The skill guides users to install the Syncfusion.Scheduler.WinUI NuGet package, which is an official library from a known vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:01 AM
Security Audit — agent-trust-hub — syncfusion-winui-scheduler