syncfusion-wpf-charts
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The documentation in references/printing-exporting.md outlines the use of sfChart.Serialize and sfChart.Deserialize methods. These methods perform XML deserialization on local files to save and load chart configurations. While this is a standard feature for UI state management in the Syncfusion library, it involves processing local data structures that could be a vector for malicious content if the file system is compromised.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data sets for visualization, creating a surface for indirect prompt injection.
- Ingestion points: Data collections bound to the ItemsSource property of various chart series, such as LineSeries and ColumnSeries, as described in references/data-binding.md.
- Boundary markers: The instructions do not specify any delimiters or safety warnings for the agent to differentiate between chart data and instructional content.
- Capability inventory: Across all referenced files, the skill demonstrates capabilities for writing to the local file system (using the Save and Serialize methods) and performing print operations (via the Print method), as documented in references/printing-exporting.md.
- Sanitization: There is no evidence of data sanitization, validation, or escaping protocols within the provided implementation examples.
Audit Metadata