syncfusion-wpf-ribbon
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides standard documentation for a commercial UI library and follows established patterns for desktop application development without introducing malicious code or behaviors.
- [EXTERNAL_DOWNLOADS]: The skill instructions in
references/getting-started.mdguide users to download and install the officialSyncfusion.Tools.WPFNuGet package. This is a legitimate dependency for the described functionality and originates from the documented vendor. - [PERSISTENCE]: The skill demonstrates how to use the
SaveRibbonStateandLoadRibbonStatemethods to persist UI configurations in .NET isolated storage, as seen inreferences/ribbon-advanced.md. This is a standard feature for user interface state management and is not a security threat. - [INDIRECT_PROMPT_INJECTION]: The skill describes UI components that ingest untrusted user input, which constitutes a potential injection surface.
- Ingestion points: Data enters via input controls like
RibbonTextBoxandRibbonComboBoxdescribed inreferences/ribbon-inputs.md. - Boundary markers: Not present in the provided UI snippets, as is standard for component library documentation.
- Capability inventory: The skill defines UI layouts and simple interaction logic; it does not implement risky capabilities such as file system writing or remote network access beyond standard package management.
- Sanitization: Input sanitization is not addressed in the examples, remaining the responsibility of the application developer.
Audit Metadata