syncfusion-javascript-ai-assistview

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive developer guide for the Syncfusion AI AssistView UI component.\n- [DATA_EXFILTRATION]: Code snippets demonstrate using placeholders or environment variables for API keys and connecting to established service endpoints (e.g., api.openai.com, localhost). No unauthorized data access or exfiltration patterns were detected.\n- [EXTERNAL_DOWNLOADS]: The skill references legitimate npm packages including @syncfusion/ej2-interactive-chat and marked from standard registries. All external service URLs are for well-known and reputable AI platforms.\n- [INDIRECT_PROMPT_INJECTION]: The component provides an interface for displaying AI-generated content, representing a typical surface for indirect prompt injection.\n
  • Ingestion points: Untrusted AI responses are received and processed via the promptRequest event in SKILL.md and references/ai-integrations.md.\n
  • Boundary markers: None are explicitly used in the basic examples provided.\n
  • Capability inventory: The component supports network requests (fetch) and file operations through configured server endpoints (saveUrl).\n
  • Sanitization: The documentation demonstrates using the marked library to parse AI output into HTML for display.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 11:28 AM