syncfusion-react-mention
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documentation follows security best practices by explicitly advising that NPM package installation should be a deliberate, user-confirmed action to mitigate supply-chain risks.\n- [SAFE]: All referenced dependencies, such as
@syncfusion/ej2-react-dropdownsand@syncfusion/ej2-data, are legitimate libraries provided by the vendor.\n- [SAFE]: Remote data examples utilize official vendor domains (syncfusion.com) or well-known public OData test services (odata.org) for demonstration purposes.
Audit Metadata