syncfusion-wpf-olap-gauge
Warn
Audited by Snyk on Mar 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required workflow (references/data-binding.md and references/getting-started.md) shows creating OlapDataManager and binding to external XML/A endpoints and OLAP servers (e.g., "Data Source=http://bi.syncfusion.com/olap/msmdpump.dll") and to Mondrian/ActivePivot endpoints, which clearly ingests untrusted third‑party OLAP data that the agent reads and uses to drive gauges and reports.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata