interactive-json-form

Warn

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The deployment instructions in SKILL.md provide a series of bash commands designed to be executed via SSH on a remote server. These include directory management (mkdir), file transfers (scp), and utility execution (openssl).
  • [PRIVILEGE_ESCALATION]: The provided deployment recipe uses sudo on the remote host to create directories in restricted static root paths ($DOCROOT) and to modify file ownership (chown) to the web server user. This assumes the executing environment has elevated permissions or the ability to authenticate for sudo access.
  • [DYNAMIC_EXECUTION]: The templates/local-shot.mjs script utilizes Playwright to launch a browser instance and execute JavaScript within the generated page context using page.evaluate. This is used to automate form filling and verify the state of the client-side logic.
  • [INDIRECT_PROMPT_INJECTION]: The templates/index.html file includes a JSON import feature (hydrate function) that parses and ingests external data from a user-provided file. This creates a surface where malicious instructions could be embedded in the survey data, potentially influencing the agent during post-execution reflection or data processing.
  • Ingestion points: The fileInput element in templates/index.html allows users to upload JSON files which are then parsed and used to populate form fields.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the processing logic.
  • Capability inventory: The skill has access to file system operations (Read, Write, Edit) and shell execution (Bash), which could be targeted by a successful injection.
  • Sanitization: The data is parsed via JSON.parse and assigned to input values, but there is no validation or sanitization of the string content to prevent payloads that target the LLM's interpretation of the data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 8, 2026, 08:22 AM
Security Audit — agent-trust-hub — interactive-json-form