formbuilder-admin

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and manage data from an external web application (University of Illinois FormBuilder), creating a surface for indirect prompt injection via form content or responses.
  • Ingestion points: Web application interface at appserv7.admin.uillinois.edu.
  • Boundary markers: Instructions emphasize human confirmation for destructive actions, but do not provide specific data delimiters for the agent context.
  • Capability inventory: Browser automation capabilities, including navigation, element interaction, and JavaScript execution.
  • Sanitization: No explicit sanitization or filtering is described in the prompt-based instructions.
  • [DYNAMIC_EXECUTION]: The skill includes JavaScript code blocks intended to be executed in the browser context via the agent's automation tools. These snippets are provided as a workaround to manipulate date-time input fields that often fail to receive input through standard typing commands in automation environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:09 PM