formbuilder-admin
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and manage data from an external web application (University of Illinois FormBuilder), creating a surface for indirect prompt injection via form content or responses.
- Ingestion points: Web application interface at appserv7.admin.uillinois.edu.
- Boundary markers: Instructions emphasize human confirmation for destructive actions, but do not provide specific data delimiters for the agent context.
- Capability inventory: Browser automation capabilities, including navigation, element interaction, and JavaScript execution.
- Sanitization: No explicit sanitization or filtering is described in the prompt-based instructions.
- [DYNAMIC_EXECUTION]: The skill includes JavaScript code blocks intended to be executed in the browser context via the agent's automation tools. These snippets are provided as a workaround to manipulate date-time input fields that often fail to receive input through standard typing commands in automation environments.
Audit Metadata