formbuilder-admin

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for administrative interaction with a known university web application (appserv7.admin.uillinois.edu). The functionality and navigation patterns align with the stated purpose of university form and event management.
  • [PROMPT_INJECTION]: The skill includes an attack surface for indirect prompt injection because it ingests data from an external web interface. 1. Ingestion points: Browser-based administrative interface for forms and responses. 2. Boundary markers: Explicit safety guidelines instructing the agent to confirm all destructive actions and work step-by-step. 3. Capability inventory: Creating, editing, and deleting form elements, configuring payments, and triggering emails. 4. Sanitization: Relies on the target platform's internal security and validation. The risk is minimized by the skill's operational safety instructions.
  • [SAFE]: The skill provides JavaScript snippets in 'references/event-sessions.md' and 'references/gotchas.md' intended to assist browser automation tools in setting values for datetime-local input fields. These are legitimate utility scripts for UI interaction and do not represent a remote code execution or privilege escalation risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 06:32 PM
Security Audit — agent-trust-hub — formbuilder-admin