alterlab-rma-qualitative-coder

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes untrusted user data while having the ability to write files to the project directory. \n
  • Ingestion points: Reads interview transcripts, research questions, and interview guides from project files (SKILL.md, Workflow step 1). \n
  • Boundary markers: No delimiters or instructions are provided to help the agent distinguish between researcher instructions and potentially malicious content within the transcripts. \n
  • Capability inventory: The agent is instructed to write multiple files, including codebooks and thematic analysis reports, to the project directory. \n
  • Sanitization: There are no instructions to sanitize, validate, or escape the content of the data before it is processed or written. \n- [NO_CODE]: The skill consists entirely of natural language instructions and does not contain any scripts or executable code. \n- [SAFE]: The skill incorporates a mandatory rule for de-identifying raw data before analysis, which is an excellent privacy practice for handling sensitive research information.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 11:45 PM
Security Audit — agent-trust-hub — alterlab-rma-qualitative-coder