alterlab-rma-statistics-guide

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it is designed to ingest and act upon untrusted external data without sufficient isolation.
  • Ingestion points: The agent is instructed to read "project data descriptions", "research questions", "hypotheses", "variable descriptions", and "data collection instruments" from the project environment (SKILL.md).
  • Boundary markers: The instructions do not define delimiters or "ignore instructions" tags to separate the ingested research content from the agent's core operating directives.
  • Capability inventory: The skill has the authority to perform web searches (network access), read files, and write multiple markdown deliverables to the local filesystem.
  • Sanitization: There are no requirements for the agent to validate or filter the content of ingested files before processing them or using them to generate new files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 11:44 PM
Security Audit — agent-trust-hub — alterlab-rma-statistics-guide