alterlab-rma-statistics-guide
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it is designed to ingest and act upon untrusted external data without sufficient isolation.
- Ingestion points: The agent is instructed to read "project data descriptions", "research questions", "hypotheses", "variable descriptions", and "data collection instruments" from the project environment (SKILL.md).
- Boundary markers: The instructions do not define delimiters or "ignore instructions" tags to separate the ingested research content from the agent's core operating directives.
- Capability inventory: The skill has the authority to perform web searches (network access), read files, and write multiple markdown deliverables to the local filesystem.
- Sanitization: There are no requirements for the agent to validate or filter the content of ingested files before processing them or using them to generate new files.
Audit Metadata