qualitative-research

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a legitimate academic framework for PhD-level qualitative research. It guides the agent through methodologies like Grounded Theory and Thematic Analysis without including executable code or dangerous instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external qualitative data, which establishes a potential surface for indirect prompt injection. However, given this is the primary purpose of the skill and it lacks high-risk tools like shell execution or file writing, the risk is minimal.
  • Ingestion points: External data enters the agent's context through the listed tools WebFetch, Read, Grep, and Glob used for qualitative extraction.
  • Boundary markers: The skill does not define specific instruction-data boundary markers (e.g., XML tags or delimiters) to isolate research content from the analysis instructions.
  • Capability inventory: The skill's scope is restricted to search and retrieval tools (WebSearch, WebFetch, Read, Grep, Glob). It does not possess capabilities for network exfiltration, persistence, or privilege escalation.
  • Sanitization: There are no explicit sanitization or filtering instructions for the ingested text, as the focus is on verbatim qualitative analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:29 PM
Security Audit — agent-trust-hub — qualitative-research