Risk of Having Keyboard Recorder Installed During the Running of VM

AppVM: Template implementation — Qubes OS Documentation
Disposable: Disposable implementation — Qubes OS Documentation

You should use disposable for any risky task, example: archive decryption.
Second layer, is to access data within network isolated disposable.

As storage for future access, use network isolated appvm - while “storage” mean, that you never access to data within this appvm. Move data to disposable or network isolated disposable for any data manipulation tasks.
Also, prefer to remove any software that may read data from template you use for storage appvm: libreoffice, browser and etc. Consider to use antivirus, like ClamAV: How to Set Up ClamAV on Qubes for time to time data scans within up-to-date copy of your network isolated appvm storage.