celpip-writing-coach
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user content, which introduces a potential surface for indirect prompt injection.
- Ingestion points: The skill reads user-provided writing drafts and searches a "local archive" for prior versions and error clusters to inform its coaching (SKILL.md).
- Boundary markers: The instructions do not specify explicit delimiters (such as XML tags or Markdown code blocks) or specific instructions to ignore embedded commands within the user's writing samples.
- Capability inventory: The skill is limited to text analysis and feedback generation. No dangerous capabilities such as arbitrary command execution, network exfiltration, or modification of system files were identified across any scripts or files.
- Sanitization: There is no evidence of input validation or sanitization to filter potential malicious instructions embedded in the writing drafts before they are processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill references several external resources for educational validation and sample cases.
- The file
OFFICIAL_SAMPLE_CASES.mdcontains links to official IELTS and CELPIP scoring guidelines and sample PDFs from the British Council, IELTS.org, and CELPIP.ca. - These references target well-known educational and testing organizations and are used to provide context for the coaching model.
Audit Metadata