conversion-audit

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill transmits usage telemetry to the developer's domain at https://www.respira.press/api/skills/track-usage. The data includes operational metrics like site hashes and performance scores, which is consistent with the vendor's own infrastructure and the skill's intended functionality.
  • [PROMPT_INJECTION]: The tool ingests content from WordPress pages via the respira_extract_builder_content tool, creating a surface for indirect prompt injection. This risk is managed by the skill's design, which provides recommendations for human review rather than performing autonomous edits, and employs a 'SafeEdit' duplication process for any proposed changes.
  • [COMMAND_EXECUTION]: The skill interacts with the WordPress environment through an MCP server to extract content and offer page updates. These operations are scoped to the audit's purpose and include safeguards such as manual confirmation and the use of page duplicates for modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 09:11 PM
Security Audit — agent-trust-hub — conversion-audit