figma-to-divi

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads image assets from Figma to sideload them into the WordPress media library, which is a core part of its intended design migration functionality.
  • [DATA_EXFILTRATION]: The skill sends anonymous usage telemetry (slug, version, duration, success) to the vendor's official domain at https://www.respira.press/api/skills/track-usage. This aligns with the developer context and does not involve sensitive user data.
  • [COMMAND_EXECUTION]: The skill interacts with WordPress via the respira-wordpress MCP server using predefined tools like respira_build_page and respira_update_page. These are scoped to the Respira plugin and the Divi builder environment.
  • [PROMPT_INJECTION]: The skill includes instructions to read and map Figma node trees. While it processes external design data, the execution workflow requires explicit user confirmation of the 'Build Plan' before any write operations occur, and all changes are written to a draft status by default.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 05:51 PM
Security Audit — agent-trust-hub — figma-to-divi