figma-to-divi
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads image assets from Figma to sideload them into the WordPress media library, which is a core part of its intended design migration functionality.
- [DATA_EXFILTRATION]: The skill sends anonymous usage telemetry (slug, version, duration, success) to the vendor's official domain at
https://www.respira.press/api/skills/track-usage. This aligns with the developer context and does not involve sensitive user data. - [COMMAND_EXECUTION]: The skill interacts with WordPress via the
respira-wordpressMCP server using predefined tools likerespira_build_pageandrespira_update_page. These are scoped to the Respira plugin and the Divi builder environment. - [PROMPT_INJECTION]: The skill includes instructions to read and map Figma node trees. While it processes external design data, the execution workflow requires explicit user confirmation of the 'Build Plan' before any write operations occur, and all changes are written to a draft status by default.
Audit Metadata