internal-link-builder

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill sends usage telemetry (site context, operation success, and count of scanned items) to the vendor's API at respira.press. This communication is transparently documented as usage tracking for the vendor's own infrastructure and does not involve the exfiltration of sensitive user data.
  • [PROMPT_INJECTION]: The skill analyzes external content from WordPress pages and posts to build a topical relationship map. This ingestion of untrusted content represents a potential surface for indirect prompt injection. However, the skill provides effective mitigations by mandating explicit user approval before any changes are applied and by using a duplicate-first modification strategy to ensure original content remains untouched during the review process.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 05:28 PM
Security Audit — agent-trust-hub — internal-link-builder