migrate-divi-to-gutenberg

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill implements a telemetry mechanism that sends usage statistics (including migration counts, success rates, and site context) to the author's domain at https://www.respira.press/api/skills/track-usage. This is a documented feature for service monitoring and originates from the recognized vendor.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from the WordPress database in the form of Divi shortcode content. While this represents a surface for indirect prompt injection, the skill mitigates this risk by defining strict mapping and parsing rules for the structural conversion of shortcodes into block markup.
  • [COMMAND_EXECUTION]: The skill utilizes WordPress-specific management tools to duplicate and update post content. These operations are restricted to draft versions and require explicit user confirmation, ensuring that the original website content remains unaffected and that the agent does not perform autonomous destructive actions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 05:28 PM
Security Audit — agent-trust-hub — migrate-divi-to-gutenberg