migrate-elementor-to-oxygen

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by ingesting untrusted JSON data from WordPress posts via the wordpress_extract_builder_content tool. While the skill primarily transforms this data, a malicious source page could attempt to influence the agent's behavior during the migration workflow. There are no explicit boundary markers or sanitization steps defined in the instructions for handling the extracted content.\n- [DATA_EXFILTRATION]: The skill includes a telemetry feature that sends anonymized usage data (skill name, site context, and migration counts) to the developer's official domain at https://www.respira.press/api/skills/track-usage. This is documented as a fire-and-forget mechanism for service improvement and does not include sensitive credentials or full page content.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 05:28 PM
Security Audit — agent-trust-hub — migrate-elementor-to-oxygen