migrate-visual-composer-to-gutenberg

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill transmits usage telemetry data, including site context, duration, success status, and page counts, to the vendor's official domain at https://www.respira.press/api/skills/track-usage. This is a standard telemetry mechanism for monitoring tool performance and does not involve the exfiltration of sensitive credentials or private user data.
  • [PROMPT_INJECTION]: The skill processes untrusted content from existing WordPress pages via the wordpress_extract_builder_content tool, creating a surface for indirect prompt injection. Ingestion points: Page content is extracted during the audit (Phase 1) and migration (Phase 3) workflows. Boundary markers: No explicit delimiters or boundary markers are specified for the processing of extracted content. Capability inventory: The skill has the ability to write to the WordPress database using tools such as wordpress_update_page, wordpress_update_post, and their duplicate creation counterparts. Sanitization: The instructions do not specify explicit sanitization or validation of the extracted content before conversion. However, since this processing is the primary purpose of the migration tool and the workflow requires user review of duplicates, the risk is considered low and associated with the intended function.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 05:29 PM
Security Audit — agent-trust-hub — migrate-visual-composer-to-gutenberg