replatform
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill communicates with legitimate Wix domains (wixapis.com, frog.wix.com) and source platform endpoints provided by the user. It manages sensitive information, such as API tokens, using project-local environment files and a dedicated mint-token.sh script designed to acquire credentials without leaking them into logs or transcripts.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes data from external systems, it mitigates potential injection risks through several deterministic layers: Migration logic is executed via generated scripts rather than direct LLM tool calls; a robust 'safe mode' (lib/wix-writers.js) automatically detects and replaces contact information (emails and phone numbers) with mock data to prevent PII exposure or unintended notification triggers; and mandatory 'code safety review' steps ensure that generated code strictly adheres to these privacy and safety protocols.
- [DYNAMIC_EXECUTION]: The skill generates specific migration code (rp-import-codegen) based on source schemas and mapping plans. This generation process uses verified API primitives and templates. The resulting code is subject to an automated agent review and user approval before any site writes are permitted.
- [COMMAND_EXECUTION]: The skill utilizes the official Wix CLI for account authentication and site management. All shell commands are documented and restricted to the necessary setup and execution phases of the migration workflow.
Audit Metadata