Back to skill

Security audit

Pipeworx bamboohr

Security checks across malware telemetry and agentic risk

Overview

This BambooHR skill appears legitimate, but it gives an agent access to sensitive employee HR data through a third-party gateway without enough scoping or privacy detail.

Review before installing. Use this only if you are authorized to expose BambooHR employee directory, profile, time-off, and file metadata to an agent through Pipeworx. Confirm the BambooHR tenant, credential scopes, read-only behavior, audit logging, retention policy, and third-party data handling before enabling it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill exposes high-sensitivity HR functions including employee directory data, detailed employee records, time-off information, and employee profile files, but provides no warning, restriction guidance, or privacy handling expectations. In an agent context, this increases the risk of over-collection, inappropriate disclosure, and unsafe use of personal and employment data, especially if invoked without strong authorization and data-minimization controls.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.