Brightpay Uk

Security checks across malware telemetry and agentic risk

Overview

This BrightPay payroll skill is coherent, but it gives broad authenticated access that can change or delete sensitive payroll records without clear confirmation safeguards.

Install only if you trust Membrane and intend to let an agent access BrightPay payroll data. Use read-only or prebuilt actions when possible, require explicit human confirmation before any create, update, delete, payroll-run, or HMRC-related action, and revoke the Membrane/BrightPay connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly documents raw proxy requests with support for POST, PUT, PATCH, and DELETE against a payroll system but does not require confirmation, warn about side effects, or constrain writes to safe workflows. In a payroll context, this can enable unintended or unauthorized modification of employee, payroll, or compliance-related records, which makes the omission materially risky.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal