Deel

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate Deel integration, but it gives an agent broad access to sensitive HR and payroll actions without enough built-in guardrails.

Install only if you trust Membrane and intend to let an agent work with Deel. Use the least-privilege Deel connection available, verify the organization and target records before each task, and require explicit approval before any action that creates, updates, deletes, pays, invoices, or changes worker records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broad enough that an agent may invoke it for loosely related requests involving Deel or HR data without clearly establishing user intent, scope, or authorization. In an HRIS/payroll context, over-broad invocation increases the chance of exposing sensitive employee data or initiating actions in the wrong system.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents data-modifying actions such as creating invoice adjustments, updating departments, and creating milestones without requiring confirmation, authorization checks, or warning about business impact. In a payroll/HRIS environment, these operations can directly affect compensation, records, and workforce management, making accidental or unauthorized changes particularly risky.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal