Greythr

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real GreytHR integration, but it gives an agent broad authenticated access to sensitive HR and payroll data without enough guardrails.

Install only if you trust Membrane and intend to let an agent access GreytHR. Use a least-privileged GreytHR account, prefer prebuilt Membrane actions, require explicit approval before any create/update/delete request, avoid exposing unnecessary employee or payroll fields, and revoke the connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly documents arbitrary proxy requests to the GreytHR API, including support for mutating HTTP methods and raw request bodies, but does not require confirmation, scope restrictions, or safety checks. In an HR/payroll context, this can expose or modify sensitive employee, attendance, leave, and payroll data, making unintended destructive or privacy-impacting actions more likely.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal