Paychex

Security checks across malware telemetry and agentic risk

Overview

This Paychex skill is transparent about using Membrane, but it can modify sensitive payroll and worker records without clear confirmation safeguards.

Install only if you trust Membrane and intend to give it Paychex access. Use least-privilege Paychex permissions, verify the exact company, worker, pay period, and fields before any change, and require explicit confirmation before create, update, delete, pay-rate, check, or raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises create, update, and delete operations on payroll and worker records without explicit warnings, confirmation requirements, or safe-handling guidance. In an HR/payroll context, accidental execution could alter employee records, checks, or compensation data, causing financial, privacy, and operational harm.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal