hr-works

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references API specifications and connection documentation from official Apideck domains such as specs.apideck.com and developers.apideck.com.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill facilitates access to sensitive human resources data, including employee and payroll records, and transmits it to the Apideck API gateway at unify.apideck.com. These operations are consistent with the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing data from external HR Works records.
  • Ingestion points: Employee profiles, payroll data, and time-off request fields retrieved via the HRIS API.
  • Boundary markers: No specific delimiters are defined in the instructions to separate data from instructions.
  • Capability inventory: The agent can list, read, and sync HR resources through the Apideck SDK and Proxy API.
  • Sanitization: The skill does not explicitly mention sanitization or validation of the retrieved data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 11:02 AM
Security Audit — agent-trust-hub — hr-works