paychex
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose and capabilities are broadly aligned, and the CLI install path appears legitimate. The main risk is architectural: sensitive Paychex HR/payroll data and auth are mediated through Membrane, and the proxy/action model enables impactful record changes. This looks coherent for an integration skill, but it carries medium security risk due to third-party credential/data handling and high-impact operations.
Confidence: 84%Severity: 54%
Audit Metadata