skills/erphq/skills/payroll/Gen Agent Trust Hub

payroll

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of documentation and procedural instructions for payroll management. It does not include scripts, command-line executions, or requests for sensitive credentials.
  • [PROMPT_INJECTION]: The skill describes processes that involve ingesting untrusted data (timecards, expense reports, and contractor tax forms), which represents a potential surface for indirect prompt injection.
  • Ingestion points: The skill instructions mention reviewing timecards, PTO usage, expense reports, and onboarding documents (W-4, I-9, W-9, W-8BEN).
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the guidelines.
  • Capability inventory: The agent workflows involve flagging financial anomalies, coordinating state tax registrations, managing employee terminations, and interacting with payroll platforms (Gusto, Rippling, Deel).
  • Sanitization: No explicit data validation or sanitization steps are defined for the input sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 04:43 PM
Security Audit — agent-trust-hub — payroll