paylocity

Warn

Audited by Snyk on Apr 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The Paylocity skill is explicitly a payroll/HCM integration (used to manage paychecks, payroll, and direct deposits) and exposes writable actions via Membrane that can modify payroll-related data. The documented popular actions include Add or Update Earning, Delete Earning, Get Direct Deposits (and implied payroll/paycheck operations). Membrane's "action run" capability combined with these specific actions allows the agent to perform changes that directly affect payroll and payment routing (i.e., money movement). This is a specific financial-execution integration (payroll/banking-related), not a generic tool, so it meets the threshold for direct financial execution authority.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 29, 2026, 01:00 AM
Issues
1