Back to skill

Security audit

VCF Regulatory Compliance

Security checks for vulnerabilities and agentic risk

Overview

The skill’s main purpose is coherent, but it handles an infrastructure API token unsafely and can return simulated compliance findings when live checks fail.

Review before installing. Use only with a narrowly scoped read-only Aria Operations token, restrict the host to your intended internal endpoint, require real TLS certificate validation or a trusted CA bundle, and remove or gate the simulated-report fallback so failed API calls cannot produce fake compliance results. Pin dependencies before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
server.py:45
Finding

TLS Certificate Verification Disabled for Authenticated API Requests

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
server.py:47
Finding

Failed API Requests Produce Fabricated Compliance Findings

Content
View full analysis
Compliance)*\n\n" f"- **Overall {standard} Compliance Score:** 92%\n" "- **Total Objects Assessed:** 142 (vCenters, ESXi Hosts, VMs, Distributed Switches)\n" "- **Status:** NON-COMPLIANT\n\n" "**Top Violations Detected:**\n" "1. [Critical] `reject-promiscuous-mode-dvportgroup` - Distributed Virtual Port Group 'dvPG-Dev' is allowing promiscuous mode.\n" "2. [Warning] `restrict-port-level-overrides` - Port-level overrides are enabled on 'dvPG-Prod'.\n" "3. [Critical] `Manage Password Expiry` - Root password expiration policy is not enforced on ESXi host 'esx-04.vcf.local'.\n\n" "**Remediation Recommendation:** Disable promiscuous mode on 'dvPG-Dev' and enforce standard password rotation on 'esx-04' to reach 100% compliance." ) ``` ### Technical Analysis Every non-200 HTTP response—including authentication failures, authorization failures, rate limits, malformed requests, and server errors—is converted into a fixed report containing a `92%` score, 142 assessed objects, named infrastructure assets, and purported critical violations. The response contains a simulated-payload note, but it otherwise has the form of a valid regulatory report and supplies specific remediation instructions. An agent or operator can therefore consume invented findings as though they describe the actual environment. The behavior also hides the real HTTP failure ...[truncated 1258 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Third-Party Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tainted flow: 'url' from os.getenv (line 34, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The request URL is built from the ARIA_OPS_HOST environment variable and sent with an API token, while TLS certificate validation is explicitly disabled. If an attacker can influence the host value or intercept traffic, they could redirect the request and capture the bearer token or sensitive compliance query data. In this skill’s context, the tool is explicitly intended to reach an internal VMware Aria Operations endpoint, so outbound requests to an attacker-controlled host are especially risky.

Content

Scanner excerpt · server.py (reported line 41)May include surrounding context.

python
}

    try:
        response = requests.get(url, headers=headers, verify=False)
        
        # Fallback mock data if the API requires a specific UUID or object iteration in the user's environment
        if response.status_code != 200:

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises live compliance checks against the VCF environment, but the fallback emits hard-coded findings unrelated to the actual deployment. This creates integrity risk: operators may make security decisions based on invented violations, or overlook real issues because the tool masks API failures with plausible output.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

On any non-200 response, the tool returns a polished simulated compliance report that appears authoritative instead of clearly failing. This can mislead users into acting on fabricated security findings or falsely believing the environment was assessed, which is dangerous for a compliance-scanning skill where trust in result accuracy is essential.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares and documents use of sensitive environment variables and network access, but does not define any explicit tool scope such as permissions or allowed-tools. That leaves the agent/runtime without a clear least-privilege boundary, increasing the chance the skill can access secrets or make unintended outbound requests beyond what reviewers expect. In this context, the skill connects to VMware Aria Operations using an API token, so unclear scoping is more dangerous because it involves privileged infrastructure and compliance data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code reads a sensitive credential from ARIA_OPS_API_TOKEN and sends it in an HTTPS request header, but there is no user-facing print/log message, confirmation, or warning comment/docstring explaining that credentials and host data will be used for a live API call. The docstring describes the feature purpose, but it does not disclose the credential use or outbound transmission behavior.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

The code disables TLS certificate verification and suppresses the corresponding warnings, allowing man-in-the-middle interception without visibility to the user. Because the request includes a sensitive Aria Operations API token and targets compliance data in an enterprise environment, this weak default materially increases the chance of credential theft and response tampering.

Content

Scanner excerpt · server.py (reported line 41)May include surrounding context.

python
}

    try:
        response = requests.get(url, headers=headers, verify=False)
        
        # Fallback mock data if the API requires a specific UUID or object iteration in the user's environment
        if response.status_code != 200:

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency mcp is unpinned, so installs may resolve to different versions over time, including vulnerable or breaking releases. In an MCP server that interfaces with VMware Aria Operations and performs compliance checks, this increases supply-chain risk because a future install could silently pull a compromised or insecure SDK version into a security-sensitive integration.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
mcp
requests

Unverifiable Dependency: mcp has 12 known advisory(ies) (CVE-2025-53366 (MCP Python SDK vulnerability in the FastMCP Server causes validation error, lead); CVE-2025-66416 (Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection); CVE-2026-52870 (MCP Python SDK: Experimental task handlers allow any client to access and cancel) +9 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

mcp has multiple known advisories, and because no version is pinned, there is no way to verify whether deployment will use a fixed or vulnerable release. This is especially concerning in an MCP server context, where SDK flaws can affect server exposure, client access controls, or request validation in a component that may process sensitive compliance and infrastructure data.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency requests is also unpinned, which makes builds non-reproducible and can introduce vulnerable versions during installation. Because this skill likely makes outbound API calls to VMware Aria Operations, any weakness in the HTTP client library could directly affect authentication, credential handling, or transport security behavior.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
mcp
requests

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
94% confidence
Finding

requests has many historical advisories, and without version pinning the actual installed package may be vulnerable. In a tool that communicates with infrastructure management endpoints, this uncertainty can expose secrets, mishandle redirects or URL parsing, or weaken secure request behavior depending on which version gets installed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.