Back to skill

Security audit

VCF Log Insight Health Check

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a disclosed Log Insight health check using a configured host and API token, with no evidence of hidden persistence, destructive behavior, or unrelated data access.

Install only if you want Codex to query your Log Insight service. Set LOGINSIGHT_HOST to a trusted internal endpoint, use a least-privilege or read-only API token where possible, and be aware that TLS certificate verification is disabled by the provided curl commands.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.