Back to skill

Security audit

Vmware Aiops

Security checks across malware telemetry and agentic risk

Overview

This is a powerful VMware administration skill with clearly disclosed high-impact capabilities, so it should be installed only with scoped credentials and deliberate operator controls.

Install this only for operators who are allowed to change VMware infrastructure. Prefer enabling VMWARE_READ_ONLY or VMWARE_AIOPS_READ_ONLY for monitoring use, use least-privilege vCenter accounts, declare each target environment, pin the package version for production, and require human review before guest execution, deletion, migration, cluster changes, alarm resets, or enabling the daemon/webhooks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The CLI reference exposes VM create/delete/reconfigure and guest file transfer capabilities that are broader than the declared skill description, creating a scope mismatch between what integrators may expect and what the tool can actually do. In an agent context, undocumented or under-declared mutating capabilities increase the chance of unsafe invocation, over-privileged use, and policy bypass during automated task execution.

Description-Behavior Mismatch

Medium
Confidence
79% confidence
Finding
Documenting scan and daemon control features that are not reflected in the manifest creates hidden operational capability that users or orchestrators may not account for. In a privileged infrastructure-management skill, undeclared background process and scanning controls can expand attack surface and enable unexpected persistent or disruptive behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill is explicitly positioned as the default entry point for a very broad set of VMware tasks, including high-risk lifecycle and guest-execution actions. In an agentic environment, this broad routing can cause the agent to invoke a write-capable skill when a narrower read-only or specialized skill would be safer, increasing the chance of unnecessary destructive actions.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The reference documents destructive actions such as power-off, delete, snapshot revert/delete, clone, migrate, and clean-slate without prominent warnings about impact, reversibility, or confirmation expectations. In an AI-operated VMware environment, omission of such guardrails materially increases the risk of accidental outages, data loss, and unsafe automation against production systems.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
Guest execution and file transfer commands enable code execution inside VMs and access to potentially sensitive files, yet the documentation lacks warnings about credential handling, privacy exposure, and system impact. In this skill's context, these are especially dangerous because they bridge from infrastructure control into in-guest command execution, greatly increasing the potential for lateral movement or data exfiltration if invoked carelessly.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
Cluster deletion and host-removal are high-impact infrastructure operations that can disrupt scheduling, HA/DRS behavior, and service availability, but the reference does not present prominent safety guidance. In a VMware administration skill, missing warnings around these actions makes accidental service disruption more likely, especially when used by autonomous or semi-autonomous agents.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.