Back to skill

Security audit

vmware-aria

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed VMware Aria Operations integration with expected credentials and operational write tools, but users should install it only with least-privilege accounts and understand the maintenance/report/alert actions it can take.

Before installing, use a least-privilege Aria Operations account, preferably read-only unless you need alert/report/maintenance writes. Avoid storing production passwords in ~/.vmware-aria/.env when a secret manager or session-only environment injection is available. Treat CLI --yes and maintenance end carefully, especially if the resource state is unknown, and review the vmware-aria and vmware-policy package source before production deployment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (33)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
metadata: {"openclaw":{"requires":{"anyBins":["vmware-aria","uvx"]},"optional":{"env":["VMWARE_ARIA_CONFIG","VMWARE_ARIA_<TARGET>_PASSWORD","VMWARE_ARIA_<TARGET>_USERNAME","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy"]},"homepage":"https://github.com/vmware-skills/VMware-Aria","emoji":"📊","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  Credentials: Each Aria Operations target requires a per-target password env var in ~/.vmware-aria/.env following the pattern VMWARE_ARIA_<TARGET_NAME_UPPER>_PASSWORD. Passwords are never logged or echoed.
  Read-heavy: 34 of 44 tools are read-only. Write operations limited to alert acknowledge/cancel, alert notes, alert definition management, report management, and resource maintenance start/end.
  No webhooks, no outbound network calls, no guest operations. Local only: stdio MCP + Aria Operations REST API (HTTPS 443).
  Transitive dependencies: Only vmware-policy (audit/policy). No post-install scripts or background services.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
metadata: {"openclaw":{"requires":{"anyBins":["vmware-aria","uvx"]},"optional":{"env":["VMWARE_ARIA_CONFIG","VMWARE_ARIA_<TARGET>_PASSWORD","VMWARE_ARIA_<TARGET>_USERNAME","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy"]},"homepage":"https://github.com/vmware-skills/VMware-Aria","emoji":"📊","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  Credentials: Each Aria Operations target requires a per-target password env var in ~/.vmware-aria/.env following the pattern VMWARE_ARIA_<TARGET_NAME_UPPER>_PASSWORD. Passwords are never logged or echoed.
  Read-heavy: 34 of 44 tools are read-only. Write operations limited to alert acknowledge/cancel, alert notes, alert definition management, report management, and resource maintenance start/end.
  No webhooks, no outbound network calls, no guest operations. Local only: stdio MCP + Aria Operations REST API (HTTPS 443).
  Transitive dependencies: Only vmware-policy (audit/policy). No post-install scripts or background services.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

md
size. Full rules, per-tool `total` sources and `list_anomalies`' scan fields: [`references/capabilities.md`](references/capabilities.md#list-result-envelope).

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/capabilities.md (reported line 109)May include surrounding context.

md
| `GET /suite-api/api/resources/{id}/stats/latest` | get_capacity_overview, get_remaining_capacity, get_time_remaining (OnlineCapacityAnalytics keys) |
| `POST /suite-api/api/resources/stats/query` | list_rightsizing_recommendations (OnlineCapacityAnalytics recommendedSize keys), list_anomalies (`System Attributes\|total_alarms`) — one request for a resourceId array; get_aria_node_resources (window min / avg / max); get_resource_health (latest `SERVICE\|AVAILABILITY`, service-kind objects only) |
| `PUT /suite-api/api/resources/{id}/maintained` | start_resource_maintenance (window as the `duration` or `end` query parameter; neither = manual maintenance) |
| `DELETE /suite-api/api/resources/{id}/maintained` | end_resource_maintenance |
| `GET /suite-api/api/maintenanceschedules` | list_maintenance_schedules (paged; `resourceId` filter) |
| `POST /suite-api/api/alerts/query` | list_alerts (server-side status/criticality/resource filtering) |
| `GET /suite-api/api/alerts/{id}` | get_alert, investigate_alert (alert-side leg; no dedicated endpoint — the tool composes the two existing reads), get_alert_recommendations (the alert's definition id and criticality), acknowledge_alert / cancel_alert (blast radius) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/capabilities.md (reported line 124)May include surrounding context.

md
| `GET /suite-api/api/alertdefinitions` | list_alert_definitions |
| `POST /suite-api/api/alertdefinitions` | create_alert_definition |
| `PUT /suite-api/api/alertdefinitions/{id}/enable` (or `/disable`) | set_alert_definition_state |
| `DELETE /suite-api/api/alertdefinitions/{id}` | delete_alert_definition |
| `GET /suite-api/api/symptomdefinitions` | list_symptom_definitions (filter param is `resourceKind`); get_alert / investigate_alert symptom names and severities (`id` repeated, 50 per request) |
| `GET /suite-api/api/reportdefinitions` | list_report_definitions (`subject` is an array of resource-kind strings) |
| `POST /suite-api/api/reports` | generate_report (requires at least one resource UUID) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/capabilities.md (reported line 129)May include surrounding context.

md
| `GET /suite-api/api/reportdefinitions` | list_report_definitions (`subject` is an array of resource-kind strings) |
| `POST /suite-api/api/reports` | generate_report (requires at least one resource UUID) |
| `GET /suite-api/api/reports` / `GET /suite-api/api/reports/{id}` | list_reports / get_report (timestamp field is `completionTime`; definition filter and limit applied client-side); delete_report (blast radius) |
| `DELETE /suite-api/api/reports/{id}` | delete_report |
| `GET /suite-api/api/deployment/node/status` | get_aria_health (a 503 is read as a status, not an error), is_alive, list_adapters (the appliance clock, `systemTime`, for collection ages) |
| `GET /suite-api/api/adapters` | list_adapters (unpaged) |
| `GET /suite-api/api/deployment/node/services/info` | get_aria_health, doctor (per-service health) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 254)May include surrounding context.

vmware-aria doctor [OPTIONS]

Options: --skip-auth Skip authentication check (only tests config + network) --config -c Path to config file

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cli-reference.md (reported line 21)May include surrounding context.

vmware-aria doctor [OPTIONS]

Options: --skip-auth Skip authentication check (only tests config + network) --config -c Path to config file

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cli-reference.md (reported line 31)May include surrounding context.

vmware-aria doctor [OPTIONS]

Options: --skip-auth Skip authentication check (only tests config + network) --config -c Path to config file

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
81% confidence
Finding

Allowing maintenance end to proceed when the prior state is unknown weakens a safety check around a state-changing operation. In an agentic context, this can cause unintended removal of maintenance mode from the wrong or unverified resource, resuming alerting and collection unexpectedly and potentially disrupting maintenance workflows or generating noisy operational side effects.

Content

Scanner excerpt · references/cli-reference.md (reported line 676)May include surrounding context.

--config -c PATH Config file path

text

Refused (exit 2) only when the resource is known not to be in maintenance — an adapter reports a state such as `STARTED` or `STOPPED`, so there is nothing to end. When the state is unknown (it cannot be read, or an adapter reports `UNKNOWN` / `NONE`) the call proceeds and `before` says unknown. `--dry-run` prints `DELETE /suite-api/api/resources/<resource-id>/maintained`.

**Output**: JSON with `before`, `after`, `confirmed` (true once the resource no longer reports maintenance, false when it still does, null when unknown) and `note`.

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The guide recommends storing the Aria password in a plaintext .env file under the user's home directory. Even with chmod 600, local plaintext secret storage increases credential exposure risk through backups, endpoint compromise, accidental file disclosure, or shell/editor artifacts; the later base64 rewrite is explicitly only obfuscation, not protection.

Content

Scanner excerpt · references/setup-guide.md (reported line 66)May include surrounding context.

3. Set password

Option A — .env file (recommended):

bash
cat > ~/.vmware-aria/.env << 'EOF'
VMWARE_ARIA_PROD_PASSWORD=your_password_here

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

This specific example writes a live password directly into ~/.vmware-aria/.env, normalizing a pattern of storing reusable infrastructure credentials on disk. In this skill's context, those credentials can access production monitoring and possibly acknowledge/cancel alerts, so compromise could enable unauthorized visibility or operational tampering.

Content

Scanner excerpt · references/setup-guide.md (reported line 68)May include surrounding context.

Option A — .env file (recommended):

bash
cat > ~/.vmware-aria/.env << 'EOF'
VMWARE_ARIA_PROD_PASSWORD=your_password_here
EOF
chmod 600 ~/.vmware-aria/.env

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Although chmod 600 is good practice, the surrounding pattern still relies on a local .env credential file, so the broader issue remains credential-at-rest exposure. Permission restriction mitigates casual multi-user access but does not protect against malware, compromised user accounts, backups, or accidental inclusion in archives.

Content

Scanner excerpt · references/setup-guide.md (reported line 71)May include surrounding context.

cat > ~/.vmware-aria/.env << 'EOF' VMWARE_ARIA_PROD_PASSWORD=your_password_here EOF chmod 600 ~/.vmware-aria/.env

text

**Option B — shell environment**:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["vmware-aria","uvx"]},"optional":{"env":["VMWARE_ARIA_CONFIG","VMWARE_ARIA_<TARGET>_PASSWORD","VMWARE_ARIA_<TARGET>_USERNAME","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy"]},"homepage":"https://github.com/vmware-skills/VMware-Aria","emoji":"📊","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  Credentials: Each Aria Operations target requires a per-target password env var in ~/.vmware-aria/.env following the pattern VMWARE_ARIA_<TARGET_NAME_UPPER>_PASSWORD. Passwords are never logged or echoed.
  Read-heavy: 34 of 44 tools are read-only. Write operations limited to alert acknowledge/cancel, alert notes, alert definition management, report management, and resource maintenance start/end.
  No webhooks, no outbound network calls, no guest operations. Local only: stdio MCP + Aria Operations REST API (HTTPS 443).

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest frames the skill as handling Aria Operations data such as metrics, alerts, capacity, anomalies, reports, maintenance mode, and adapter/node health. However, the body documentation adds materially broader capabilities for VCF 9.1: fleet certificates, managed password-account status, VCF domains, diagnostic findings, and real-time PromQL queries, which go beyond the manifest's stated scope of Aria monitoring/operations data.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

bash
uv tool install vmware-aria==1.17.0
vmware-aria init      # guided setup: writes config + .env (chmod 600, password grep-safe), then verifies
vmware-aria doctor

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup-guide.md (reported line 71)May include surrounding context.

bash
uv tool install vmware-aria==1.17.0
vmware-aria init      # guided setup: writes config + .env (chmod 600, password grep-safe), then verifies
vmware-aria doctor

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

md
| | `findings_list` | Read | Operations diagnostic findings (not compliance — see vmware-harden) |
| | `promql_query` | Read | Real-time PromQL instant query via the VODAP service (base path INFERRED, unverified on real hardware) |

**Read/write split**: 34 read-only, 10 write. All write operations are audit-logged to `~/.vmware/audit.db` (via vmware-policy).

### List results are envelopes — read `truncated` before you summarise

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 312)May include surrounding context.

md
3. **No webhooks**: no outbound calls besides the Aria Operations REST API over HTTPS 443; the MCP server is local stdio.
4. **TLS**: verification on by default; for a private CA set `SSL_CERT_FILE` rather than `verify_ssl: false` (isolated labs only).
5. **Prompt-injection defense**: API text is sanitized (control characters stripped, length capped) before it reaches the agent.
6. **Least privilege**: use an Aria Operations account with read-only roles unless the write tools (alert acknowledge/cancel, alert notes, alert definitions, reports, resource maintenance) are needed.

Every tool call goes through vmware-policy (`@vmware_tool`): audited to `~/.vmware/audit.db`, subject to `~/.vmware/rules.yaml` deny rules and maintenance windows, each tool risk-tagged. View with `vmware-audit log --last 20` or `--status denied`. The suite-api token is re-acquired automatically before it expires. Setup, multiple targets, MCP clients and Docker: [`references/setup-guide.md`](references/setup-guide.md).

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/capabilities.md (reported line 16)May include surrounding context.

md
| **L5** | Auto-remediation from learned pattern | Pattern library only; requires `risk:low` + `reversible:true` + `repeatable:true` | *(roadmap — candidates: auto-acknowledge known-noisy alerts, auto-cancel resolved-by-event alerts)* |

**Notes**:
- L1/L2 tools are always safe for agents to call without confirmation.
- L3 alert-state writes pass through the `@vmware_tool` decorator: connection check → policy check → audit log. Cancel is irreversible by Aria API design and treated as a destructive operation.
- For VM/host operations see [vmware-aiops](https://github.com/vmware-skills/VMware-AIops); Aria recommendations are advisory, not actuating.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 254)May include surrounding context.

vmware-aria doctor [OPTIONS]

Options: --skip-auth Skip authentication check (only tests config + network) --config -c Path to config file

text

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/cli-reference.md (reported line 21)May include surrounding context.

vmware-aria doctor [OPTIONS]

Options: --skip-auth Skip authentication check (only tests config + network) --config -c Path to config file

text

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/cli-reference.md (reported line 31)May include surrounding context.

vmware-aria doctor [OPTIONS]

Options: --skip-auth Skip authentication check (only tests config + network) --config -c Path to config file

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/cli-reference.md (reported line 297)May include surrounding context.

vmware-aria alert acknowledge [OPTIONS]

Options: --yes -y Skip confirmation prompt --target -t TEXT Target name

text

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes this skill as handling Aria Operations data such as metrics, alerts, capacity, anomalies, reports, maintenance mode, node health, and adapter collection state. This CLI reference additionally exposes VCF Operations 9.1 fleet diagnostics, certificate/password/domain inventory, and a real-time PromQL interface to a separate data-query service, which are materially broader capabilities than the declared scope.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/capabilities.md:90

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/setup-guide.md:282