Back to skill

Security audit

vmware-avi

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed VMware AVI/NSX ALB operations integration with sensitive infrastructure access, but the risky actions are purpose-aligned, documented, and gated by confirmation/audit controls.

Install only if you intend to let the agent inspect and potentially change AVI/NSX ALB and AKO/Kubernetes state. Use least-privilege controller and kubeconfig credentials, prefer a secret manager or runtime environment injection over storing production passwords in ~/.vmware-avi/.env, and review blast-radius previews before approving any write action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (39)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
argument-hint: "[vs-name, ako command, or describe your task]"
allowed-tools:
  - Bash
metadata: {"openclaw":{"requires":{"anyBins":["vmware-avi","uvx"]},"optional":{"env":["VMWARE_AVI_CONFIG","<CONTROLLER>_PASSWORD","<CONTROLLER>_USERNAME","KUBECONFIG","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy","kubectl","helm"]},"homepage":"https://github.com/vmware-skills/VMware-AVI","emoji":"🔀","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
argument-hint: "[vs-name, ako command, or describe your task]"
allowed-tools:
  - Bash
metadata: {"openclaw":{"requires":{"anyBins":["vmware-avi","uvx"]},"optional":{"env":["VMWARE_AVI_CONFIG","<CONTROLLER>_PASSWORD","<CONTROLLER>_USERNAME","KUBECONFIG","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy","kubectl","helm"]},"homepage":"https://github.com/vmware-skills/VMware-AVI","emoji":"🔀","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
metadata: {"openclaw":{"requires":{"anyBins":["vmware-avi","uvx"]},"optional":{"env":["VMWARE_AVI_CONFIG","<CONTROLLER>_PASSWORD","<CONTROLLER>_USERNAME","KUBECONFIG","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy","kubectl","helm"]},"homepage":"https://github.com/vmware-skills/VMware-AVI","emoji":"🔀","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

md
metadata: {"openclaw":{"requires":{"anyBins":["vmware-avi","uvx"]},"optional":{"env":["VMWARE_AVI_CONFIG","<CONTROLLER>_PASSWORD","<CONTROLLER>_USERNAME","KUBECONFIG","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy","kubectl","helm"]},"homepage":"https://github.com/vmware-skills/VMware-AVI","emoji":"🔀","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 241)May include surrounding context.

md
metadata: {"openclaw":{"requires":{"anyBins":["vmware-avi","uvx"]},"optional":{"env":["VMWARE_AVI_CONFIG","<CONTROLLER>_PASSWORD","<CONTROLLER>_USERNAME","KUBECONFIG","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy","kubectl","helm"]},"homepage":"https://github.com/vmware-skills/VMware-AVI","emoji":"🔀","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 331)May include surrounding context.

md
metadata: {"openclaw":{"requires":{"anyBins":["vmware-avi","uvx"]},"optional":{"env":["VMWARE_AVI_CONFIG","<CONTROLLER>_PASSWORD","<CONTROLLER>_USERNAME","KUBECONFIG","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy","kubectl","helm"]},"homepage":"https://github.com/vmware-skills/VMware-AVI","emoji":"🔀","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 384)May include surrounding context.

md
metadata: {"openclaw":{"requires":{"anyBins":["vmware-avi","uvx"]},"optional":{"env":["VMWARE_AVI_CONFIG","<CONTROLLER>_PASSWORD","<CONTROLLER>_USERNAME","KUBECONFIG","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy","kubectl","helm"]},"homepage":"https://github.com/vmware-skills/VMware-AVI","emoji":"🔀","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 387)May include surrounding context.

md
metadata: {"openclaw":{"requires":{"anyBins":["vmware-avi","uvx"]},"optional":{"env":["VMWARE_AVI_CONFIG","<CONTROLLER>_PASSWORD","<CONTROLLER>_USERNAME","KUBECONFIG","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy","kubectl","helm"]},"homepage":"https://github.com/vmware-skills/VMware-AVI","emoji":"🔀","os":["macos","linux"]}}
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---

# VMware AVI

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 131)May include surrounding context.

md
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---

# VMware AVI

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 149)May include surrounding context.

md
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---

# VMware AVI

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
compatibility: >
  vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
  AVI Controller operations require avisdk and a per-controller password env var in ~/.vmware-avi/.env following the pattern <CONTROLLER_NAME_UPPER>_PASSWORD (e.g., controller "prod-avi" → PROD_AVI_PASSWORD).
  AKO operations require kubectl and a valid kubeconfig (default ~/.kube/config or KUBECONFIG env var). Kubeconfig is read-only — this skill does not modify kubeconfig files.
---

# VMware AVI

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
| Command | Description | Flags |
|---------|-------------|-------|
| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |
| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |
| `vmware-avi config` | Show current configuration (passwords masked) | -- |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
| Command | Description | Flags |
|---------|-------------|-------|
| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |
| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |
| `vmware-avi config` | Show current configuration (passwords masked) | -- |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/capabilities.md (reported line 187)May include surrounding context.

md
| Command | Description | Flags |
|---------|-------------|-------|
| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |
| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |
| `vmware-avi config` | Show current configuration (passwords masked) | -- |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli-reference.md (reported line 9)May include surrounding context.

md
| Command | Description | Flags |
|---------|-------------|-------|
| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |
| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |
| `vmware-avi config` | Show current configuration (passwords masked) | -- |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 17)May include surrounding context.

md
| Command | Description | Flags |
|---------|-------------|-------|
| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |
| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |
| `vmware-avi config` | Show current configuration (passwords masked) | -- |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 90)May include surrounding context.

md
| Command | Description | Flags |
|---------|-------------|-------|
| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |
| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |
| `vmware-avi config` | Show current configuration (passwords masked) | -- |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 131)May include surrounding context.

md
| Command | Description | Flags |
|---------|-------------|-------|
| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |
| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |
| `vmware-avi config` | Show current configuration (passwords masked) | -- |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 149)May include surrounding context.

md
| Command | Description | Flags |
|---------|-------------|-------|
| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |
| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |
| `vmware-avi config` | Show current configuration (passwords masked) | -- |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 178)May include surrounding context.

md
| Command | Description | Flags |
|---------|-------------|-------|
| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |
| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |
| `vmware-avi config` | Show current configuration (passwords masked) | -- |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-guide.md (reported line 180)May include surrounding context.

md
| Command | Description | Flags |
|---------|-------------|-------|
| `vmware-avi doctor` | Run environment diagnostics (Controller connectivity, kubeconfig, SDK availability) | -- |
| `vmware-avi init` | Generate `config.yaml` and `.env` templates in `~/.vmware-avi/` | -- |
| `vmware-avi config` | Show current configuration (passwords masked) | -- |

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The guide instructs users to place controller passwords in a local .env file, which creates a persistent plaintext-at-rest secret store even if permissions are later tightened. In an agent/MCP context, local files may be more likely to be inspected, backed up, or exposed by tooling, making this more sensitive than ordinary documentation.

Content

Scanner excerpt · references/setup-guide.md (reported line 153)May include surrounding context.

| ako.default_context | No | current-context | K8s context for AKO operations | | ako.namespace | No | avi-system | Namespace where AKO is deployed |

Step 3: Set passwords in .env

bash
# ~/.vmware-avi/.env

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The example shows concrete password variables populated in ~/.vmware-avi/.env, normalizing storage of reusable credentials on disk. Even with the later note that base64 is only obfuscation, this practice increases risk of secret leakage through backups, workstation compromise, or accidental file exposure.

Content

Scanner excerpt · references/setup-guide.md (reported line 156)May include surrounding context.

Step 3: Set passwords in .env

bash
# ~/.vmware-avi/.env
PROD_AVI_PASSWORD=your-secure-password-here
STAGING_AVI_PASSWORD=another-password-here

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The troubleshooting step explicitly instructs appending a password directly into ~/.vmware-avi/.env, reinforcing insecure long-lived local secret storage. In a skill intended for infrastructure operations, these credentials can grant access to load balancer controllers and potentially production environments.

Content

Scanner excerpt · references/setup-guide.md (reported line 343)May include surrounding context.

export PROD_AVI_PASSWORD=yourpassword

Or set it in ~/.vmware-avi/.env:

echo 'PROD_AVI_PASSWORD=yourpassword' >> ~/.vmware-avi/.env

text

### "Controller unreachable" in doctor

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/setup-guide.md:158