Back to skill

Security audit

vmware-harden

Security checks across malware telemetry and agentic risk

Overview

The skill is a VMware compliance scanner with disclosed local storage and optional LLM advice, and its sensitive behaviors are mostly purpose-aligned.

Install only where VMware compliance data may be stored locally, protect the DuckDB and audit files, and set ANTHROPIC_API_KEY only if sending remediation context to Anthropic is acceptable for your environment. Use vmware-pilot approval gates for any actual remediation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The `advise` command can use `AnthropicProvider` when `ANTHROPIC_API_KEY` is set, but the documentation does not warn that violation details and environment-derived data may be transmitted to an external LLM service. In a VMware compliance context, those inputs may contain sensitive infrastructure configuration, hostnames, control failures, or security posture data, creating a real confidentiality and compliance risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.