Back to skill

Security audit

Vmware Monitor

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed read-only VMware monitoring tool with opt-in background scans and webhooks that users should configure carefully.

Before installing, review the source and run it with a least-privilege read-only VMware account. Treat inventory, sessions, events, and host logs as sensitive. Only start the daemon if continuous monitoring is wanted, and only configure Slack, Discord, or webhook URLs if sending aggregated alert metadata to that endpoint is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
85% confidence
Finding
The documented `scan now` and daemon lifecycle commands materially expand the skill beyond passive, on-demand querying into active background collection and host log scanning. Even if still nominally read-only, scheduled scanning increases the operational footprint, may collect and persist sensitive telemetry, and contradicts the manifest's stronger safety claims, which can mislead users and downstream agents about side effects and monitoring behavior.

Description-Behavior Mismatch

Low
Confidence
88% confidence
Finding
The documentation understates outbound data exposure by claiming webhook notifications go only to user-controlled endpoints and not to third-party services, while explicitly allowing Slack, Discord, or any arbitrary HTTP endpoint. This can mislead operators into enabling integrations without recognizing that monitoring metadata will be transmitted outside the local environment, creating a data disclosure and trust-boundary issue.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.