Vmware Nsx

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed VMware NSX management skill with real network-admin power, and the main risk is configuring it safely rather than hidden behavior.

Install only if you intend to let an agent manage VMware NSX networking. Use a least-privilege NSX account, keep ~/.vmware-nsx/.env at chmod 600, set verify_ssl: true with a trusted or custom CA for production, review dry-runs before writes, and be aware that delete operations can affect live network connectivity.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The setup examples normalize `verify_ssl: false` for NSX Manager connections without an immediate warning, which can lead users to disable certificate validation in real environments. That exposes administrative credentials and API traffic to man-in-the-middle attacks, especially dangerous because this skill manages high-privilege network infrastructure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal