Back to plugin

Security audit

VMware Monitor

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed read-only VMware monitoring skill with local config/audit files and optional user-started scanning/webhook alerts.

Before installing, use a dedicated VMware service account with the built-in Read-Only role, grant Global.Diagnostics or session-list privileges only if you need those specific reads, and treat optional webhooks as receiving operational data such as hostnames, IPs, usernames, and event/log text. Review the pinned PyPI package source before production use because the artifact registers an external MCP/CLI package rather than bundling the runtime code.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.