vsphere

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions in references/govc.md for downloading the govc CLI tool from VMware's official GitHub repository (github.com/vmware/govmomi). This is a reference to a well-known technology provider and is standard practice for tool installation.
  • [COMMAND_EXECUTION]: The skill contains extensive examples of command-line operations for govc, ansible-galaxy, pip, esxcli, and curl. These commands are used for legitimate infrastructure management tasks such as VM lifecycle management, snapshotting, and system configuration. All sensitive values (passwords, hostnames, IP addresses) are provided as placeholders or suggested to be managed via environment variables and Ansible Vault.
  • [DATA_EXFILTRATION]: While the skill documents tools capable of transferring files (e.g., govc guest.download), these are described within the context of standard guest operations and troubleshooting. There are no patterns indicating the exfiltration of data to unauthorized or suspicious external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 06:51 PM
Security Audit — agent-trust-hub — vsphere