windows-vm-detection-post-wmic

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses ProcessBuilder to execute shell commands (powershell and wmic) to query system information from the management layer. This behavior is used to identify hypervisor brand strings (e.g., VMware, VirtualBox) within the Win32_ComputerSystem class to handle specific graphics rendering issues in VM environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 07:03 AM
Security Audit — agent-trust-hub — windows-vm-detection-post-wmic