vmware-vcenter-attack

Fail

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides explicit exploit templates and payloads for Remote Code Execution (RCE), specifically targeting Server-Side Template Injection (SSTI) vulnerabilities in Workspace ONE Access (CVE-2022-22954).
  • [COMMAND_EXECUTION]: Orchestrates automated command sequences for active exploitation, including probes for unauthenticated arbitrary file upload vulnerabilities (CVE-2021-21972) and directory traversal.
  • [DATA_EXFILTRATION]: Details specific methods and commands for the unauthorized extraction of sensitive information, including Virtual Machine Disks (VMDK), snapshots, and credentials stored in cloud-init configuration files from remote datastores.
  • [CREDENTIALS_UNSAFE]: Hardcodes a reference table of default administrative credentials for various VMware products (e.g., vCenter, Aria, ESXi) intended for use in unauthorized access attempts.
  • [PROMPT_INJECTION]: The skill lacks sanitization for the user-supplied 'TARGET' variable, which is directly interpolated into shell commands. This represents a vulnerability surface for indirect prompt injection where a malicious target environment could influence agent behavior through banner content or metadata.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — vmware-vcenter-attack