vmware-vcenter-attack
Fail
Audited by Snyk on Aug 27, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (critical risk: 1.00). This document is an explicit offensive playbook for discovering and exploiting internet-exposed VMware vCenter/Workspace ONE/Aria instances, containing step-by-step reconnaissance commands, CVE exploitation probes/PoC references, credential abuse guidance, and attack chaining instructions intended to facilitate compromise.
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill contains curl examples that embed credentials/placeholders (e.g., -u 'user@vsphere.local:' and vmware-api-session-id: ) and explicitly tells operators to "use creds discovered in breach corpora", which requires inserting real secret values verbatim into commands/headers — an exfiltration risk if the LLM were to handle or emit them.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (critical risk: 1.00). The skill is explicitly an offensive "vmware-vcenter-attack" playbook that contains actionable runtime exploit commands and payloads (e.g., pre-auth file-upload probes, a Freemarker SSTI payload, session-token retrieval and datastore download, and SAML-assertion takeover chains) intended to achieve remote RCE and takeover of vCenter/VMware assets.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). SKILL.md’s “external attack matrix” runtime workflow instructs the agent to actively probe and ingest first-party remote HTTP/SAML/XML/LDAP content from attacker-chosen target URLs (e.g.,
/ui/login,/sdk/vimServiceVersions.xml,/websso/SAML2/Metadata/..., catalog portal query, and vmdir LDAP responses), rather than consuming outsider-authored free text from a queue/feed it monitors.
Issues (4)
E004
CRITICALPrompt injection detected in skill instructions.
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata