The skill lacks version pinning for dependencies, creating a supply chain risk, and contains broken documentation references and metadata non-compliance that undermine its reliability and security posture.
npx skills add https://github.com/zw008/VMware-NSXSKILL.md links to "references/agent-guardrails.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`references/agent-guardrails.md`](references/agent-guardrails.md)
Skill does not specify a license field. Specifying a license helps users understand usage terms.
Skill 'compatibility' field exceeds the Agent Skills spec limit of 500 characters.
The installation instruction uses `uv tool install vmware-nsx-mgmt` without specifying a version pin or hash, which could lead to the installation of compromised code if the package registry is poisoned.
uv tool install vmware-nsx-mgmt
[](https://mondoo.com/ai-agent-security/skills/github/zw008/VMware-NSX/vmware-nsx)<a href="https://mondoo.com/ai-agent-security/skills/github/zw008/VMware-NSX/vmware-nsx"><img src="https://mondoo.com/ai-agent-security/api/badge/github/zw008/VMware-NSX/vmware-nsx.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/zw008/VMware-NSX/vmware-nsx.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.