The skill introduces a critical security vulnerability by allowing users to disable policy enforcement via an environment variable, effectively bypassing essential audit and restriction controls.
npx skills add https://github.com/zw008/VMware-PolicyThe skill provides a mechanism to disable security policy enforcement via the VMWARE_POLICY_DISABLED environment variable, which could be exploited by an attacker to bypass audit and restriction controls.
To temporarily bypass: VMWARE_POLICY_DISABLED=1 (still logged as bypassed).
Skill does not specify a license field. Specifying a license helps users understand usage terms.
Skill description is empty or too short. A clear description helps users evaluate the skill's purpose.
[](https://mondoo.com/ai-agent-security/skills/github/zw008/VMware-Policy/vmware-policy)<a href="https://mondoo.com/ai-agent-security/skills/github/zw008/VMware-Policy/vmware-policy"><img src="https://mondoo.com/ai-agent-security/api/badge/github/zw008/VMware-Policy/vmware-policy.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/zw008/VMware-Policy/vmware-policy.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.