The skill lacks version pinning and integrity verification for its installation process, creating a significant supply chain vulnerability that could allow the execution of malicious code.
npx skills add https://github.com/zw008/VMware-PolicyThe installation instructions use 'uv tool install vmware-policy' without specifying a version or hash, making the installation susceptible to supply chain poisoning.
uv tool install vmware-policy
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/zw008/VMware-Policy/vmware-policy)<a href="https://mondoo.com/ai-agent-security/skills/github/zw008/VMware-Policy/vmware-policy"><img src="https://mondoo.com/ai-agent-security/api/badge/github/zw008/VMware-Policy/vmware-policy.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/zw008/VMware-Policy/vmware-policy.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.