The skill executes arbitrary commands and network operations without declaring allowed tools, creating an unconstrained and opaque attack surface that poses a significant security risk.
npx skills add https://github.com/zw008/VMware-VKSSkill does not specify a license field. Specifying a license helps users understand usage terms.
Skill description is empty or too short. A clear description helps users evaluate the skill's purpose.
[](https://mondoo.com/ai-agent-security/skills/github/zw008/VMware-VKS/vmware-vks)<a href="https://mondoo.com/ai-agent-security/skills/github/zw008/VMware-VKS/vmware-vks"><img src="https://mondoo.com/ai-agent-security/api/badge/github/zw008/VMware-VKS/vmware-vks.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/zw008/VMware-VKS/vmware-vks.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.