vmware-aiops
Use this skill whenever the user needs to manage VMs in VMware/vSphere/ESXi — it's the entry point for all VM operations. Directly handles: power on/off, clone, snapshot, migrate, deploy from OVA or templates, run commands inside VMs, batch operations, cluster management, vCenter alarm acknowledgment, a one-glance cluster-health triage ("is anything on fire?"), and VM/host/datastore investigation drill-downs. Always use this skill for any "power on", "clone", "deploy", "migrate", "batch", "guest exec", "alarm", or VM lifecycle task, and for triage like "is anything on fire" / "what needs attention now" / "investigate this VM", when the context is explicitly VMware, vSphere, or ESXi. Do NOT use for general read-only queries (inventory/events/VM details — use vmware-monitor), NSX networking (use vmware-nsx), storage/iSCSI/vSAN (use vmware-storage), or Kubernetes cluster lifecycle (use vmware-vks). For multi-step workflows use vmware-pilot. For load balancing/AVI/AKO use vmware-avi.
Rank
62
Safety
84
Downloads
5.0k
Updated
Oct 9, 2026
Version
1.12.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 5K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 5K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.12.0release · observed Sep 20, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/vmware-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-aiops/snapshot"
Documentation
CLAWHUB
153,264 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: vmware-aiops
description: >
Use this skill whenever the user needs to manage VMs in VMware/vSphere/ESXi — it's the entry point for all VM operations.
Directly handles: power on/off, clone, snapshot, migrate, deploy from OVA or templates, run commands inside VMs, batch operations, cluster management, vCenter alarm acknowledgment, a one-glance cluster-health triage ("is anything on fire?"), and VM/host/datastore investigation drill-downs.
Always use this skill for any "power on", "clone", "deploy", "migrate", "batch", "guest exec", "alarm", or VM lifecycle task, and for triage like "is anything on fire" / "what needs attention now" / "investigate this VM", when the context is explicitly VMware, vSphere, or ESXi.
Do NOT use for general read-only queries (inventory/events/VM details — use vmware-monitor), NSX networking (use vmware-nsx), storage/iSCSI/vSAN (use vmware-storage), or Kubernetes cluster lifecycle (use vmware-vks).
For multi-step workflows use vmware-pilot. For load balancing/AVI/AKO use vmware-avi.
installer:
kind: uv
package: vmware-aiops
argument-hint: "[vm-name or describe your task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["vmware-aiops","uvx"]},"optional":{"env":["VMWARE_AIOPS_CONFIG","VMWARE_TARGET_PASSWORD","VMWARE_<TARGET>_USERNAME","SLACK_WEBHOOK_URL","DISCORD_WEBHOOK_URL","VMWARE_AUDIT_APPROVED_BY"],"bins":["vmware-policy"]},"homepage":"https://github.com/vmware-skills/VMware-AIops","emoji":"🖥️","os":["macos","linux"]}}
compatibility: >
vmware-policy auto-installed as Python dependency (provides @vmware_tool decorator and audit logging). All write operations audited to ~/.vmware/audit.db.
Credentials: Each vCenter/ESXi target requires a per-target password env var in ~/.vmware-aiops/.env following the pattern VMWARE_<TARGET_NAME_UPPER>_PASSWORD. Passwords are never logged or echoed.
Destructive operations: All write tools require explicit parameters and pass through the @vmware_tool decorator (policy check + audit + sanitize). Every MCP write tool annotated destructive (22 of 43: power-off, delete, migrate, snapshot revert/delete, guest exec/upload/provision, cluster delete/remove-host, TTL, Clean Slate, plan apply/rollback, host-network and DRS) takes one confirm argument whose default returns a no-write blast-radius preview (HLD section 7); confirm=True is refused, and audited as a failure, on a blocker or an unreadable measurement, and vm_delete also requires the preview's acknowledgement echoed back and still matching; the other 21 write tools (create, clone, deploy, power-on, reconfigure) act on the first call. The enforcement boundary is the RBAC of the vCenter/ESXi account the server connects with, so run it under a dedicated least-privilege service account (a read-only role makes it read-only). Optional deny rules in ~/.vmware/rules.yaml are checked before every MCP call and remote CLI command; the shipped baseline denies nothing. CLI destructive commands addi_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "vmware-aiops",
"version": "1.12.0",
"publishedAt": 1789915898030
}references/agent-guardrails.md
# Operating vmware-aiops with a local / small model
Claude-class models drive this skill without special instruction. Smaller and
locally-hosted models — Llama 3.3 70B, Qwen, Mistral, and similar, served
through Goose, Ollama, or OpenShift AI — need explicit operating rules to call
tools reliably.
This page exists because an operator wrote those rules by hand first. The
guardrails below are adapted, with thanks, from the working configuration
[@juanpf-ha](https://github.com/juanpf-ha) developed while running
vmware-monitor and vmware-aria against a production vSphere estate with Llama
3.3 70B FP8 on an on-prem H100
([VMware-AIops#31](https://github.com/vmware-skills/VMware-AIops/issues/31)). The
cross-skill rules are identical across this family; the parts below marked
vmware-aiops are specific to this skill.
vmware-aiops carries the family's largest write surface — 43 of its 60 MCP
tools change state, including `vm_delete`, cluster deletion, host VMkernel
removal and guest command execution. Of every skill here, this is the one where a model's discipline
should not be the only thing standing between a prompt and a destroyed VM — and
over MCP, apart from optional deny rules, the only enforcement is the RBAC of
the vCenter/ESXi account the server connects with. Run it under a dedicated,
least-privilege service account scoped to what the agent may change.
> **Disclaimer**: This is a community-maintained open-source project and is
> **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom
> Inc.** "VMware" and "vSphere" are trademarks of Broadcom.
---
## First: the rules you no longer need to write
Several guardrails from the original configuration are now enforced by the
skill itself. Prompt instructions are advisory — a model can ignore them.
These are structural, so it cannot.
| Guardrail you would otherwise prompt for | Now enforced by |
|---|---|
| "Use explicit limits for queries that may return large amounts of data" | **The list envelope.** `browse_datastore`, `list_vcenter_alarms`, `vm_list_plans`, `vm_list_snapshots` and `vm_list_ttl` return `{items, returned, limit, total, truncated, hint}`, so the model reads truncation instead of guessing at it. |
| "If a listing came back empty, say so rather than claiming the call failed" | Same envelope. Empty `items` with `truncated: false` means checked-and-none — a stated result, not a silence the model has to interpret. |
| "Log every state change you make" | **The `@vmware_tool` decorator.** Every write is recorded to `~/.vmware/audit.db` before the model sees the result, and policy rules are evaluated ahead of execution. Neither depends on the model cooperating. |
| "Block state-changing writes against a production target" | **Policy.** An opt-in environment-scoped `deny` rule in `~/.vmware/rules.yaml` matches a target's `environment:` label and refuses matching writes before execution. |
---
## The system prompt
Everything below still benefits from being stated ereferences/capabilities.md
# Capabilities Reference
## Automation Level Reference
Each operation is classified by autonomy level per the Enterprise Harness Engineering framework. This tells AI agents how much human gating each tool needs:
| Level | Meaning | Agent autonomy | Examples in this skill |
|:-:|---|---|---|
| **L1** | Read-only, raw data | Always auto-run | `cluster_info`, `browse_datastore`, `scan_datastore_images`, `list_vcenter_alarms`, `vm_list_snapshots`, `vm_list_ttl`, `vm_task_status` |
| **L2** | Read + analysis / recommendation | Always auto-run | `cluster_health_summary`, `cross_vcenter_attention`, `vm_investigation_bundle`, `host_investigation_bundle`, `datastore_investigation_bundle`; scheduled scan reports, alarm/event correlation, log pattern analysis |
| **L3** | Single write | The level is a statement about blast radius, not about an enforced gate. On the CLI the destructive ones double-confirm (`vm power-on` and `vm snapshot-create` do not); over MCP every destructive one (`vm_power_off`, `vm_delete`, `vm_migrate`, …) returns a no-write preview of its blast radius unless called with `confirm=True`, while `vm_power_on`, `vm_create_snapshot` and `vm_clone` act on the first call — see [What gates a write](#what-gates-a-write) | `vm_power_on`, `vm_power_off`, `vm_delete`, `vm_create_snapshot`, `vm_clone`, `vm_migrate` |
| **L4** | Multi-step plan / apply workflow | Plan generation auto. Review with the user before applying — an agent convention, not enforced: `vm_apply_plan` takes only a plan id | `vm_create_plan` → `vm_apply_plan` → `vm_rollback_plan`, batch-clone, batch-deploy YAML |
| **L5** | Auto-remediation from learned pattern | Pattern library only; requires `risk:low` + `reversible:true` + `repeatable:true` + signed approval | *(roadmap — not implemented; candidates: snapshot consolidation, orphaned VM cleanup)* |
**Notes**:
- L1/L2 tools are read-only and safe for agents to call unprompted.
- **The levels describe risk, not enforcement.** The MCP previews stop an agent acting blind, and `confirm=True` is refused on a blocker, but nothing in this skill stops an agent that passes `confirm=True` from calling an L3 or L4 tool the account may call. What decides whether the write lands is the vCenter account — see [What gates a write](#what-gates-a-write).
- **List envelope**: the read list tools (`browse_datastore`, `list_vcenter_alarms`, `vm_list_plans`, `vm_list_snapshots`, `vm_list_ttl`) return `{items, returned, limit, total, truncated, hint}` instead of a bare array, so an agent can tell a complete answer from a first page rather than inferring it (issue #31). All five enumerate their collection in full before any limit is applied, so `total` is always the real count; only `list_vcenter_alarms` takes a `limit` and can therefore report `truncated: true`. The write `batch_*` tools deliberately keep a bare list — each row is a per-item result of work already done, complete by construction. Errors from these read tools are `{error, hint}` (references/cli-reference.md
# CLI Reference Destructive and deploy commands ask for two confirmations and most write commands take `--dry-run` (not `deploy iso`, `deploy mark-template`, `vm cancel-ttl`, `vm guest-download`). These are CLI-only: over MCP the 22 destructive write tools take `confirm` and preview by default, the other 21 write tools act immediately, and the enforcement boundary there is the RBAC of the vCenter/ESXi account — see `capabilities.md` → "What gates a write". ```bash # Diagnostics vmware-aiops doctor [--skip-auth] # --skip-auth only skips doctor's own vSphere login check; no other command has it # MCP Config Generator vmware-aiops mcp-config generate --agent <goose|cursor|claude-code|continue|vscode-copilot|localcowork|mcp-agent> vmware-aiops mcp-config list # VM Operations vmware-aiops vm power-on <vm-name> vmware-aiops vm power-off <vm-name> [--force] vmware-aiops vm create <name> [--cpu <n>] [--memory <mb>] [--disk <gb>] vmware-aiops vm delete <vm-name> vmware-aiops vm reconfigure <vm-name> [--cpu <n>] [--memory <mb>] vmware-aiops vm snapshot-create <vm-name> --name <snap-name> [--description <text>] [--memory] vmware-aiops vm snapshot-list <vm-name> vmware-aiops vm snapshot-revert <vm-name> --name <snap-name> vmware-aiops vm snapshot-delete <vm-name> --name <snap-name> [--remove-children] vmware-aiops vm clone <vm-name> --new-name <name> [--to-host <host>] [--to-datastore <ds>] [--power-on] vmware-aiops vm migrate <vm-name> --to-host <host> [--to-datastore <ds>] vmware-aiops vm set-ttl <vm-name> --minutes <n> vmware-aiops vm cancel-ttl <vm-name> vmware-aiops vm list-ttl vmware-aiops vm clean-slate <vm-name> [--snapshot baseline] # Guest Operations (requires VMware Tools) vmware-aiops vm guest-exec <vm-name> --cmd /bin/bash --args "-c 'ls -la /tmp'" --user root vmware-aiops vm guest-upload <vm-name> --local ./script.sh --guest /tmp/script.sh --user root vmware-aiops vm guest-download <vm-name> --guest /var/log/syslog --local ./syslog.txt --user root # Plan → Apply (multi-step operations) vmware-aiops plan list # Deploy vmware-aiops deploy ova <path> --name <vm-name> [--datastore <ds>] [--network <net>] vmware-aiops deploy template <template-name> --name <vm-name> [--datastore <ds>] vmware-aiops deploy linked-clone --source <vm> --snapshot <snap> --name <new-name> vmware-aiops deploy iso <vm-name> --iso "[datastore] path/file.iso" vmware-aiops deploy mark-template <vm-name> vmware-aiops deploy batch-clone --source <vm> --count <n> [--prefix <prefix>] vmware-aiops deploy batch <spec.yaml> # Cluster vmware-aiops cluster info <name> vmware-aiops cluster create <name> [--ha] [--drs] [--drs-behavior fullyAutomated|partiallyAutomated|manual] [--datacenter <dc>] vmware-aiops cluster delete <name> vmware-aiops cluster add-host <cluster> --host <hostname> vmware-aiops cluster remove-host <cluster> --host <hostname> # host must be in maintenance mode; moved to datacenter host folder as standalone vmware-aiops cluster configure <name> [--ha/--no-
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/vmware-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/vmware-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T04:26:49.944Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T04:26:49.944Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "5K downloads",
"href": "https://clawhub.ai/zw008/vmware-aiops",
"sourceUrl": "https://clawhub.ai/zw008/vmware-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T04:26:49.944Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.12.0",
"href": "https://clawhub.ai/zw008/vmware-aiops",
"sourceUrl": "https://clawhub.ai/zw008/vmware-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-20T14:51:38.030Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.12.0",
"description": "MCP instructions now name the configured targets and how to choose one; a config that cannot be read says so instead of falling silent.",
"href": "https://clawhub.ai/zw008/vmware-aiops",
"sourceUrl": "https://clawhub.ai/zw008/vmware-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-20T14:51:38.030Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
