vmware-debug
Use this skill whenever the user is troubleshooting a VMware/vSphere problem — a reported error, an exception, a log dump, a slow or failed VM, a host that went sideways — and needs help locating the root cause. It is the diagnostic brain of the VMware family: it drives a systematic investigation, pulls the right signals from the other skills, correlates events into one timeline, ranks root-cause hypotheses, and tells you what to check next even when you don't know where to start. Always use this skill for "diagnose this VMware issue", "why is my VM slow", "troubleshoot this vSphere error", "what does this log mean", "help me figure out what broke" when the context is explicitly VMware/vSphere/ESXi/NSX. It never touches vSphere: its only writes are to a local case ledger. Do NOT use it to execute fixes — single fixes go to vmware-aiops, multi-step gated remediation goes to vmware-pilot. Do NOT use it for routine inventory or health checks with no problem to solve — use vmware-monitor.
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
1.13.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.13.1release · observed Sep 16, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-debug- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:vmware-debug` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/vmware-debug before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-debug/snapshot"
Documentation
CLAWHUB
149,681 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: vmware-debug
description: >
Use this skill whenever the user is troubleshooting a VMware/vSphere problem —
a reported error, an exception, a log dump, a slow or failed VM, a host that
went sideways — and needs help locating the root cause. It is the diagnostic
brain of the VMware family: it drives a systematic investigation, pulls the
right signals from the other skills, correlates events into one timeline,
ranks root-cause hypotheses, and tells you what to check next even when you
don't know where to start. Always use this skill for "diagnose this VMware
issue", "why is my VM slow", "troubleshoot this vSphere error", "what does
this log mean", "help me figure out what broke" when the context is explicitly
VMware/vSphere/ESXi/NSX. It never touches vSphere: its only writes are to a
local case ledger. Do NOT
use it to execute fixes — single fixes go to vmware-aiops, multi-step gated
remediation goes to vmware-pilot. Do NOT use it for routine inventory or
health checks with no problem to solve — use vmware-monitor.
installer:
kind: uv
package: vmware-debug
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["vmware-debug","uvx"]},"optional":{"env":["VMWARE_AUDIT_APPROVED_BY","VMWARE_AUDIT_RATIONALE"],"bins":["vmware-policy"]},"homepage":"https://github.com/vmware-skills/VMware-Debug","os":["macos","linux"]}}
---
# VMware Debug
> **Disclaimer**: Community-maintained open-source project, **not affiliated with,
> endorsed by, or sponsored by VMware, Inc. or Broadcom Inc.** "VMware" and "vSphere"
> are trademarks of Broadcom. Source is publicly auditable under the MIT license.
The diagnostic brain of the VMware skill family. You bring the symptom; this skill
runs the investigation and points at the root cause. It **reads and reasons** — it
never writes to vSphere; its only writes go to its own local case ledger.
Companion skills do the data collection and the fixing.
## What This Skill Does
| Category | What | Read or Write |
|---|---|---|
| Incident correlation | Merge events from many sources into one timeline, detect spikes | Read |
| Root-cause ranking | Score symptom clusters, surface the most likely cause first | Read |
| Next-check ideas | Suggest exactly what to look at next (which skill/tool) when you're stuck | Read |
| Remediation routing | Hand the fix to vmware-aiops (single) or vmware-pilot (gated, multi-step) | Read (routes only) |
| Investigation ledger | Open a case; record evidence, gaps and hypotheses; grade and close it | Write (local ledger only) |
**No network access of its own, and no write to any VMware system.** It correlates
data the agent has already gathered with the other skills' read tools; its seven
write tools touch only the local case ledger.
## Quick Install
```bash
uv tool install vmware-debug==1.13.1
vmware-debug categories # see what it can diagnose
```
## When to Use This Skill
Use it when there is a **problem to solve**: an error message_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "vmware-debug",
"version": "1.13.1",
"publishedAt": 1789535979714
}references/agent-guardrails.md
# Operating vmware-debug with a local / small model Claude-class models drive this skill without special instruction. Smaller and locally-hosted models — Llama 3.3 70B, Qwen, Mistral, and similar, served through Goose, Ollama, or OpenShift AI — need explicit operating rules to call tools reliably. This page exists because an operator wrote those rules by hand first. The guardrails below are adapted, with thanks, from the working configuration [@juanpf-ha](https://github.com/juanpf-ha) developed while running vmware-monitor and vmware-aria against a production vSphere estate with Llama 3.3 70B FP8 on an on-prem H100 ([VMware-AIops#31](https://github.com/vmware-skills/VMware-AIops/issues/31)). The cross-skill rules are identical across this family; the parts below marked vmware-debug are specific to this skill. vmware-debug exposes 14 MCP tools: 7 reads and 7 writes. It connects to nothing and holds no credentials — the calling agent gathers events from the other skills, normalises them, and hands them over. The seven writes go to the local investigation ledger under `~/.vmware/cases/`, never to a VMware system. That makes it the safest skill in the family to point a small model at — and the one most exposed to the model's reasoning, because its output *is* an interpretation. For a small model the ledger is more than bookkeeping: `case_grade` computes the conclusion level from recorded evidence rather than accepting one, so a model that would happily narrate "root cause confirmed" cannot record that unless the evidence for it is actually in the folder. > **Disclaimer**: This is a community-maintained open-source project and is > **not affiliated with, endorsed by, or sponsored by VMware, Inc. or Broadcom > Inc.** "VMware" and "vSphere" are trademarks of Broadcom. --- ## First: the rules you no longer need to write Several guardrails from the original configuration are now enforced by the skill itself. Prompt instructions are advisory — a model can ignore them. These are structural, so it cannot. | Guardrail you would otherwise prompt for | Now enforced by | |---|---| | "Work read-only and never modify anything" | **The tool surface itself.** No tool reaches a VMware system. The seven [WRITE] tools write only to this skill's own local case ledger, so there is nothing in vSphere to withhold and nothing to switch off. | | "Diagnose only — never apply the fix you propose" | **Structural.** This skill has no tool that changes anything outside its own ledger, and it holds no connection to vCenter, NSX or anything else. Remediation is routed to vmware-aiops or vmware-pilot by the calling agent. | | "Do not fabricate a timeline — build it from the events I gave you" | **`incident_timeline` correlates only its input.** It is source-agnostic and has no way to fetch anything, so the timeline cannot contain an event the agent did not supply. | | "Tell me when the symptom is outside what you can recognise" | **`list_symptom_categories`** states the cat
references/capabilities.md
# vmware-debug Capabilities
Offline incident correlation. No network, no credentials, no writes to any VMware
system. This table covers the two stateless correlation tools; the twelve `case_*`
investigation-ledger tools (seven of which write, to the local ledger only) are
listed in `SKILL.md`, and their response sizes are not yet measured here.
| Tool | What it returns | Typical response tokens |
|---|---|---|
| `incident_timeline` | `{event_count, window, spikes:[{start,end,count,zscore}], hypotheses:[{category, score, summary, evidence_count, first_seen, last_seen, sample_text, suggested_check}], next_checks:[...]}` | 300–2000 (scales with hypotheses) |
| `list_symptom_categories` | `{items: [{category, example_keywords, suggested_check}], returned, limit, total, truncated, hint}` | ~400 |
`list_symptom_categories` returns the family list envelope — read the rows from
`items`. It has no `limit` parameter, which is exactly why the envelope matters:
`truncated: false` states that this is every category there is, rather than
leaving a model to guess whether it is holding page one. The catalogue is a
fixed in-process constant, so `total` is a real count and `limit` is `null`.
## Correlation engine
- **Timeline**: events normalised to the unified envelope, sorted, and time-binned
(auto bin width ≈ span/30, or caller-specified).
- **Spike detection**: z-score over bin counts (≥3 bins required for a baseline;
flat series yields no false spikes).
- **Hypothesis ranking**: events clustered by symptom category (keyword match on
text + entity), scored by summed severity weight, tie-broken by recency.
Uncategorised events are kept visible, not dropped.
- **Next-check routing**: each category carries a concrete "which skill/tool to run
next" suggestion — the value when the user doesn't know what to check.
## Symptom categories
`storage`, `network`, `compute`, `ha_drs`, `host_lifecycle`, `power_lifecycle`,
`auth`, `platform`, `hardware`, `licensing`, `data_collection`.
See `references/routing.md` for keyword signatures and the skill each routes to.
`hardware`, `licensing` and `data_collection` were added after real alert titles
("Host TPM attestation alarm", "License will soon expire", "Objects are not
receiving data from adapter instance") matched no category at all. A roll-up
such as "Group population health is degraded" is deliberately left
uncategorized: it names no subsystem, and the cause is in one of its members.
`host_lifecycle` is a host changing its own availability state — maintenance
mode, shutdown, reboot, standby, connection loss, sync failure.
`power_lifecycle` is the VM-level equivalent. They are separate because they are
separate investigations: the second is a task question for vmware-aiops, the
first is a cluster, DPM, vLCM or drift question.
## Design properties
- **Zero cross-skill runtime deps** — correlation is pure functions over plain
dicts; the agent fans out to other skills' read tools (踩坑 #21/#32).
- **JSON-references/cli-reference.md
# vmware-debug CLI Reference
All commands are offline (no network, no credentials). All but `mcp` are
read-only; `mcp` starts the MCP server, whose seven `case_*` write tools record
into the local case ledger.
## triage — correlate a set of collected events
```bash
vmware-debug triage [OPTIONS]
-e, --events PATH JSON file of event envelopes (reads stdin if omitted)
--bin-seconds N Time-bin width (auto if omitted)
--top-n N Max hypotheses to return [default: 5]
```
Input is a JSON array of event envelopes (see `references/event-envelope.md`):
```bash
cat events.json | vmware-debug triage
vmware-debug triage --events events.json --top-n 3
```
Output (JSON): `{event_count, window, spikes, hypotheses, next_checks}`.
## categories — list recognised symptom categories
```bash
vmware-debug categories
```
Prints each category, sample keywords, and the suggested next check (which
skill/tool to run). Use when you don't know what to look at.
## version / mcp
```bash
vmware-debug version # installed version
vmware-debug mcp # start the stdio MCP server (no network at startup)
```
## How the agent uses it
In an agent, the cross-skill correlation happens at the agent layer:
1. Fetch events with the data-source skills (vmware-monitor `event_list`,
vmware-log-insight `log_search`/`log_aggregate`, vmware-aria alerts/anomaly,
vmware-nsx).
2. Normalise each into the event envelope.
3. Call the `incident_timeline` MCP tool to correlate and rank.
4. Follow `next_checks`; route any fix to vmware-aiops / vmware-pilot.AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/vmware-debug",
"sourceUrl": "https://clawhub.ai/zw008/skills/vmware-debug",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T06:37:53.811Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-debug/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-debug/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T06:37:53.811Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/zw008/vmware-debug",
"sourceUrl": "https://clawhub.ai/zw008/vmware-debug",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T06:37:53.811Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.13.1",
"href": "https://clawhub.ai/zw008/vmware-debug",
"sourceUrl": "https://clawhub.ai/zw008/vmware-debug",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-16T05:19:39.714Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-debug/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-vmware-debug/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.13.1",
"description": "Exclusion is decided per hypothesis; an empty ledger rules nothing out",
"href": "https://clawhub.ai/zw008/vmware-debug",
"sourceUrl": "https://clawhub.ai/zw008/vmware-debug",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-16T05:19:39.714Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
