{"id":"cc958240-d7ef-4335-b66a-65e7284fa4fb","entityType":"agent","slug":"clawhub-zw008-nutanix-aiops","name":"nutanix-aiops","canonicalUrl":"https://www.xpersona.co/agent/clawhub-zw008-nutanix-aiops","canonicalPath":"/agent/clawhub-zw008-nutanix-aiops","generatedAt":"2026-10-10T07:42:11.303Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T00:59:20.333Z","emptyReason":null},"description":"Use this skill whenever the user needs to operate a Nutanix estate through Prism Central (v4 REST API) — an estate/cluster health overview, cluster & host inventory and utilization, VM lifecycle across AHV and ESXi (list/get/power/create/update/clone/delete/migrate), storage containers, subnets/network, images & categories, data protection / DR (snapshots, recovery points, protection domains, VM protect, failover), alerts & events with alert RCA (analyze_alert), LCM firmware/software upgrades, capacity runway forecasting, and read-only diagnostics/RCA over the whole estate (cluster_health_rca, alert_triage_rca). Always use this skill for \"Nutanix\", \"Prism Central\", \"AHV\", \"cluster health\", \"list VMs\", \"power on/off a VM\", \"clone/migrate a VM\", \"delete a VM\", \"snapshot\", \"recovery point\", \"protection domain\", \"failover\", \"why did this alert fire\" / \"root cause this alert\", \"LCM upgrade / firmware\", \"days until storage is full\" / \"capacity runway\", \"what's wrong with my cluster\" / \"diagnose the estate\", \"triage my alerts\", when the context is a Nutanix cluster or Prism Central. Do NOT use when the target is a non-Nutanix platform — those belong to their own AIops-tools sibling; this skill is Prism Central v4 only. Governed Nutanix Prism Central operations with a built-in governance harness (audit, token budget, undo, descriptive risk-tier labels).","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:nutanix-aiops","sourceUrl":"https://clawhub.ai/zw008/nutanix-aiops","homepage":"https://clawhub.ai/zw008/skills/nutanix-aiops","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/zw008/nutanix-aiops","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/zw008/skills/nutanix-aiops","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":65,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"nutanix-aiops technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T00:59:20.333Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T00:59:20.333Z","emptyReason":null},"stars":null,"forks":null,"downloads":1821,"packageName":null,"latestVersion":"0.11.4","tractionLabel":"1.8K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T00:59:20.304Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T00:59:20.333Z","lastCrawledAt":"2026-10-10T00:59:20.304Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T00:59:20.304Z","lastVerifiedAt":null,"highlights":[{"version":"0.11.4","createdAt":"2026-09-16T23:26:16.071Z","changelog":"- Removed the skill-card.md file. - Updated references/agent-guardrails.md. - No major user-facing changes to functionality. - Documentation or internal references update only.","fileCount":7,"zipByteSize":19285},{"version":"0.11.3","createdAt":"2026-09-15T06:10:55.539Z","changelog":"- Removed the skill-card.md file to streamline documentation. - No functional or behavioral changes to the skill itself. - Existing operations, features, and usage remain unchanged.","fileCount":7,"zipByteSize":19195},{"version":"0.11.2","createdAt":"2026-09-12T14:34:29.100Z","changelog":"- skill-card.md file removed. - SKILL.md updated to reference a new OpenClaw plugin source: `clawhub:@zw008/nutanix-aiops` (previously `@aiops-tools/nutanix-aiops`). - No functional or interface changes to the underlying skill described. - Documentation updated to reflect plugin registry/location change.","fileCount":7,"zipByteSize":19060},{"version":"0.11.1","createdAt":"2026-09-12T10:19:20.395Z","changelog":"- Added OpenClaw plugin installation instructions to documentation (SKILL.md). - Updated usage details for installing and working with the skill as an OpenClaw plugin. - Removed the skill-card.md file. - No changes to core functionality or interface.","fileCount":7,"zipByteSize":19210},{"version":"0.11.0","createdAt":"2026-09-12T01:06:41.892Z","changelog":"- Updated the skill metadata to require either \"nutanix-aiops\" or \"uvx\" in PATH, instead of only \"nutanix-aiops\" - Made \"NUTANIX_AIOPS_CONFIG\" and \"NUTANIX_AIOPS_MASTER_PASSWORD\" environment variables optional rather than required - Removed unused file: skill-card.md - No functional changes to tool behaviors or interfaces","fileCount":7,"zipByteSize":18963},{"version":"0.10.0","createdAt":"2026-08-10T06:52:52.400Z","changelog":"# nutanix-aiops 0.10.0 – Changelog - Removed the sample file: skill-card.md - No user-facing changes to skill features or functionality.","fileCount":7,"zipByteSize":19091},{"version":"0.9.0","createdAt":"2026-08-03T05:54:03.780Z","changelog":"- Removed the sample skill card file (skill-card.md) from the package. - No changes were made to functionality or user-facing features. - All existing operations and features remain unchanged.","fileCount":7,"zipByteSize":19021},{"version":"0.8.0","createdAt":"2026-08-02T09:40:47.765Z","changelog":"nutanix-aiops 0.8.0 - Removed the file skill-card.md. - No changes to functionality or features.","fileCount":7,"zipByteSize":19289}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:nutanix-aiops","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:nutanix-aiops` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/nutanix-aiops before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-nutanix-aiops/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-nutanix-aiops/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-nutanix-aiops/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-nutanix-aiops/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-nutanix-aiops/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-nutanix-aiops/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T07:42:11.299Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-nutanix-aiops/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-nutanix-aiops/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-nutanix-aiops/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-nutanix-aiops/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T00:59:20.333Z","emptyReason":null},"readme":"Skill: nutanix-aiops\n\nOwner: zw008\n\nSummary: Use this skill whenever the user needs to operate a Nutanix estate through Prism Central (v4 REST API) — an estate/cluster health overview, cluster & host inventory and utilization, VM lifecycle across AHV and ESXi (list/get/power/create/update/clone/delete/migrate), storage containers, subnets/network, images & categories, data protection / DR (snapshots, recovery points, protection domains, VM protect, failover), alerts & events with alert RCA (analyze_alert), LCM firmware/software upgrades, capacity runway forecasting, and read-only diagnostics/RCA over the whole estate (cluster_health_rca, alert_triage_rca). Always use this skill for \"Nutanix\", \"Prism Central\", \"AHV\", \"cluster health\", \"list VMs\", \"power on/off a VM\", \"clone/migrate a VM\", \"delete a VM\", \"snapshot\", \"recovery point\", \"protection domain\", \"failover\", \"why did this alert fire\" / \"root cause this alert\", \"LCM upgrade / firmware\", \"days until storage is full\" / \"capacity runway\", \"what's wrong with my cluster\" / \"diagnose the estate\", \"triage my alerts\", when the context is a Nutanix cluster or Prism Central. Do NOT use when the target is a non-Nutanix platform — those belong to their own AIops-tools sibling; this skill is Prism Central v4 only. Governed Nutanix Prism Central operations with a built-in governance harness (audit, token budget, undo, descriptive risk-tier labels).\n\nTags: agent-skills:0.1.0, ai-ops:0.1.0, latest:0.11.4, mcp:0.1.0, nutanix:0.1.0, prism-central:0.1.0\n\nVersion history:\n\nv0.11.4 | 2026-09-16T23:26:16.071Z | auto\n\n- Removed the skill-card.md file.\n- Updated references/agent-guardrails.md.\n- No major user-facing changes to functionality.\n- Documentation or internal references update only.\n\nv0.11.3 | 2026-09-15T06:10:55.539Z | auto\n\n- Removed the skill-card.md file to streamline documentation.\n- No functional or behavioral changes to the skill itself.\n- Existing operations, features, and usage remain unchanged.\n\nv0.11.2 | 2026-09-12T14:34:29.100Z | auto\n\n- skill-card.md file removed.\n- SKILL.md updated to reference a new OpenClaw plugin source: `clawhub:@zw008/nutanix-aiops` (previously `@aiops-tools/nutanix-aiops`).\n- No functional or interface changes to the underlying skill described.\n- Documentation updated to reflect plugin registry/location change.\n\nv0.11.1 | 2026-09-12T10:19:20.395Z | auto\n\n- Added OpenClaw plugin installation instructions to documentation (SKILL.md).\n- Updated usage details for installing and working with the skill as an OpenClaw plugin.\n- Removed the skill-card.md file.\n- No changes to core functionality or interface.\n\nv0.11.0 | 2026-09-12T01:06:41.892Z | auto\n\n- Updated the skill metadata to require either \"nutanix-aiops\" or \"uvx\" in PATH, instead of only \"nutanix-aiops\"\n- Made \"NUTANIX_AIOPS_CONFIG\" and \"NUTANIX_AIOPS_MASTER_PASSWORD\" environment variables optional rather than required\n- Removed unused file: skill-card.md\n- No functional changes to tool behaviors or interfaces\n\nv0.10.0 | 2026-08-10T06:52:52.400Z | auto\n\n# nutanix-aiops 0.10.0 – Changelog\n\n- Removed the sample file: skill-card.md\n- No user-facing changes to skill features or functionality.\n\nv0.9.0 | 2026-08-03T05:54:03.780Z | auto\n\n- Removed the sample skill card file (skill-card.md) from the package.\n- No changes were made to functionality or user-facing features.\n- All existing operations and features remain unchanged.\n\nv0.8.0 | 2026-08-02T09:40:47.765Z | auto\n\nnutanix-aiops 0.8.0\n\n- Removed the file skill-card.md.\n- No changes to functionality or features.\n\nv0.7.0 | 2026-07-21T15:30:32.298Z | auto\n\nnutanix-aiops 0.7.0\n\n- Removed the sample file skill-card.md from the repository.\n- No feature or documentation changes; functionality and usage remain the same.\n\nv0.6.0 | 2026-07-21T09:42:14.282Z | auto\n\nnutanix-aiops 0.6.0\n\n- Governance harness revised: rule-based policy engine and risk gates removed in favor of descriptive audit/risk labels only; agent or connecting user now determines write operation access.\n- Documentation (SKILL.md) and setup guides updated to clarify governance scope, agent responsibilities, and operation annotations.\n- All mentions of required approval environment variables removed; approvals/annotations are now always optional.\n- One documentation file (skill-card.md) deleted for improved clarity and to prevent duplication.\n\nv0.5.0 | 2026-07-20T11:16:34.938Z | auto\n\n- Updated agent guardrails and capabilities documentation for improved clarity and accuracy.\n- Removed the deprecated skill-card.md file.\n- No changes to core functionality or user-facing features in this release.\n\nv0.4.0 | 2026-07-19T03:52:33.128Z | auto\n\nVersion 0.4.0\n\n- Added new diagnostics and RCA tools: cluster_health_rca and alert_triage_rca.\n- Expanded total toolset to 51 (from 47), increasing coverage for diagnostics, undo, and estate triage.\n- Introduced undo_list and undo_apply for reversible actions.\n- Added a dedicated agent guardrails documentation file.\n- Updated references and documentation for clarity on new features and use cases.\n- Removed deprecated skill-card.md documentation.\n\nv0.3.0 | 2026-07-17T05:55:06.473Z | auto\n\nnutanix-aiops 0.3.0\n\n- Removed the file skill-card.md.\n- No other functional or user-facing changes.\n\nv0.2.0 | 2026-07-13T13:08:14.931Z | auto\n\nnutanix-aiops v0.2.0\n\n- Introduced secure-by-default mode: without a rules.yaml, high/critical operations require an explicit approver via NUTANIX_AUDIT_APPROVED_BY and rationale.\n- nutanix-aiops init now seeds a starter rules.yaml for operator policy.\n- Updated documentation reflecting stronger security defaults and governance.\n- Removed obsolete skill-card.md file.\n\nv0.1.0 | 2026-07-12T06:57:45.738Z | auto\n\nNutanix AIops skill preview release.\n\n- Enables governed Nutanix Prism Central (v4 REST API) operations from cluster health to VM lifecycle, storage, network, DR, upgrades, and capacity forecasting.\n- Comprehensive governance harness: local audit log, policy engine, risk-tier gates, undo/rollback records, double-confirm on destructive ops.\n- Secure credential handling: encrypted password store, master password unlock, support for non-interactive/CI workflows.\n- Full support for AHV and ESXi VMs; all tools handle pagination and ETag/If-Match automatically on mutations.\n- 47 tools included: 21 read-only, 26 write (all writes audited and risk-gated).\n- PREVIEW: Not yet tested against live Prism Central—mock-validated only.\n\nArchive index:\n\nArchive v0.11.4: 7 files, 19285 bytes\n\nFiles: references/agent-guardrails.md (9921b), references/capabilities.md (9075b), references/cli-reference.md (3528b), references/setup-guide.md (3988b), skill-card.md (2631b), SKILL.md (13165b), _meta.json (133b)\n\nFile v0.11.4:SKILL.md\n\n---\nname: nutanix-aiops\nslug: nutanix-aiops\ndisplayName: \"Nutanix AIops\"\nsummary: \"Governed Nutanix Prism Central v4 ops: clusters/VMs/storage/DR/LCM/RCA, ETag-safe, 51 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Nutanix-AIops\ntags: [aiops, mcp, governance, nutanix]\ndescription: >\n  Use this skill whenever the user needs to operate a Nutanix estate through Prism Central (v4 REST API) — an estate/cluster health overview, cluster & host inventory and utilization, VM lifecycle across AHV and ESXi (list/get/power/create/update/clone/delete/migrate), storage containers, subnets/network, images & categories, data protection / DR (snapshots, recovery points, protection domains, VM protect, failover), alerts & events with alert RCA (analyze_alert), LCM firmware/software upgrades, capacity runway forecasting, and read-only diagnostics/RCA over the whole estate (cluster_health_rca, alert_triage_rca).\n  Always use this skill for \"Nutanix\", \"Prism Central\", \"AHV\", \"cluster health\", \"list VMs\", \"power on/off a VM\", \"clone/migrate a VM\", \"delete a VM\", \"snapshot\", \"recovery point\", \"protection domain\", \"failover\", \"why did this alert fire\" / \"root cause this alert\", \"LCM upgrade / firmware\", \"days until storage is full\" / \"capacity runway\", \"what's wrong with my cluster\" / \"diagnose the estate\", \"triage my alerts\", when the context is a Nutanix cluster or Prism Central.\n  Do NOT use when the target is a non-Nutanix platform — those belong to their own AIops-tools sibling; this skill is Prism Central v4 only.\n  Governed Nutanix Prism Central operations with a built-in governance harness (audit, token budget, undo, descriptive risk-tier labels).\ninstaller:\n  kind: uv\n  package: nutanix-aiops\nargument-hint: \"[VM/cluster extId or describe your Nutanix task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"nutanix-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"NUTANIX_AIOPS_CONFIG\",\"NUTANIX_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Nutanix-AIops\",\"emoji\":\"🧊\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed Nutanix Prism Central operations. The governance harness (audit, token/runaway budget, undo, descriptive risk-tier labels) is bundled in the package — no external skill-family dependency.\n  Connects to Prism Central on HTTPS :9440 with HTTP Basic auth (username + password). The v4 REST API requires an ETag/If-Match on every mutation; nutanix-aiops fetches and sends it automatically. All list tools paginate automatically; vm_list returns both AHV and ESXi VMs.\n  All write operations are audited to a local SQLite DB under ~/.nutanix-aiops/ (relocatable via NUTANIX_AIOPS_HOME).\n  Credentials: the Prism Central password is stored ENCRYPTED in ~/.nutanix-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'nutanix-aiops init' to onboard, or 'nutanix-aiops secret set <target>' to add one. The store is unlocked by a master password from NUTANIX_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var NUTANIX_<TARGET_NAME_UPPER>_PASSWORD is still honoured as a fallback with a deprecation warning (migrate with 'nutanix-aiops secret migrate'). The account needs REST API rights, not just Web UI access.\n  State-changing operations require the @governed_tool decorator (budget guard + audit + risk-tier tagging). The skill does not decide whether a write is permitted — that is the agent's judgement or the connecting account's permissions. High-risk ops (vm_delete, vm_migrate, storage_container_delete, subnet_delete, snapshot_delete, snapshot_restore, pd_failover, image_delete, lcm_update) support dry_run and, at the CLI, double confirmation; reversible writes record an undo descriptor (vm_update → prior CPU/memory, vm_migrate → prior host).\n  NUTANIX_AUDIT_APPROVED_BY and NUTANIX_AUDIT_RATIONALE are optional annotations recorded on the audit row (who/why); they are never required and never block a call.\n  SSL: verify_ssl defaults to true; disable only for self-signed lab / Community Edition certificates.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Validation status: behaviour is currently validated against mocked v4 REST responses; the LCM update, PD failover, and ESXi-VM listing paths in particular still need live verification (self-testable free on Nutanix Community Edition + X-Small Prism Central). See docs/VERIFICATION.md in the repo for the live-verification checklist.\n---\n\n# Nutanix AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by Nutanix.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/Nutanix-AIops](https://github.com/AIops-tools/Nutanix-AIops) under the MIT license.\n\nGoverned Nutanix **Prism Central (v4 REST API)** operations — **51 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.nutanix-aiops/`, token/runaway budget guard, undo-token recording, and descriptive risk-tier labels. The Prism Central password is stored **encrypted** (`~/.nutanix-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk.\n\n**What sets it apart** from read-only Nutanix MCPs: (1) automatic **ETag / If-Match** on every mutation — the v4 footgun handled for you; (2) automatic **pagination**; (3) **mixed-hypervisor** VM listing (AHV + ESXi, relevant to hypervisor-migration estates); and (4) the governance harness with **dry-run + double-confirm** on destructive writes.\n\n> **Standalone**: the governance harness is bundled in the package (`nutanix_aiops.governance`) — no external skill-family dependency.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read / Write |\n|-------|-------|:-----:|:------------:|\n| **Clusters** | cluster_list, cluster_health, host_list, cluster_utilization | 4 | 4 read |\n| **VMs** | list, get, power_on, guest_shutdown, power_off, reboot, create, update, clone, delete, migrate | 11 | 2 read · 9 write |\n| **Storage** | container list / create / update / delete | 4 | 1 read · 3 write |\n| **Network** | subnet list / get / create / delete | 4 | 2 read · 2 write |\n| **Catalog** | image list / delete, category list / create / assign | 5 | 2 read · 3 write |\n| **Data protection / DR** | snapshot list/create/delete/restore, recovery_point_list, protection_domain_list, vm_protect, pd_failover | 8 | 3 read · 5 write |\n| **Alerts** | alert_list, event_list, audit_list, **analyze_alert (RCA)**, alert_acknowledge, alert_resolve | 6 | 4 read · 2 write |\n| **LCM (upgrades)** | lcm_inventory, lcm_precheck, lcm_update | 3 | 1 read · 2 write |\n| **Capacity** | task_list, capacity_runway | 2 | 2 read |\n| **Diagnostics / RCA** | **cluster_health_rca**, **alert_triage_rca** | 2 | 2 read |\n| **Undo** | `undo_list`, `undo_apply` | 2 | 1 read · 1 write |\n| **Total** | | **51** | 24 read · 27 write |\n\nThe CLI is a convenience subset; the full 51-tool surface is via the MCP server. See `references/capabilities.md` for the tool → API-path → returns map.\n\n## Quick Install\n\n```bash\nuv tool install nutanix-aiops\nnutanix-aiops init       # interactive wizard: PC host/port 9440/username + encrypted password\nnutanix-aiops doctor     # connectivity + REST-RBAC preflight\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/nutanix-aiops\nopenclaw skills info nutanix-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Diagnose the estate in one shot (`diagnose cluster-health`): degraded resiliency, storage pools/containers over 80% / 90%, nodes down or missing — worst-first, each finding citing the measured number\n- Triage the alert backlog (`diagnose alert-triage`): per-severity counts, unacknowledged criticals, the oldest unresolved alert and its age\n- Inspect the estate (`overview`, `cluster health`, `cluster util`): clusters, hosts, resiliency, utilization\n- VM lifecycle across **AHV + ESXi** (`vm list/get/power/create/update/clone`), and guarded destructive ops (`vm delete`, `vm migrate`) with dry-run + double-confirm\n- Root-cause an alert (`analyze_alert`) — correlate it with related events into a probable-cause + suggested-actions summary\n- Data protection: snapshots, recovery points, protection domains, `vm_protect`, `pd_failover`\n- Upgrades (`lcm_inventory` → `lcm_precheck` → `lcm_update`) and capacity forecasting (`capacity_runway`)\n\n**Do NOT use when** the target is a non-Nutanix platform — this skill is Prism Central v4 only. For other infrastructure, use the appropriate **other AIops-tools** sibling.\n\n## Common Workflows\n\n### \"Something is wrong with the estate\" → diagnose, then act\n\n1. `nutanix-aiops diagnose cluster-health` → worst-first findings, e.g.\n   `critical · prod-cluster · storage container near full · 93.0% used >= 90.0% threshold`\n2. `storage_container_list` → confirm which container it is and what its\n   `maxCapacityBytes` / `logicalUsageBytes` actually are\n3. `recovery_point_list` / `snapshot_list <vm_ext_id>` → the usual culprit is\n   snapshot sprawl in that container\n4. `snapshot_delete <…> --dry-run` to preview, then re-run to reclaim space —\n   optionally set `NUTANIX_AUDIT_APPROVED_BY` first to annotate who authorized\n   it; each deletion is audited and records an undo descriptor\n5. Re-run `diagnose cluster-health` → the finding should drop below the 80%\n   warning threshold; the before/after percentages are your evidence\n\n### Triage a cluster alert (RCA)\n\n1. `nutanix-aiops diagnose alert-triage` (or `alert_list`) → per-severity counts and the oldest unresolved alert, so you know which extId to open first\n2. `analyze_alert <alert_ext_id>` → probable cause + suggested actions, built by correlating the alert with related `event_list` records\n3. Confirm blast radius with `cluster_health` / `cluster_utilization`, then `alert_acknowledge` (or `alert_resolve` once fixed)\n\n### Safely delete a VM (high-risk, audited)\n\n1. `vm_get <vm_ext_id>` → confirm it's the right VM (and see its ETag)\n2. `nutanix-aiops vm delete <vm_ext_id> --dry-run` → preview the exact `DELETE` call\n3. Optionally annotate who/why: `export NUTANIX_AUDIT_APPROVED_BY=… NUTANIX_AUDIT_RATIONALE=…`\n4. Re-run without `--dry-run` (double-confirm at the CLI); the call is audited with\n   tier and any approver/rationale supplied\n\n### Snapshot sprawl cleanup\n\n1. `recovery_point_list` (or per-VM `snapshot_list <vm_ext_id>`) → find stale / redundant snapshots\n2. `snapshot_delete <…> --dry-run` on each candidate → preview\n3. Re-run without dry-run (HIGH risk, double-confirm at the CLI) to reclaim space; each deletion is audited\n\n### Capacity runway\n\n1. `cluster_utilization <cluster_ext_id>` → current CPU / memory / storage / IOPS\n2. `capacity_runway` → days-to-full forecast per resource; use it to schedule an `lcm` expansion or storage add before you hit the wall\n\n### Migrate a VM to another host (reversible)\n\n1. `host_list` → pick the destination host extId\n2. `nutanix-aiops vm migrate <vm_ext_id> <target_host_ext_id> --dry-run` → preview\n3. Re-run without dry-run (HIGH, double-confirm); the **prior host is captured as an undo descriptor** so a regression can be reversed\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide whether a write is\npermitted. That is your agent's judgement, or the permission of the account you connect it with\n(connect with a Prism Central account holding only a read-only (Viewer) role — writes then fail\nat the server). There is no read-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.nutanix-aiops/audit.db` (relocatable via `NUTANIX_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- `NUTANIX_AUDIT_APPROVED_BY` / `NUTANIX_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `NUTANIX_RUNAWAY_MAX=0`.\n- Every mutation auto-handles **ETag / If-Match**; every list auto-paginates.\n- Destructive writes support `dry_run` / `--dry-run` and, at the CLI, double confirmation.\n- Reversible writes record an undo descriptor (`vm_update` → prior CPU/memory, `vm_migrate` → prior host).\n\n## References\n\n- `references/capabilities.md` — full 51-tool + API-path reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, REST-RBAC, CE self-test\n- `references/agent-guardrails.md` — which guardrails the harness enforces for you, and a ready-to-paste system prompt for smaller / local models\n</content>\n\nFile v0.11.4:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"nutanix-aiops\",\n  \"version\": \"0.11.4\",\n  \"publishedAt\": 1789601176071\n}\n\nFile v0.11.4:references/agent-guardrails.md\n\n# Agent guardrails — running nutanix-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## What the tool now enforces — do not waste prompt budget on these\n\nAuthorization is not this tool's job — decide it via the account you connect it\nwith, or the agent's own prompt. What the harness does guarantee:\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Fetch the ETag before you change anything\" | Prism Central v4 requires an `If-Match` ETag on most mutations (optimistic concurrency). Every write tool fetches the entity's current ETag itself and sends it back. There is **no ETag parameter for the model to get wrong**, and no read it must remember to run first. |\n| \"Don't invent a value when a field is missing\" | A field Prism Central did not return comes back as `null`, never as `\"\"`. Absent and empty are distinguishable in the payload — which matters here, because v4 omits a great many fields (`description`, `hypervisorType`, host and cluster names, LCM version strings, alert `impactType`). |\n| \"Tell me if the output was cut off\" | Every list tool returns `{\"<items>\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is **measured** (one extra row is fetched), not guessed from a length coincidence. `vm_list`, `cluster_list`, `host_list`, `alert_list`, `event_list`, `audit_list`, `task_list`, `image_list`, `category_list`, `subnet_list`, `snapshot_list`, `recovery_point_list`, `protection_domain_list`, `storage_container_list`, `lcm_inventory` and `undo_list` all take a `limit` and report against it. |\n| \"Preserve the ordering / tell me what's most urgent\" | `cluster_health_rca` and `alert_triage_rca` findings carry an explicit 1-based `rank`, worst-first. Priority is in the payload, not implied by list position, and every finding cites the measured percentage or the raw Prism state string that tripped it. |\n| \"Confirm before anything destructive\" | Destructive tools (`vm_delete`, `vm_migrate`, `snapshot_delete`, `snapshot_restore`, `image_delete`, `subnet_delete`, `storage_container_delete`, `lcm_update`, `pd_failover`) take `dry_run=True` for a preview and are `risk=high`, tagged `review` on the audit row. ⚠️ **The CLI double confirmation exists only for `vm_delete` and `vm_migrate`** — the other seven have no CLI command and are reachable only over MCP, where nothing prompts. Keep your own confirmation for those. |\n| \"Run the LCM precheck before upgrading\" | `lcm_update` **refuses** unless you hand back the `taskExtId` from `lcm_precheck` as `precheck_task_ext_id` and that task reached `SUCCEEDED`. The `dry_run` preview enforces it too, so a preview can never promise an upgrade the real call would refuse. The ordering is a guarantee, not a suggestion the model can skip. |\n| \"Undo it if it goes wrong\" | Reversible writes record an inverse descriptor capturing the **prior** state (power state, CPU/memory, capacity/RF, source host). `undo_list` shows them; `undo_apply` replays one through the same governed path. Irreversible deletes still record what was there: `subnet_delete` captures the subnet's name, description, type, VLAN id, cluster and IP config/pools, so a wrongly deleted subnet can be rebuilt by hand from the audit row. |\n| \"Log what you did\" | Every call is audited to `~/.nutanix-aiops/audit.db` regardless of what the model says it did (relocatable via `NUTANIX_AIOPS_HOME`). |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate a Nutanix Prism Central (v4) environment through the nutanix-aiops\nMCP tools.\n\nTOOL USE\n- Before answering any question about the current Nutanix environment, you MUST\n  call a tool. Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nIDENTIFIERS\n- Every entity is identified by an opaque extId (a UUID). Copy an extId verbatim\n  from a tool result. Never retype, abbreviate, reformat, or reconstruct one.\n- extIds are NOT interchangeable by type. A VM extId, a cluster extId, a host\n  extId, a subnet extId, a storage-container extId, a recovery-point extId and\n  a task extId are different namespaces that look identical. Passing a cluster\n  extId where a VM extId is wanted is the single most common failure here.\n- Call cluster_list first — most other tools need a clusterExtId from it, and\n  vm_list / host_list give you the VM and host extIds.\n\nREADING RESULTS\n- Read the whole result before concluding. If a result has \"truncated\": true,\n  say so and re-run with a higher limit instead of treating the partial result\n  as complete.\n- A null field means Prism Central did not return that value. Report it as \"not\n  available\" — never infer it.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  power states, severities, fault-tolerance states, or extIds.\n- When a cluster_health_rca or alert_triage_rca result has findings, work in\n  \"rank\" order and cite the measured number in each finding's \"detail\".\n\nWRITES\n- Run the dry_run=True form of a destructive tool and show the operator what it\n  would change before running it for real.\n- Async writes return a task extId, not a result. Poll task_list for its status\n  rather than assuming the operation finished.\n\n- Only `vm_delete` and `vm_migrate` have CLI commands. The other seven destructive tools\n  are MCP-only and nothing will ask you to confirm them: call with `dry_run=True` first,\n  show the operator what would change, and wait for an explicit go-ahead.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a capacity, resiliency, or performance problem unless a tool\n  result supports it.\n- Do not add generic advice that does not follow from the tool output.\n```\n\n## Nutanix-specific notes\n\n- **AHV and ESXi VMs are both visible, and they are not equivalent.** Prism\n  Central sees ESXi-backed VMs in a hypervisor-migration estate, so `vm_list`\n  returns them by default and the `hypervisor` field distinguishes them. AHV-only\n  operations (snapshot create/restore via the AHV VM API, live migrate to a\n  target AHV host) will fail against an ESXi-managed VM. Pass\n  `include_esxi=false` to `vm_list` when you only want VMs the AHV lifecycle\n  tools can act on, and check the `hypervisor` field before proposing a write.\n- **ETags are handled for you.** v4 mutations use `If-Match` for optimistic\n  concurrency. `vm_get` and `subnet_get` surface the current `_etag` if you want\n  it, but no write tool asks for one — do not prompt the model to fetch it, and\n  do not treat a missing ETag as a blocker.\n- **Writes are asynchronous.** Most v4 mutations return a task extId\n  (`taskExtId`) rather than the finished entity. A snapshot may not exist the\n  instant `snapshot_create` returns — the tool resolves the real snapshot extId\n  best-effort, and honestly records no undo when it could not.\n- **`snapshot_restore` and `pd_failover` are not undoable.** A revert overwrites\n  the VM's current state and a failover is a DR event. Both declare no inverse\n  rather than pretending to one.\n- **Storage headroom is not the same as free space.** Nutanix reserves capacity\n  to rebuild after a node or disk failure, which is why `cluster_health_rca`\n  flags containers and pools at 80% (warning) / 90% (critical) rather than\n  waiting for full.\n\n## Recommended setup for a local model\n\nAuthorization is not this tool's job, so enforce it where it actually belongs:\nconnect with a Prism Central account holding only a read-only (Viewer) role\nuntil you trust the setup — writes then fail at the server, not at a switch in\nthis tool.\n\n```bash\nnutanix-aiops doctor\n```\n\nThen, when you are ready to allow writes, point the account at a role with the\nwrite permissions it needs, and optionally set an approver so the audit trail\ncarries an accountable name:\n\n```bash\nexport NUTANIX_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport NUTANIX_AUDIT_RATIONALE=\"scheduled maintenance window 2026-07-20\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **Multi-tool workflows time out or drift.** Prefer `cluster_health_rca`,\n  `alert_triage_rca` and `analyze_alert` — each does the multi-step correlation\n  inside one call, so the model does not have to chain reads and keep extIds\n  straight across turns.\n- **The model mixes up extIds.** Ask for one entity type at a time, and use\n  `overview` first to orient before drilling in.\n- **The model ignores later tool results in a long context.** Ask narrower\n  questions and use `limit` deliberately rather than pulling whole inventories.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Nutanix-AIops](https://github.com/AIops-tools/Nutanix-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.4:references/capabilities.md\n\n# nutanix-aiops capabilities\n\n> **51 MCP tools** (24 read, 27 write) over the Nutanix\n> **Prism Central v4 REST API** (HTTPS :9440, HTTP Basic auth). Every mutation\n> handles **ETag / If-Match** automatically; every list is **paginated**\n> automatically. Paths below are the v4 API prefixes actually called; validate\n> against a live Prism Central / Community Edition before production use.\n\n## Clusters (4 read)\n\n| Tool | API path | Returns |\n|------|----------|---------|\n| `cluster_list` | `GET /api/clustermgmt/v4.0/config/clusters` | extId, name, AOS version, hypervisors, node count |\n| `cluster_health` | `GET /api/clustermgmt/v4.0/config/clusters/{extId}` | services, resiliency / fault-tolerance, upgrade state |\n| `host_list` | `GET /api/clustermgmt/v4.0/config/hosts` | host extId, cluster, hypervisor, CPU / memory |\n| `cluster_utilization` | `GET /api/clustermgmt/v4.0/config/clusters/{extId}` | point-in-time CPU / memory / storage / IOPS |\n\n## VMs (2 read, 9 write) — base `GET /api/vmm/v4.0/ahv/config/vms`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `vm_list` | read | `GET …/vms` (paginated) | VMs across **AHV + ESXi** (extId, name, cluster, power, vCPU, mem, hypervisor) |\n| `vm_get` | read | `GET …/vms/{extId}` | one VM, **surfaces its ETag** for downstream mutations |\n| `vm_power_on` | write · low | `POST …/vms/{extId}/$actions/power-on` | task ref |\n| `vm_guest_shutdown` | write · med | `POST …/vms/{extId}/$actions/shutdown` | graceful guest shutdown |\n| `vm_power_off` | write · med | `POST …/vms/{extId}/$actions/power-off` | hard power off |\n| `vm_reboot` | write · med | `POST …/vms/{extId}/$actions/reboot` | task ref |\n| `vm_create` | write · med | `POST …/vms` | new VM extId |\n| `vm_update` | write · med | `PUT …/vms/{extId}` (If-Match) | **undo captures prior CPU / memory** |\n| `vm_clone` | write · med | `POST …/vms/{extId}/$actions/clone` | clone extId |\n| `vm_delete` | write · **HIGH** | `DELETE …/vms/{extId}` | **dry_run**; double-confirm at CLI |\n| `vm_migrate` | write · **HIGH** | `POST …/vms/{extId}/$actions/migrate` | **dry_run**; **undo → prior host** |\n\n## Storage (1 read, 3 write) — base `GET /api/clustermgmt/v4.0/config/storage-containers`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `storage_container_list` | read | `GET …/storage-containers` | extId, name, cluster, capacity, usage |\n| `storage_container_create` | write · med | `POST …/storage-containers` | new container extId |\n| `storage_container_update` | write · med | `PUT …/storage-containers/{extId}` (If-Match) | **undo captures prior config** |\n| `storage_container_delete` | write · **HIGH** | `DELETE …/storage-containers/{extId}` | **dry_run** |\n\n## Network (2 read, 2 write) — base `GET /api/networking/v4.0/config/subnets`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `subnet_list` | read | `GET …/subnets` | extId, name, type, VLAN, IP config |\n| `subnet_get` | read | `GET …/subnets/{extId}` | one subnet, **surfaces ETag** |\n| `subnet_create` | write · med | `POST …/subnets` | new subnet extId |\n| `subnet_delete` | write · **HIGH** | `DELETE …/subnets/{extId}` | **dry_run** |\n\n## Catalog (2 read, 3 write)\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `image_list` | read | `GET /api/vmm/v4.0/content/images` | image extId, name, type, size |\n| `image_delete` | write · **HIGH** | `DELETE /api/vmm/v4.0/content/images/{extId}` | **dry_run** |\n| `category_list` | read | `GET /api/prism/v4.0/config/categories` | key, value, extId |\n| `category_create` | write · low | `POST /api/prism/v4.0/config/categories` | new category extId |\n| `category_assign` | write · med | `POST …/categories/{extId}/$actions/associate` | **bulk-assign** a category to many VMs |\n\n## Data protection / DR (3 read, 5 write)\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `snapshot_list` | read | `GET …/vms/{extId}` recovery points | per-VM snapshots (extId, name, created) |\n| `recovery_point_list` | read | `GET /api/dataprotection/v4.0/config/recovery-points` | recovery points across estate |\n| `protection_domain_list` | read | `GET /api/dataprotection/v4.0/config/protection-policies` | protection policies / domains |\n| `snapshot_create` | write · low | `POST …/vms/{extId}` recovery point | new snapshot extId |\n| `snapshot_delete` | write · **HIGH** | `DELETE …/recovery-points/{extId}` | **dry_run** |\n| `snapshot_restore` | write · **HIGH** | `POST …/$actions/restore` | **dry_run** |\n| `vm_protect` | write · med | `POST …/protection-policies` associate | attach a VM to a protection policy |\n| `pd_failover` | write · **HIGH** | `POST …/$actions/failover` | **dry_run** |\n\n## Alerts (4 read, 2 write)\n\n| Tool | Risk | API path | Returns |\n|------|------|----------|---------|\n| `alert_list` | read | `GET /api/monitoring/v4.0/serviceability/alerts` | active alerts (severity, impact, source) |\n| `event_list` | read | `GET /api/monitoring/v4.0/serviceability/events` | recent events |\n| `audit_list` | read | `GET /api/prism/v4.0/config/audits` | Prism audit records |\n| `analyze_alert` | read | correlates alert + related events | **RCA (flagship read)** — probable cause + suggested actions |\n| `alert_acknowledge` | write · low | `POST …/alerts/{extId}/$actions/acknowledge` | ack a live alert |\n| `alert_resolve` | write · low | `POST …/alerts/{extId}/$actions/resolve` | resolve a live alert |\n\n## LCM — upgrades (1 read, 2 write)\n\n| Tool | Risk | API path | Returns |\n|------|------|----------|---------|\n| `lcm_inventory` | read | `GET /api/lifecycle/v4.0/resources/entities` | firmware / software entities + available versions |\n| `lcm_precheck` | write · medium | `POST /api/lifecycle/v4.0/resources/$actions/perform-precheck` | precheck task ref |\n| `lcm_update` | write · **HIGH** | `POST /api/lifecycle/v4.0/resources/$actions/perform-update` | **firmware/software update**; **dry_run**; **refused unless `precheck_task_ext_id` names a precheck task that reached SUCCEEDED** |\n\n## Capacity (2 read)\n\n| Tool | API path | Returns |\n|------|----------|---------|\n| `task_list` | `GET /api/prism/v4.0/config/tasks` | recent Prism tasks (status, entity, progress) |\n| `capacity_runway` | derived from cluster utilization | **days-to-full forecast** per resource |\n\n## Diagnostics / RCA (2 read)\n\nRead-only signature analyses (`risk_level=\"low\"`). Both are **pure and\ndeterministic** — no clock, no randomness — and every finding carries the\nmeasured number or raw Prism state that tripped it, alongside a probable cause\nand a concrete action. Findings are returned worst-first\n(critical → warning → info) with the shape\n`{severity, resource, signal, detail, cause, action}`.\n\n| Tool | API paths read | Returns |\n|------|----------------|---------|\n| `cluster_health_rca` | `clusters` + `clusters/{extId}` + `hosts` + `storage-containers` | findings for degraded `faultToleranceState`, cluster storage pool and storage containers over **80% (warning) / 90% (critical)**, hosts whose `nodeStatus` is unhealthy, and clusters with fewer visible hosts than their `nodeCount`; plus a `summary` of every measured percentage |\n| `alert_triage_rca` | `serviceability/alerts` | active (unresolved) alerts grouped by severity with a per-level count, unacknowledged criticals called out, and `oldestUnresolved` (title, severity, `ageDays`) — an alert open **≥ 7 days** is flagged stale |\n\n`alert_triage_rca` is the fleet-level lens; `analyze_alert` is the per-alert\nlens (event correlation on one alert's affected entity). They compose: triage\nfirst to pick the extId, then analyze it.\n\n## Undo (1 read, 1 write)\n\n| Tool | Risk | Returns / effect |\n|------|:----:|------------------|\n| `undo_list` | low | recorded, not-yet-applied reversible writes — `undoId`, original tool, inverse tool, note |\n| `undo_apply` | medium | executes a recorded inverse descriptor; itself governed and audited, single-use, supports `dry_run` |\n\n## ETag / pagination / mixed hypervisor\n\n- **ETag / If-Match** — the v4 API rejects an update or delete without the\n  current entity's ETag. Every mutation here fetches the ETag and sends\n  `If-Match` for you (the common v4 footgun); `vm_get` / `subnet_get` surface it\n  for inspection.\n- **Pagination** — all list tools follow `$page` / `$limit` and return the full\n  set, not just page one.\n- **Mixed hypervisor** — `vm_list` returns both **AHV** and **ESXi** VMs managed\n  by the same Prism Central (relevant to hypervisor-migration estates).\n\n## Out of scope (by design, this release)\n\n- IAM / users / roles / SAML, Files / Objects / Volumes services\n- Report generation, X-Play / playbooks, calm / self-service\n- Anything outside Prism Central v4 (direct Prism Element, ncli/acli)\n\nWant one of these? Open an issue or PR — feedback and contributions welcome.\n</content>\n</invoke>\n\nFile v0.11.4:references/cli-reference.md\n\n# nutanix-aiops CLI reference\n\n> Talks to Nutanix **Prism Central v4** on HTTPS `:9440`\n> with HTTP Basic auth. The CLI is a convenience subset; the full **51-tool**\n> surface is via the MCP server (`nutanix-aiops mcp`).\n\n## Setup & diagnostics\n\n```bash\nnutanix-aiops init                      # interactive onboarding wizard\nnutanix-aiops doctor [--skip-auth]      # config + secret store + connectivity + REST-RBAC preflight\nnutanix-aiops mcp                       # start the MCP server (stdio transport)\n```\n\n`doctor` checks the config file, the encrypted secret store and its permissions,\nthat a password is present per target, and (unless `--skip-auth`) connectivity\nplus a **REST-RBAC preflight** against Prism Central — confirming the account can\nactually call the v4 APIs, not just log in to the Web UI.\n\n## Estate & clusters (read)\n\n```bash\nnutanix-aiops overview [--target <t>]              # one-shot estate summary\nnutanix-aiops cluster list                         # registered clusters (extId, AOS, hypervisors, nodes)\nnutanix-aiops cluster health <cluster_ext_id>      # services, resiliency, upgrade state\nnutanix-aiops cluster hosts                         # hosts across all clusters\nnutanix-aiops cluster util <cluster_ext_id>        # CPU / memory / storage / IOPS utilization\n```\n\n## Diagnostics / RCA (read-only)\n\n```bash\nnutanix-aiops diagnose cluster-health              # resiliency, storage >80%/>90%, nodes down — worst first\nnutanix-aiops diagnose alert-triage                # active alerts by severity + oldest unresolved\n```\n\nBoth print a worst-first findings table (severity · resource · signal · detail ·\naction) or a green all-clear line when every measured value is under threshold.\n\n## VMs\n\n```bash\nnutanix-aiops vm list [--esxi | --no-esxi]         # AHV + ESXi VMs (ESXi included by default)\nnutanix-aiops vm get <vm_ext_id>                   # one VM detail (shows its ETag)\nnutanix-aiops vm power <vm_ext_id> <on|off|shutdown|reboot> [--dry-run]\nnutanix-aiops vm delete <vm_ext_id> [--dry-run]    # (HIGH) dry-run + double confirm\nnutanix-aiops vm migrate <vm_ext_id> <target_host_ext_id> [--dry-run]   # (HIGH) dry-run + double confirm\n```\n\n## Secrets (encrypted store `~/.nutanix-aiops/secrets.enc`)\n\n```bash\nnutanix-aiops secret set <target> [--value <pw>]   # store PC password (hidden prompt if no --value)\nnutanix-aiops secret list                           # names only — values never shown\nnutanix-aiops secret rm <target>\nnutanix-aiops secret migrate                        # import legacy plaintext env (NUTANIX_<T>_PASSWORD)\nnutanix-aiops secret rotate-password                # re-encrypt the store under a new master password\n```\n\n## Common options\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default / first target)\n- `--dry-run` — print the API call that would be made, change nothing\n- `--esxi / --no-esxi` — include or exclude ESXi-managed VMs in `vm list` (default: include)\n- Destructive commands (`vm delete`, `vm migrate`) require a `--dry-run` preview and **two confirmations**\n\n## Full surface via MCP\n\nThe 51 governed tools (clusters, VMs, storage, network, catalog, data\nprotection / DR, alerts + `analyze_alert` RCA, LCM upgrades, capacity runway,\nand the `cluster_health_rca` / `alert_triage_rca` diagnostics)\nare exposed by `nutanix-aiops mcp`. Set `NUTANIX_AIOPS_MASTER_PASSWORD` so the\nencrypted store unlocks non-interactively. See `capabilities.md` for the full\ntool → API-path → returns map.\n</content>\n\nFile v0.11.4:references/setup-guide.md\n\n# nutanix-aiops setup & security guide\n\n> Currently validated against mocked v4 REST responses; see `docs/VERIFICATION.md`\n> in the repo for the live-verification checklist.\n\n## 1. Install\n\n```bash\nuv tool install nutanix-aiops          # or: pipx install nutanix-aiops\n```\n\n## 2. Prepare a Prism Central account (with REST API rights)\n\nnutanix-aiops connects to **Prism Central** on HTTPS port **9440** and\nauthenticates the v4 REST APIs with **HTTP Basic auth** (username + password).\n\n> **Important gotcha:** the account needs **REST API** rights, not just Web UI\n> access. A user that can log into the Prism Central console may still be denied\n> at the API. Give the account a role with the v4 API permissions it needs\n> (read for the estate; the relevant lifecycle/VM/storage/DR permissions for any\n> writes). `nutanix-aiops doctor` runs a REST-RBAC preflight to catch this early.\n\n## 3. Onboard\n\n```bash\nnutanix-aiops init\n```\n\nThe wizard collects the (non-secret) connection details into\n`~/.nutanix-aiops/config.yaml` and stores the **password encrypted** into\n`~/.nutanix-aiops/secrets.enc`. Example config:\n\n```yaml\ntargets:\n  - name: pc1\n    host: 10.0.0.20        # Prism Central IP / FQDN\n    port: 9440\n    username: admin        # PC account with REST API rights\n    verify_ssl: false      # self-signed lab / CE certs only\n```\n\nThe `username` is not a secret and lives in the config file; the password lives\nonly in the encrypted store.\n\n## 4. Non-interactive use (MCP server / CI / cron)\n\nExport the master password so the encrypted store unlocks without a prompt:\n\n```bash\nexport NUTANIX_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n## Credential security\n\n- The Prism Central password is **never** written to disk in plaintext. It lives\n  only in `~/.nutanix-aiops/secrets.enc`, encrypted with Fernet (AES-128-CBC +\n  HMAC), the key derived from your master password via scrypt. Only a per-store\n  random salt and the ciphertext are on disk (chmod 600); the master password\n  itself is never stored.\n- A legacy plaintext env var `NUTANIX_<TARGET_NAME_UPPER>_PASSWORD` is still\n  honoured as a fallback with a deprecation warning — migrate with\n  `nutanix-aiops secret migrate`.\n- The password is held only in memory during a session and is never logged or\n  echoed; exception text and tracebacks are scrubbed of secret-shaped strings\n  before being written to the audit log.\n\n## Optional audit annotations\n\nThe skill does not decide whether a write is permitted — that is the agent's\njudgement, or the permission of the account you connect it with (connect with\na Prism Central account holding only a read-only (Viewer) role, and writes\nfail at the server). `NUTANIX_AUDIT_APPROVED_BY` / `NUTANIX_AUDIT_RATIONALE`\noptionally annotate the audit row with who authorized a high-risk operation\nand why — they are never required and never block a call:\n\n```bash\nexport NUTANIX_AUDIT_APPROVED_BY='alice@example.com'\nexport NUTANIX_AUDIT_RATIONALE='Decommissioning migrated ESXi guest per CHG-1234'\n```\n\n## Governance harness state\n\nState lives under `~/.nutanix-aiops/` (relocate with `NUTANIX_AIOPS_HOME`):\n\n- `audit.db` — every tool call (SQLite), with risk tier and any approver/rationale supplied\n- `undo.db` — inverse descriptors for reversible writes (e.g. `vm_update` prior\n  CPU/memory, `vm_migrate` prior host)\n- budget / runaway guard — caps cumulative tool calls and wall-time; trips on\n  tight poll/retry loops\n\n## Self-test for free (Community Edition)\n\nYou can validate end-to-end at no cost with **Nutanix Community Edition (CE)**:\na single-node CE cluster plus an **X-Small Prism Central** VM. Point a `pc1`\ntarget at that PC on `:9440` and run the read tools; exercise the writes against\nthrowaway VMs / snapshots.\n\n## Verify\n\n```bash\nnutanix-aiops doctor\n```\n\n`doctor` is the fastest live check — config, encrypted store + permissions, a\npassword per target, connectivity to Prism Central `:9440`, and the REST-RBAC\npreflight.\n</content>\n\nFile v0.11.4:skill-card.md\n\n## Description:\n\nGoverned Nutanix Prism Central v4 operations for estate health, cluster and VM lifecycle, storage, networking, data protection, alerts, LCM upgrades, capacity forecasting, and diagnostics/RCA.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nDevelopers, infrastructure operators, and SRE teams use this skill to inspect and operate Nutanix Prism Central v4 estates through governed CLI and MCP workflows. It supports read-only diagnosis as well as audited, dry-run-capable infrastructure changes when the connected account has suitable permissions.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can perform destructive Nutanix infrastructure changes when connected with a sufficiently privileged Prism Central account.\n\nMitigation: Start with a Viewer/read-only Prism Central account, require explicit operator approval before destructive MCP actions, and use dry-run previews before executing changes.\n\nRisk: The skill has no enforced read-only mode or built-in approval gate.\n\nMitigation: Use Prism Central role permissions as the authorization boundary and keep an external approval process for write and destructive operations.\n\nRisk: Credential exposure could grant broad access to Prism Central operations.\n\nMitigation: Keep the master password out of logs and shell history, prefer the encrypted secret store, and avoid privileged credentials until workflows are tested.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/zw008/skills/nutanix-aiops)\n- [Project Homepage](https://github.com/AIops-tools/Nutanix-AIops)\n- [capabilities.md](references/capabilities.md)\n- [cli-reference.md](references/cli-reference.md)\n- [setup-guide.md](references/setup-guide.md)\n- [agent-guardrails.md](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and structured operational guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May call governed Nutanix CLI or MCP tools that return text, tables, task identifiers, or JSON-like operational results.]\n\n## Skill Version(s):\n\n0.11.4 (source: server-resolved release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.3: 7 files, 19195 bytes\n\nFiles: references/agent-guardrails.md (9493b), references/capabilities.md (9075b), references/cli-reference.md (3528b), references/setup-guide.md (3988b), skill-card.md (2795b), SKILL.md (13165b), _meta.json (133b)\n\nFile v0.11.3:SKILL.md\n\n---\nname: nutanix-aiops\nslug: nutanix-aiops\ndisplayName: \"Nutanix AIops\"\nsummary: \"Governed Nutanix Prism Central v4 ops: clusters/VMs/storage/DR/LCM/RCA, ETag-safe, 51 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Nutanix-AIops\ntags: [aiops, mcp, governance, nutanix]\ndescription: >\n  Use this skill whenever the user needs to operate a Nutanix estate through Prism Central (v4 REST API) — an estate/cluster health overview, cluster & host inventory and utilization, VM lifecycle across AHV and ESXi (list/get/power/create/update/clone/delete/migrate), storage containers, subnets/network, images & categories, data protection / DR (snapshots, recovery points, protection domains, VM protect, failover), alerts & events with alert RCA (analyze_alert), LCM firmware/software upgrades, capacity runway forecasting, and read-only diagnostics/RCA over the whole estate (cluster_health_rca, alert_triage_rca).\n  Always use this skill for \"Nutanix\", \"Prism Central\", \"AHV\", \"cluster health\", \"list VMs\", \"power on/off a VM\", \"clone/migrate a VM\", \"delete a VM\", \"snapshot\", \"recovery point\", \"protection domain\", \"failover\", \"why did this alert fire\" / \"root cause this alert\", \"LCM upgrade / firmware\", \"days until storage is full\" / \"capacity runway\", \"what's wrong with my cluster\" / \"diagnose the estate\", \"triage my alerts\", when the context is a Nutanix cluster or Prism Central.\n  Do NOT use when the target is a non-Nutanix platform — those belong to their own AIops-tools sibling; this skill is Prism Central v4 only.\n  Governed Nutanix Prism Central operations with a built-in governance harness (audit, token budget, undo, descriptive risk-tier labels).\ninstaller:\n  kind: uv\n  package: nutanix-aiops\nargument-hint: \"[VM/cluster extId or describe your Nutanix task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"nutanix-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"NUTANIX_AIOPS_CONFIG\",\"NUTANIX_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Nutanix-AIops\",\"emoji\":\"🧊\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed Nutanix Prism Central operations. The governance harness (audit, token/runaway budget, undo, descriptive risk-tier labels) is bundled in the package — no external skill-family dependency.\n  Connects to Prism Central on HTTPS :9440 with HTTP Basic auth (username + password). The v4 REST API requires an ETag/If-Match on every mutation; nutanix-aiops fetches and sends it automatically. All list tools paginate automatically; vm_list returns both AHV and ESXi VMs.\n  All write operations are audited to a local SQLite DB under ~/.nutanix-aiops/ (relocatable via NUTANIX_AIOPS_HOME).\n  Credentials: the Prism Central password is stored ENCRYPTED in ~/.nutanix-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'nutanix-aiops init' to onboard, or 'nutanix-aiops secret set <target>' to add one. The store is unlocked by a master password from NUTANIX_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var NUTANIX_<TARGET_NAME_UPPER>_PASSWORD is still honoured as a fallback with a deprecation warning (migrate with 'nutanix-aiops secret migrate'). The account needs REST API rights, not just Web UI access.\n  State-changing operations require the @governed_tool decorator (budget guard + audit + risk-tier tagging). The skill does not decide whether a write is permitted — that is the agent's judgement or the connecting account's permissions. High-risk ops (vm_delete, vm_migrate, storage_container_delete, subnet_delete, snapshot_delete, snapshot_restore, pd_failover, image_delete, lcm_update) support dry_run and, at the CLI, double confirmation; reversible writes record an undo descriptor (vm_update → prior CPU/memory, vm_migrate → prior host).\n  NUTANIX_AUDIT_APPROVED_BY and NUTANIX_AUDIT_RATIONALE are optional annotations recorded on the audit row (who/why); they are never required and never block a call.\n  SSL: verify_ssl defaults to true; disable only for self-signed lab / Community Edition certificates.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Validation status: behaviour is currently validated against mocked v4 REST responses; the LCM update, PD failover, and ESXi-VM listing paths in particular still need live verification (self-testable free on Nutanix Community Edition + X-Small Prism Central). See docs/VERIFICATION.md in the repo for the live-verification checklist.\n---\n\n# Nutanix AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by Nutanix.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/Nutanix-AIops](https://github.com/AIops-tools/Nutanix-AIops) under the MIT license.\n\nGoverned Nutanix **Prism Central (v4 REST API)** operations — **51 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.nutanix-aiops/`, token/runaway budget guard, undo-token recording, and descriptive risk-tier labels. The Prism Central password is stored **encrypted** (`~/.nutanix-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk.\n\n**What sets it apart** from read-only Nutanix MCPs: (1) automatic **ETag / If-Match** on every mutation — the v4 footgun handled for you; (2) automatic **pagination**; (3) **mixed-hypervisor** VM listing (AHV + ESXi, relevant to hypervisor-migration estates); and (4) the governance harness with **dry-run + double-confirm** on destructive writes.\n\n> **Standalone**: the governance harness is bundled in the package (`nutanix_aiops.governance`) — no external skill-family dependency.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read / Write |\n|-------|-------|:-----:|:------------:|\n| **Clusters** | cluster_list, cluster_health, host_list, cluster_utilization | 4 | 4 read |\n| **VMs** | list, get, power_on, guest_shutdown, power_off, reboot, create, update, clone, delete, migrate | 11 | 2 read · 9 write |\n| **Storage** | container list / create / update / delete | 4 | 1 read · 3 write |\n| **Network** | subnet list / get / create / delete | 4 | 2 read · 2 write |\n| **Catalog** | image list / delete, category list / create / assign | 5 | 2 read · 3 write |\n| **Data protection / DR** | snapshot list/create/delete/restore, recovery_point_list, protection_domain_list, vm_protect, pd_failover | 8 | 3 read · 5 write |\n| **Alerts** | alert_list, event_list, audit_list, **analyze_alert (RCA)**, alert_acknowledge, alert_resolve | 6 | 4 read · 2 write |\n| **LCM (upgrades)** | lcm_inventory, lcm_precheck, lcm_update | 3 | 1 read · 2 write |\n| **Capacity** | task_list, capacity_runway | 2 | 2 read |\n| **Diagnostics / RCA** | **cluster_health_rca**, **alert_triage_rca** | 2 | 2 read |\n| **Undo** | `undo_list`, `undo_apply` | 2 | 1 read · 1 write |\n| **Total** | | **51** | 24 read · 27 write |\n\nThe CLI is a convenience subset; the full 51-tool surface is via the MCP server. See `references/capabilities.md` for the tool → API-path → returns map.\n\n## Quick Install\n\n```bash\nuv tool install nutanix-aiops\nnutanix-aiops init       # interactive wizard: PC host/port 9440/username + encrypted password\nnutanix-aiops doctor     # connectivity + REST-RBAC preflight\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/nutanix-aiops\nopenclaw skills info nutanix-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Diagnose the estate in one shot (`diagnose cluster-health`): degraded resiliency, storage pools/containers over 80% / 90%, nodes down or missing — worst-first, each finding citing the measured number\n- Triage the alert backlog (`diagnose alert-triage`): per-severity counts, unacknowledged criticals, the oldest unresolved alert and its age\n- Inspect the estate (`overview`, `cluster health`, `cluster util`): clusters, hosts, resiliency, utilization\n- VM lifecycle across **AHV + ESXi** (`vm list/get/power/create/update/clone`), and guarded destructive ops (`vm delete`, `vm migrate`) with dry-run + double-confirm\n- Root-cause an alert (`analyze_alert`) — correlate it with related events into a probable-cause + suggested-actions summary\n- Data protection: snapshots, recovery points, protection domains, `vm_protect`, `pd_failover`\n- Upgrades (`lcm_inventory` → `lcm_precheck` → `lcm_update`) and capacity forecasting (`capacity_runway`)\n\n**Do NOT use when** the target is a non-Nutanix platform — this skill is Prism Central v4 only. For other infrastructure, use the appropriate **other AIops-tools** sibling.\n\n## Common Workflows\n\n### \"Something is wrong with the estate\" → diagnose, then act\n\n1. `nutanix-aiops diagnose cluster-health` → worst-first findings, e.g.\n   `critical · prod-cluster · storage container near full · 93.0% used >= 90.0% threshold`\n2. `storage_container_list` → confirm which container it is and what its\n   `maxCapacityBytes` / `logicalUsageBytes` actually are\n3. `recovery_point_list` / `snapshot_list <vm_ext_id>` → the usual culprit is\n   snapshot sprawl in that container\n4. `snapshot_delete <…> --dry-run` to preview, then re-run to reclaim space —\n   optionally set `NUTANIX_AUDIT_APPROVED_BY` first to annotate who authorized\n   it; each deletion is audited and records an undo descriptor\n5. Re-run `diagnose cluster-health` → the finding should drop below the 80%\n   warning threshold; the before/after percentages are your evidence\n\n### Triage a cluster alert (RCA)\n\n1. `nutanix-aiops diagnose alert-triage` (or `alert_list`) → per-severity counts and the oldest unresolved alert, so you know which extId to open first\n2. `analyze_alert <alert_ext_id>` → probable cause + suggested actions, built by correlating the alert with related `event_list` records\n3. Confirm blast radius with `cluster_health` / `cluster_utilization`, then `alert_acknowledge` (or `alert_resolve` once fixed)\n\n### Safely delete a VM (high-risk, audited)\n\n1. `vm_get <vm_ext_id>` → confirm it's the right VM (and see its ETag)\n2. `nutanix-aiops vm delete <vm_ext_id> --dry-run` → preview the exact `DELETE` call\n3. Optionally annotate who/why: `export NUTANIX_AUDIT_APPROVED_BY=… NUTANIX_AUDIT_RATIONALE=…`\n4. Re-run without `--dry-run` (double-confirm at the CLI); the call is audited with\n   tier and any approver/rationale supplied\n\n### Snapshot sprawl cleanup\n\n1. `recovery_point_list` (or per-VM `snapshot_list <vm_ext_id>`) → find stale / redundant snapshots\n2. `snapshot_delete <…> --dry-run` on each candidate → preview\n3. Re-run without dry-run (HIGH risk, double-confirm at the CLI) to reclaim space; each deletion is audited\n\n### Capacity runway\n\n1. `cluster_utilization <cluster_ext_id>` → current CPU / memory / storage / IOPS\n2. `capacity_runway` → days-to-full forecast per resource; use it to schedule an `lcm` expansion or storage add before you hit the wall\n\n### Migrate a VM to another host (reversible)\n\n1. `host_list` → pick the destination host extId\n2. `nutanix-aiops vm migrate <vm_ext_id> <target_host_ext_id> --dry-run` → preview\n3. Re-run without dry-run (HIGH, double-confirm); the **prior host is captured as an undo descriptor** so a regression can be reversed\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide whether a write is\npermitted. That is your agent's judgement, or the permission of the account you connect it with\n(connect with a Prism Central account holding only a read-only (Viewer) role — writes then fail\nat the server). There is no read-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.nutanix-aiops/audit.db` (relocatable via `NUTANIX_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- `NUTANIX_AUDIT_APPROVED_BY` / `NUTANIX_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `NUTANIX_RUNAWAY_MAX=0`.\n- Every mutation auto-handles **ETag / If-Match**; every list auto-paginates.\n- Destructive writes support `dry_run` / `--dry-run` and, at the CLI, double confirmation.\n- Reversible writes record an undo descriptor (`vm_update` → prior CPU/memory, `vm_migrate` → prior host).\n\n## References\n\n- `references/capabilities.md` — full 51-tool + API-path reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, REST-RBAC, CE self-test\n- `references/agent-guardrails.md` — which guardrails the harness enforces for you, and a ready-to-paste system prompt for smaller / local models\n</content>\n\nFile v0.11.3:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"nutanix-aiops\",\n  \"version\": \"0.11.3\",\n  \"publishedAt\": 1789452655539\n}\n\nFile v0.11.3:references/agent-guardrails.md\n\n# Agent guardrails — running nutanix-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## What the tool now enforces — do not waste prompt budget on these\n\nAuthorization is not this tool's job — decide it via the account you connect it\nwith, or the agent's own prompt. What the harness does guarantee:\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Fetch the ETag before you change anything\" | Prism Central v4 requires an `If-Match` ETag on most mutations (optimistic concurrency). Every write tool fetches the entity's current ETag itself and sends it back. There is **no ETag parameter for the model to get wrong**, and no read it must remember to run first. |\n| \"Don't invent a value when a field is missing\" | A field Prism Central did not return comes back as `null`, never as `\"\"`. Absent and empty are distinguishable in the payload — which matters here, because v4 omits a great many fields (`description`, `hypervisorType`, host and cluster names, LCM version strings, alert `impactType`). |\n| \"Tell me if the output was cut off\" | Every list tool returns `{\"<items>\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is **measured** (one extra row is fetched), not guessed from a length coincidence. `vm_list`, `cluster_list`, `host_list`, `alert_list`, `event_list`, `audit_list`, `task_list`, `image_list`, `category_list`, `subnet_list`, `snapshot_list`, `recovery_point_list`, `protection_domain_list`, `storage_container_list`, `lcm_inventory` and `undo_list` all take a `limit` and report against it. |\n| \"Preserve the ordering / tell me what's most urgent\" | `cluster_health_rca` and `alert_triage_rca` findings carry an explicit 1-based `rank`, worst-first. Priority is in the payload, not implied by list position, and every finding cites the measured percentage or the raw Prism state string that tripped it. |\n| \"Confirm before anything destructive\" | Destructive tools (`vm_delete`, `vm_migrate`, `snapshot_delete`, `snapshot_restore`, `image_delete`, `subnet_delete`, `storage_container_delete`, `lcm_update`, `pd_failover`) take `dry_run=True` for a preview and are `risk=high`, tagged `review` on the audit row. The CLI adds a double confirmation on top. |\n| \"Run the LCM precheck before upgrading\" | `lcm_update` **refuses** unless you hand back the `taskExtId` from `lcm_precheck` as `precheck_task_ext_id` and that task reached `SUCCEEDED`. The `dry_run` preview enforces it too, so a preview can never promise an upgrade the real call would refuse. The ordering is a guarantee, not a suggestion the model can skip. |\n| \"Undo it if it goes wrong\" | Reversible writes record an inverse descriptor capturing the **prior** state (power state, CPU/memory, capacity/RF, source host). `undo_list` shows them; `undo_apply` replays one through the same governed path. Irreversible deletes still record what was there: `subnet_delete` captures the subnet's name, description, type, VLAN id, cluster and IP config/pools, so a wrongly deleted subnet can be rebuilt by hand from the audit row. |\n| \"Log what you did\" | Every call is audited to `~/.nutanix-aiops/audit.db` regardless of what the model says it did (relocatable via `NUTANIX_AIOPS_HOME`). |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate a Nutanix Prism Central (v4) environment through the nutanix-aiops\nMCP tools.\n\nTOOL USE\n- Before answering any question about the current Nutanix environment, you MUST\n  call a tool. Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nIDENTIFIERS\n- Every entity is identified by an opaque extId (a UUID). Copy an extId verbatim\n  from a tool result. Never retype, abbreviate, reformat, or reconstruct one.\n- extIds are NOT interchangeable by type. A VM extId, a cluster extId, a host\n  extId, a subnet extId, a storage-container extId, a recovery-point extId and\n  a task extId are different namespaces that look identical. Passing a cluster\n  extId where a VM extId is wanted is the single most common failure here.\n- Call cluster_list first — most other tools need a clusterExtId from it, and\n  vm_list / host_list give you the VM and host extIds.\n\nREADING RESULTS\n- Read the whole result before concluding. If a result has \"truncated\": true,\n  say so and re-run with a higher limit instead of treating the partial result\n  as complete.\n- A null field means Prism Central did not return that value. Report it as \"not\n  available\" — never infer it.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  power states, severities, fault-tolerance states, or extIds.\n- When a cluster_health_rca or alert_triage_rca result has findings, work in\n  \"rank\" order and cite the measured number in each finding's \"detail\".\n\nWRITES\n- Run the dry_run=True form of a destructive tool and show the operator what it\n  would change before running it for real.\n- Async writes return a task extId, not a result. Poll task_list for its status\n  rather than assuming the operation finished.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a capacity, resiliency, or performance problem unless a tool\n  result supports it.\n- Do not add generic advice that does not follow from the tool output.\n```\n\n## Nutanix-specific notes\n\n- **AHV and ESXi VMs are both visible, and they are not equivalent.** Prism\n  Central sees ESXi-backed VMs in a hypervisor-migration estate, so `vm_list`\n  returns them by default and the `hypervisor` field distinguishes them. AHV-only\n  operations (snapshot create/restore via the AHV VM API, live migrate to a\n  target AHV host) will fail against an ESXi-managed VM. Pass\n  `include_esxi=false` to `vm_list` when you only want VMs the AHV lifecycle\n  tools can act on, and check the `hypervisor` field before proposing a write.\n- **ETags are handled for you.** v4 mutations use `If-Match` for optimistic\n  concurrency. `vm_get` and `subnet_get` surface the current `_etag` if you want\n  it, but no write tool asks for one — do not prompt the model to fetch it, and\n  do not treat a missing ETag as a blocker.\n- **Writes are asynchronous.** Most v4 mutations return a task extId\n  (`taskExtId`) rather than the finished entity. A snapshot may not exist the\n  instant `snapshot_create` returns — the tool resolves the real snapshot extId\n  best-effort, and honestly records no undo when it could not.\n- **`snapshot_restore` and `pd_failover` are not undoable.** A revert overwrites\n  the VM's current state and a failover is a DR event. Both declare no inverse\n  rather than pretending to one.\n- **Storage headroom is not the same as free space.** Nutanix reserves capacity\n  to rebuild after a node or disk failure, which is why `cluster_health_rca`\n  flags containers and pools at 80% (warning) / 90% (critical) rather than\n  waiting for full.\n\n## Recommended setup for a local model\n\nAuthorization is not this tool's job, so enforce it where it actually belongs:\nconnect with a Prism Central account holding only a read-only (Viewer) role\nuntil you trust the setup — writes then fail at the server, not at a switch in\nthis tool.\n\n```bash\nnutanix-aiops doctor\n```\n\nThen, when you are ready to allow writes, point the account at a role with the\nwrite permissions it needs, and optionally set an approver so the audit trail\ncarries an accountable name:\n\n```bash\nexport NUTANIX_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport NUTANIX_AUDIT_RATIONALE=\"scheduled maintenance window 2026-07-20\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **Multi-tool workflows time out or drift.** Prefer `cluster_health_rca`,\n  `alert_triage_rca` and `analyze_alert` — each does the multi-step correlation\n  inside one call, so the model does not have to chain reads and keep extIds\n  straight across turns.\n- **The model mixes up extIds.** Ask for one entity type at a time, and use\n  `overview` first to orient before drilling in.\n- **The model ignores later tool results in a long context.** Ask narrower\n  questions and use `limit` deliberately rather than pulling whole inventories.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Nutanix-AIops](https://github.com/AIops-tools/Nutanix-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.3:references/capabilities.md\n\n# nutanix-aiops capabilities\n\n> **51 MCP tools** (24 read, 27 write) over the Nutanix\n> **Prism Central v4 REST API** (HTTPS :9440, HTTP Basic auth). Every mutation\n> handles **ETag / If-Match** automatically; every list is **paginated**\n> automatically. Paths below are the v4 API prefixes actually called; validate\n> against a live Prism Central / Community Edition before production use.\n\n## Clusters (4 read)\n\n| Tool | API path | Returns |\n|------|----------|---------|\n| `cluster_list` | `GET /api/clustermgmt/v4.0/config/clusters` | extId, name, AOS version, hypervisors, node count |\n| `cluster_health` | `GET /api/clustermgmt/v4.0/config/clusters/{extId}` | services, resiliency / fault-tolerance, upgrade state |\n| `host_list` | `GET /api/clustermgmt/v4.0/config/hosts` | host extId, cluster, hypervisor, CPU / memory |\n| `cluster_utilization` | `GET /api/clustermgmt/v4.0/config/clusters/{extId}` | point-in-time CPU / memory / storage / IOPS |\n\n## VMs (2 read, 9 write) — base `GET /api/vmm/v4.0/ahv/config/vms`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `vm_list` | read | `GET …/vms` (paginated) | VMs across **AHV + ESXi** (extId, name, cluster, power, vCPU, mem, hypervisor) |\n| `vm_get` | read | `GET …/vms/{extId}` | one VM, **surfaces its ETag** for downstream mutations |\n| `vm_power_on` | write · low | `POST …/vms/{extId}/$actions/power-on` | task ref |\n| `vm_guest_shutdown` | write · med | `POST …/vms/{extId}/$actions/shutdown` | graceful guest shutdown |\n| `vm_power_off` | write · med | `POST …/vms/{extId}/$actions/power-off` | hard power off |\n| `vm_reboot` | write · med | `POST …/vms/{extId}/$actions/reboot` | task ref |\n| `vm_create` | write · med | `POST …/vms` | new VM extId |\n| `vm_update` | write · med | `PUT …/vms/{extId}` (If-Match) | **undo captures prior CPU / memory** |\n| `vm_clone` | write · med | `POST …/vms/{extId}/$actions/clone` | clone extId |\n| `vm_delete` | write · **HIGH** | `DELETE …/vms/{extId}` | **dry_run**; double-confirm at CLI |\n| `vm_migrate` | write · **HIGH** | `POST …/vms/{extId}/$actions/migrate` | **dry_run**; **undo → prior host** |\n\n## Storage (1 read, 3 write) — base `GET /api/clustermgmt/v4.0/config/storage-containers`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `storage_container_list` | read | `GET …/storage-containers` | extId, name, cluster, capacity, usage |\n| `storage_container_create` | write · med | `POST …/storage-containers` | new container extId |\n| `storage_container_update` | write · med | `PUT …/storage-containers/{extId}` (If-Match) | **undo captures prior config** |\n| `storage_container_delete` | write · **HIGH** | `DELETE …/storage-containers/{extId}` | **dry_run** |\n\n## Network (2 read, 2 write) — base `GET /api/networking/v4.0/config/subnets`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `subnet_list` | read | `GET …/subnets` | extId, name, type, VLAN, IP config |\n| `subnet_get` | read | `GET …/subnets/{extId}` | one subnet, **surfaces ETag** |\n| `subnet_create` | write · med | `POST …/subnets` | new subnet extId |\n| `subnet_delete` | write · **HIGH** | `DELETE …/subnets/{extId}` | **dry_run** |\n\n## Catalog (2 read, 3 write)\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `image_list` | read | `GET /api/vmm/v4.0/content/images` | image extId, name, type, size |\n| `image_delete` | write · **HIGH** | `DELETE /api/vmm/v4.0/content/images/{extId}` | **dry_run** |\n| `category_list` | read | `GET /api/prism/v4.0/config/categories` | key, value, extId |\n| `category_create` | write · low | `POST /api/prism/v4.0/config/categories` | new category extId |\n| `category_assign` | write · med | `POST …/categories/{extId}/$actions/associate` | **bulk-assign** a category to many VMs |\n\n## Data protection / DR (3 read, 5 write)\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `snapshot_list` | read | `GET …/vms/{extId}` recovery points | per-VM snapshots (extId, name, created) |\n| `recovery_point_list` | read | `GET /api/dataprotection/v4.0/config/recovery-points` | recovery points across estate |\n| `protection_domain_list` | read | `GET /api/dataprotection/v4.0/config/protection-policies` | protection policies / domains |\n| `snapshot_create` | write · low | `POST …/vms/{extId}` recovery point | new snapshot extId |\n| `snapshot_delete` | write · **HIGH** | `DELETE …/recovery-points/{extId}` | **dry_run** |\n| `snapshot_restore` | write · **HIGH** | `POST …/$actions/restore` | **dry_run** |\n| `vm_protect` | write · med | `POST …/protection-policies` associate | attach a VM to a protection policy |\n| `pd_failover` | write · **HIGH** | `POST …/$actions/failover` | **dry_run** |\n\n## Alerts (4 read, 2 write)\n\n| Tool | Risk | API path | Returns |\n|------|------|----------|---------|\n| `alert_list` | read | `GET /api/monitoring/v4.0/serviceability/alerts` | active alerts (severity, impact, source) |\n| `event_list` | read | `GET /api/monitoring/v4.0/serviceability/events` | recent events |\n| `audit_list` | read | `GET /api/prism/v4.0/config/audits` | Prism audit records |\n| `analyze_alert` | read | correlates alert + related events | **RCA (flagship read)** — probable cause + suggested actions |\n| `alert_acknowledge` | write · low | `POST …/alerts/{extId}/$actions/acknowledge` | ack a live alert |\n| `alert_resolve` | write · low | `POST …/alerts/{extId}/$actions/resolve` | resolve a live alert |\n\n## LCM — upgrades (1 read, 2 write)\n\n| Tool | Risk | API path | Returns |\n|------|------|----------|---------|\n| `lcm_inventory` | read | `GET /api/lifecycle/v4.0/resources/entities` | firmware / software entities + available versions |\n| `lcm_precheck` | write · medium | `POST /api/lifecycle/v4.0/resources/$actions/perform-precheck` | precheck task ref |\n| `lcm_update` | write · **HIGH** | `POST /api/lifecycle/v4.0/resources/$actions/perform-update` | **firmware/software update**; **dry_run**; **refused unless `precheck_task_ext_id` names a precheck task that reached SUCCEEDED** |\n\n## Capacity (2 read)\n\n| Tool | API path | Returns |\n|------|----------|---------|\n| `task_list` | `GET /api/prism/v4.0/config/tasks` | recent Prism tasks (status, entity, progress) |\n| `capacity_runway` | derived from cluster utilization | **days-to-full forecast** per resource |\n\n## Diagnostics / RCA (2 read)\n\nRead-only signature analyses (`risk_level=\"low\"`). Both are **pure and\ndeterministic** — no clock, no randomness — and every finding carries the\nmeasured number or raw Prism state that tripped it, alongside a probable cause\nand a concrete action. Findings are returned worst-first\n(critical → warning → info) with the shape\n`{severity, resource, signal, detail, cause, action}`.\n\n| Tool | API paths read | Returns |\n|------|----------------|---------|\n| `cluster_health_rca` | `clusters` + `clusters/{extId}` + `hosts` + `storage-containers` | findings for degraded `faultToleranceState`, cluster storage pool and storage containers over **80% (warning) / 90% (critical)**, hosts whose `nodeStatus` is unhealthy, and clusters with fewer visible hosts than their `nodeCount`; plus a `summary` of every measured percentage |\n| `alert_triage_rca` | `serviceability/alerts` | active (unresolved) alerts grouped by severity with a per-level count, unacknowledged criticals called out, and `oldestUnresolved` (title, severity, `ageDays`) — an alert open **≥ 7 days** is flagged stale |\n\n`alert_triage_rca` is the fleet-level lens; `analyze_alert` is the per-alert\nlens (event correlation on one alert's affected entity). They compose: triage\nfirst to pick the extId, then analyze it.\n\n## Undo (1 read, 1 write)\n\n| Tool | Risk | Returns / effect |\n|------|:----:|------------------|\n| `undo_list` | low | recorded, not-yet-applied reversible writes — `undoId`, original tool, inverse tool, note |\n| `undo_apply` | medium | executes a recorded inverse descriptor; itself governed and audited, single-use, supports `dry_run` |\n\n## ETag / pagination / mixed hypervisor\n\n- **ETag / If-Match** — the v4 API rejects an update or delete without the\n  current entity's ETag. Every mutation here fetches the ETag and sends\n  `If-Match` for you (the common v4 footgun); `vm_get` / `subnet_get` surface it\n  for inspection.\n- **Pagination** — all list tools follow `$page` / `$limit` and return the full\n  set, not just page one.\n- **Mixed hypervisor** — `vm_list` returns both **AHV** and **ESXi** VMs managed\n  by the same Prism Central (relevant to hypervisor-migration estates).\n\n## Out of scope (by design, this release)\n\n- IAM / users / roles / SAML, Files / Objects / Volumes services\n- Report generation, X-Play / playbooks, calm / self-service\n- Anything outside Prism Central v4 (direct Prism Element, ncli/acli)\n\nWant one of these? Open an issue or PR — feedback and contributions welcome.\n</content>\n</invoke>\n\nFile v0.11.3:references/cli-reference.md\n\n# nutanix-aiops CLI reference\n\n> Talks to Nutanix **Prism Central v4** on HTTPS `:9440`\n> with HTTP Basic auth. The CLI is a convenience subset; the full **51-tool**\n> surface is via the MCP server (`nutanix-aiops mcp`).\n\n## Setup & diagnostics\n\n```bash\nnutanix-aiops init                      # interactive onboarding wizard\nnutanix-aiops doctor [--skip-auth]      # config + secret store + connectivity + REST-RBAC preflight\nnutanix-aiops mcp                       # start the MCP server (stdio transport)\n```\n\n`doctor` checks the config file, the encrypted secret store and its permissions,\nthat a password is present per target, and (unless `--skip-auth`) connectivity\nplus a **REST-RBAC preflight** against Prism Central — confirming the account can\nactually call the v4 APIs, not just log in to the Web UI.\n\n## Estate & clusters (read)\n\n```bash\nnutanix-aiops overview [--target <t>]              # one-shot estate summary\nnutanix-aiops cluster list                         # registered clusters (extId, AOS, hypervisors, nodes)\nnutanix-aiops cluster health <cluster_ext_id>      # services, resiliency, upgrade state\nnutanix-aiops cluster hosts                         # hosts across all clusters\nnutanix-aiops cluster util <cluster_ext_id>        # CPU / memory / storage / IOPS utilization\n```\n\n## Diagnostics / RCA (read-only)\n\n```bash\nnutanix-aiops diagnose cluster-health              # resiliency, storage >80%/>90%, nodes down — worst first\nnutanix-aiops diagnose alert-triage                # active alerts by severity + oldest unresolved\n```\n\nBoth print a worst-first findings table (severity · resource · signal · detail ·\naction) or a green all-clear line when every measured value is under threshold.\n\n## VMs\n\n```bash\nnutanix-aiops vm list [--esxi | --no-esxi]         # AHV + ESXi VMs (ESXi included by default)\nnutanix-aiops vm get <vm_ext_id>                   # one VM detail (shows its ETag)\nnutanix-aiops vm power <vm_ext_id> <on|off|shutdown|reboot> [--dry-run]\nnutanix-aiops vm delete <vm_ext_id> [--dry-run]    # (HIGH) dry-run + double confirm\nnutanix-aiops vm migrate <vm_ext_id> <target_host_ext_id> [--dry-run]   # (HIGH) dry-run + double confirm\n```\n\n## Secrets (encrypted store `~/.nutanix-aiops/secrets.enc`)\n\n```bash\nnutanix-aiops secret set <target> [--value <pw>]   # store PC password (hidden prompt if no --value)\nnutanix-aiops secret list                           # names only — values never shown\nnutanix-aiops secret rm <target>\nnutanix-aiops secret migrate                        # import legacy plaintext env (NUTANIX_<T>_PASSWORD)\nnutanix-aiops secret rotate-password                # re-encrypt the store under a new master password\n```\n\n## Common options\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default / first target)\n- `--dry-run` — print the API call that would be made, change nothing\n- `--esxi / --no-esxi` — include or exclude ESXi-managed VMs in `vm list` (default: include)\n- Destructive commands (`vm delete`, `vm migrate`) require a `--dry-run` preview and **two confirmations**\n\n## Full surface via MCP\n\nThe 51 governed tools (clusters, VMs, storage, network, catalog, data\nprotection / DR, alerts + `analyze_alert` RCA, LCM upgrades, capacity runway,\nand the `cluster_health_rca` / `alert_triage_rca` diagnostics)\nare exposed by `nutanix-aiops mcp`. Set `NUTANIX_AIOPS_MASTER_PASSWORD` so the\nencrypted store unlocks non-interactively. See `capabilities.md` for the full\ntool → API-path → returns map.\n</content>\n\nFile v0.11.3:references/setup-guide.md\n\n# nutanix-aiops setup & security guide\n\n> Currently validated against mocked v4 REST responses; see `docs/VERIFICATION.md`\n> in the repo for the live-verification checklist.\n\n## 1. Install\n\n```bash\nuv tool install nutanix-aiops          # or: pipx install nutanix-aiops\n```\n\n## 2. Prepare a Prism Central account (with REST API rights)\n\nnutanix-aiops connects to **Prism Central** on HTTPS port **9440** and\nauthenticates the v4 REST APIs with **HTTP Basic auth** (username + password).\n\n> **Important gotcha:** the account needs **REST API** rights, not just Web UI\n> access. A user that can log into the Prism Central console may still be denied\n> at the API. Give the account a role with the v4 API permissions it needs\n> (read for the estate; the relevant lifecycle/VM/storage/DR permissions for any\n> writes). `nutanix-aiops doctor` runs a REST-RBAC preflight to catch this early.\n\n## 3. Onboard\n\n```bash\nnutanix-aiops init\n```\n\nThe wizard collects the (non-secret) connection details into\n`~/.nutanix-aiops/config.yaml` and stores the **password encrypted** into\n`~/.nutanix-aiops/secrets.enc`. Example config:\n\n```yaml\ntargets:\n  - name: pc1\n    host: 10.0.0.20        # Prism Central IP / FQDN\n    port: 9440\n    username: admin        # PC account with REST API rights\n    verify_ssl: false      # self-signed lab / CE certs only\n```\n\nThe `username` is not a secret and lives in the config file; the password lives\nonly in the encrypted store.\n\n## 4. Non-interactive use (MCP server / CI / cron)\n\nExport the master password so the encrypted store unlocks without a prompt:\n\n```bash\nexport NUTANIX_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n## Credential security\n\n- The Prism Central password is **never** written to disk in plaintext. It lives\n  only in `~/.nutanix-aiops/secrets.enc`, encrypted with Fernet (AES-128-CBC +\n  HMAC), the key derived from your master password via scrypt. Only a per-store\n  random salt and the ciphertext are on disk (chmod 600); the master password\n  itself is never stored.\n- A legacy plaintext env var `NUTANIX_<TARGET_NAME_UPPER>_PASSWORD` is still\n  honoured as a fallback with a deprecation warning — migrate with\n  `nutanix-aiops secret migrate`.\n- The password is held only in memory during a session and is never logged or\n  echoed; exception text and tracebacks are scrubbed of secret-shaped strings\n  before being written to the audit log.\n\n## Optional audit annotations\n\nThe skill does not decide whether a write is permitted — that is the agent's\njudgement, or the permission of the account you connect it with (connect with\na Prism Central account holding only a read-only (Viewer) role, and writes\nfail at the server). `NUTANIX_AUDIT_APPROVED_BY` / `NUTANIX_AUDIT_RATIONALE`\noptionally annotate the audit row with who authorized a high-risk operation\nand why — they are never required and never block a call:\n\n```bash\nexport NUTANIX_AUDIT_APPROVED_BY='alice@example.com'\nexport NUTANIX_AUDIT_RATIONALE='Decommissioning migrated ESXi guest per CHG-1234'\n```\n\n## Governance harness state\n\nState lives under `~/.nutanix-aiops/` (relocate with `NUTANIX_AIOPS_HOME`):\n\n- `audit.db` — every tool call (SQLite), with risk tier and any approver/rationale supplied\n- `undo.db` — inverse descriptors for reversible writes (e.g. `vm_update` prior\n  CPU/memory, `vm_migrate` prior host)\n- budget / runaway guard — caps cumulative tool calls and wall-time; trips on\n  tight poll/retry loops\n\n## Self-test for free (Community Edition)\n\nYou can validate end-to-end at no cost with **Nutanix Community Edition (CE)**:\na single-node CE cluster plus an **X-Small Prism Central** VM. Point a `pc1`\ntarget at that PC on `:9440` and run the read tools; exercise the writes against\nthrowaway VMs / snapshots.\n\n## Verify\n\n```bash\nnutanix-aiops doctor\n```\n\n`doctor` is the fastest live check — config, encrypted store + permissions, a\npassword per target, connectivity to Prism Central `:9440`, and the REST-RBAC\npreflight.\n</content>\n\nFile v0.11.3:skill-card.md\n\n## Description:\n\nNutanix AIops helps an agent operate a Nutanix Prism Central v4 estate, including health and inventory checks, VM lifecycle operations, storage and network administration, data protection, alerts, LCM upgrades, capacity forecasting, and RCA workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, operators, and infrastructure engineers use this skill to inspect and administer Nutanix Prism Central v4 environments through governed CLI and MCP workflows. It is intended for Nutanix estate diagnostics, VM and storage lifecycle tasks, alerts and RCA, data protection, LCM upgrades, and capacity planning.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill exposes broad destructive Nutanix infrastructure controls without an enforced approval or read-only gate.\n\nMitigation: Use a least-privilege or read-only Prism Central account by default, require operator review for high-risk writes, and preview destructive actions with dry-run where supported.\n\nRisk: Credential handling can be weakened by plaintext environment fallbacks or command-line password values.\n\nMitigation: Use the encrypted secret store and master password flow, avoid passing passwords with --value or plaintext environment variables, and migrate legacy plaintext secrets.\n\nRisk: Disabling TLS verification can expose Prism Central credentials and operations to interception outside isolated labs.\n\nMitigation: Keep verify_ssl enabled for normal use and disable it only for isolated lab or Community Edition environments with self-signed certificates.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/nutanix-aiops)\n- [Project homepage](https://github.com/AIops-tools/Nutanix-AIops)\n- [Capabilities reference](references/capabilities.md)\n- [CLI reference](references/cli-reference.md)\n- [Setup and security guide](references/setup-guide.md)\n- [Agent guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and structured tool guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May guide MCP and CLI operations that can read from or write to Nutanix infrastructure, depending on connected account permissions.]\n\n## Skill Version(s):\n\n0.11.3 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.2: 7 files, 19060 bytes\n\nFiles: references/agent-guardrails.md (9493b), references/capabilities.md (9075b), references/cli-reference.md (3528b), references/setup-guide.md (3988b), skill-card.md (2522b), SKILL.md (13165b), _meta.json (133b)\n\nFile v0.11.2:SKILL.md\n\n---\nname: nutanix-aiops\nslug: nutanix-aiops\ndisplayName: \"Nutanix AIops\"\nsummary: \"Governed Nutanix Prism Central v4 ops: clusters/VMs/storage/DR/LCM/RCA, ETag-safe, 51 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Nutanix-AIops\ntags: [aiops, mcp, governance, nutanix]\ndescription: >\n  Use this skill whenever the user needs to operate a Nutanix estate through Prism Central (v4 REST API) — an estate/cluster health overview, cluster & host inventory and utilization, VM lifecycle across AHV and ESXi (list/get/power/create/update/clone/delete/migrate), storage containers, subnets/network, images & categories, data protection / DR (snapshots, recovery points, protection domains, VM protect, failover), alerts & events with alert RCA (analyze_alert), LCM firmware/software upgrades, capacity runway forecasting, and read-only diagnostics/RCA over the whole estate (cluster_health_rca, alert_triage_rca).\n  Always use this skill for \"Nutanix\", \"Prism Central\", \"AHV\", \"cluster health\", \"list VMs\", \"power on/off a VM\", \"clone/migrate a VM\", \"delete a VM\", \"snapshot\", \"recovery point\", \"protection domain\", \"failover\", \"why did this alert fire\" / \"root cause this alert\", \"LCM upgrade / firmware\", \"days until storage is full\" / \"capacity runway\", \"what's wrong with my cluster\" / \"diagnose the estate\", \"triage my alerts\", when the context is a Nutanix cluster or Prism Central.\n  Do NOT use when the target is a non-Nutanix platform — those belong to their own AIops-tools sibling; this skill is Prism Central v4 only.\n  Governed Nutanix Prism Central operations with a built-in governance harness (audit, token budget, undo, descriptive risk-tier labels).\ninstaller:\n  kind: uv\n  package: nutanix-aiops\nargument-hint: \"[VM/cluster extId or describe your Nutanix task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"nutanix-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"NUTANIX_AIOPS_CONFIG\",\"NUTANIX_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Nutanix-AIops\",\"emoji\":\"🧊\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed Nutanix Prism Central operations. The governance harness (audit, token/runaway budget, undo, descriptive risk-tier labels) is bundled in the package — no external skill-family dependency.\n  Connects to Prism Central on HTTPS :9440 with HTTP Basic auth (username + password). The v4 REST API requires an ETag/If-Match on every mutation; nutanix-aiops fetches and sends it automatically. All list tools paginate automatically; vm_list returns both AHV and ESXi VMs.\n  All write operations are audited to a local SQLite DB under ~/.nutanix-aiops/ (relocatable via NUTANIX_AIOPS_HOME).\n  Credentials: the Prism Central password is stored ENCRYPTED in ~/.nutanix-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'nutanix-aiops init' to onboard, or 'nutanix-aiops secret set <target>' to add one. The store is unlocked by a master password from NUTANIX_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var NUTANIX_<TARGET_NAME_UPPER>_PASSWORD is still honoured as a fallback with a deprecation warning (migrate with 'nutanix-aiops secret migrate'). The account needs REST API rights, not just Web UI access.\n  State-changing operations require the @governed_tool decorator (budget guard + audit + risk-tier tagging). The skill does not decide whether a write is permitted — that is the agent's judgement or the connecting account's permissions. High-risk ops (vm_delete, vm_migrate, storage_container_delete, subnet_delete, snapshot_delete, snapshot_restore, pd_failover, image_delete, lcm_update) support dry_run and, at the CLI, double confirmation; reversible writes record an undo descriptor (vm_update → prior CPU/memory, vm_migrate → prior host).\n  NUTANIX_AUDIT_APPROVED_BY and NUTANIX_AUDIT_RATIONALE are optional annotations recorded on the audit row (who/why); they are never required and never block a call.\n  SSL: verify_ssl defaults to true; disable only for self-signed lab / Community Edition certificates.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Validation status: behaviour is currently validated against mocked v4 REST responses; the LCM update, PD failover, and ESXi-VM listing paths in particular still need live verification (self-testable free on Nutanix Community Edition + X-Small Prism Central). See docs/VERIFICATION.md in the repo for the live-verification checklist.\n---\n\n# Nutanix AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by Nutanix.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/Nutanix-AIops](https://github.com/AIops-tools/Nutanix-AIops) under the MIT license.\n\nGoverned Nutanix **Prism Central (v4 REST API)** operations — **51 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.nutanix-aiops/`, token/runaway budget guard, undo-token recording, and descriptive risk-tier labels. The Prism Central password is stored **encrypted** (`~/.nutanix-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk.\n\n**What sets it apart** from read-only Nutanix MCPs: (1) automatic **ETag / If-Match** on every mutation — the v4 footgun handled for you; (2) automatic **pagination**; (3) **mixed-hypervisor** VM listing (AHV + ESXi, relevant to hypervisor-migration estates); and (4) the governance harness with **dry-run + double-confirm** on destructive writes.\n\n> **Standalone**: the governance harness is bundled in the package (`nutanix_aiops.governance`) — no external skill-family dependency.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read / Write |\n|-------|-------|:-----:|:------------:|\n| **Clusters** | cluster_list, cluster_health, host_list, cluster_utilization | 4 | 4 read |\n| **VMs** | list, get, power_on, guest_shutdown, power_off, reboot, create, update, clone, delete, migrate | 11 | 2 read · 9 write |\n| **Storage** | container list / create / update / delete | 4 | 1 read · 3 write |\n| **Network** | subnet list / get / create / delete | 4 | 2 read · 2 write |\n| **Catalog** | image list / delete, category list / create / assign | 5 | 2 read · 3 write |\n| **Data protection / DR** | snapshot list/create/delete/restore, recovery_point_list, protection_domain_list, vm_protect, pd_failover | 8 | 3 read · 5 write |\n| **Alerts** | alert_list, event_list, audit_list, **analyze_alert (RCA)**, alert_acknowledge, alert_resolve | 6 | 4 read · 2 write |\n| **LCM (upgrades)** | lcm_inventory, lcm_precheck, lcm_update | 3 | 1 read · 2 write |\n| **Capacity** | task_list, capacity_runway | 2 | 2 read |\n| **Diagnostics / RCA** | **cluster_health_rca**, **alert_triage_rca** | 2 | 2 read |\n| **Undo** | `undo_list`, `undo_apply` | 2 | 1 read · 1 write |\n| **Total** | | **51** | 24 read · 27 write |\n\nThe CLI is a convenience subset; the full 51-tool surface is via the MCP server. See `references/capabilities.md` for the tool → API-path → returns map.\n\n## Quick Install\n\n```bash\nuv tool install nutanix-aiops\nnutanix-aiops init       # interactive wizard: PC host/port 9440/username + encrypted password\nnutanix-aiops doctor     # connectivity + REST-RBAC preflight\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/nutanix-aiops\nopenclaw skills info nutanix-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Diagnose the estate in one shot (`diagnose cluster-health`): degraded resiliency, storage pools/containers over 80% / 90%, nodes down or missing — worst-first, each finding citing the measured number\n- Triage the alert backlog (`diagnose alert-triage`): per-severity counts, unacknowledged criticals, the oldest unresolved alert and its age\n- Inspect the estate (`overview`, `cluster health`, `cluster util`): clusters, hosts, resiliency, utilization\n- VM lifecycle across **AHV + ESXi** (`vm list/get/power/create/update/clone`), and guarded destructive ops (`vm delete`, `vm migrate`) with dry-run + double-confirm\n- Root-cause an alert (`analyze_alert`) — correlate it with related events into a probable-cause + suggested-actions summary\n- Data protection: snapshots, recovery points, protection domains, `vm_protect`, `pd_failover`\n- Upgrades (`lcm_inventory` → `lcm_precheck` → `lcm_update`) and capacity forecasting (`capacity_runway`)\n\n**Do NOT use when** the target is a non-Nutanix platform — this skill is Prism Central v4 only. For other infrastructure, use the appropriate **other AIops-tools** sibling.\n\n## Common Workflows\n\n### \"Something is wrong with the estate\" → diagnose, then act\n\n1. `nutanix-aiops diagnose cluster-health` → worst-first findings, e.g.\n   `critical · prod-cluster · storage container near full · 93.0% used >= 90.0% threshold`\n2. `storage_container_list` → confirm which container it is and what its\n   `maxCapacityBytes` / `logicalUsageBytes` actually are\n3. `recovery_point_list` / `snapshot_list <vm_ext_id>` → the usual culprit is\n   snapshot sprawl in that container\n4. `snapshot_delete <…> --dry-run` to preview, then re-run to reclaim space —\n   optionally set `NUTANIX_AUDIT_APPROVED_BY` first to annotate who authorized\n   it; each deletion is audited and records an undo descriptor\n5. Re-run `diagnose cluster-health` → the finding should drop below the 80%\n   warning threshold; the before/after percentages are your evidence\n\n### Triage a cluster alert (RCA)\n\n1. `nutanix-aiops diagnose alert-triage` (or `alert_list`) → per-severity counts and the oldest unresolved alert, so you know which extId to open first\n2. `analyze_alert <alert_ext_id>` → probable cause + suggested actions, built by correlating the alert with related `event_list` records\n3. Confirm blast radius with `cluster_health` / `cluster_utilization`, then `alert_acknowledge` (or `alert_resolve` once fixed)\n\n### Safely delete a VM (high-risk, audited)\n\n1. `vm_get <vm_ext_id>` → confirm it's the right VM (and see its ETag)\n2. `nutanix-aiops vm delete <vm_ext_id> --dry-run` → preview the exact `DELETE` call\n3. Optionally annotate who/why: `export NUTANIX_AUDIT_APPROVED_BY=… NUTANIX_AUDIT_RATIONALE=…`\n4. Re-run without `--dry-run` (double-confirm at the CLI); the call is audited with\n   tier and any approver/rationale supplied\n\n### Snapshot sprawl cleanup\n\n1. `recovery_point_list` (or per-VM `snapshot_list <vm_ext_id>`) → find stale / redundant snapshots\n2. `snapshot_delete <…> --dry-run` on each candidate → preview\n3. Re-run without dry-run (HIGH risk, double-confirm at the CLI) to reclaim space; each deletion is audited\n\n### Capacity runway\n\n1. `cluster_utilization <cluster_ext_id>` → current CPU / memory / storage / IOPS\n2. `capacity_runway` → days-to-full forecast per resource; use it to schedule an `lcm` expansion or storage add before you hit the wall\n\n### Migrate a VM to another host (reversible)\n\n1. `host_list` → pick the destination host extId\n2. `nutanix-aiops vm migrate <vm_ext_id> <target_host_ext_id> --dry-run` → preview\n3. Re-run without dry-run (HIGH, double-confirm); the **prior host is captured as an undo descriptor** so a regression can be reversed\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide whether a write is\npermitted. That is your agent's judgement, or the permission of the account you connect it with\n(connect with a Prism Central account holding only a read-only (Viewer) role — writes then fail\nat the server). There is no read-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.nutanix-aiops/audit.db` (relocatable via `NUTANIX_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- `NUTANIX_AUDIT_APPROVED_BY` / `NUTANIX_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `NUTANIX_RUNAWAY_MAX=0`.\n- Every mutation auto-handles **ETag / If-Match**; every list auto-paginates.\n- Destructive writes support `dry_run` / `--dry-run` and, at the CLI, double confirmation.\n- Reversible writes record an undo descriptor (`vm_update` → prior CPU/memory, `vm_migrate` → prior host).\n\n## References\n\n- `references/capabilities.md` — full 51-tool + API-path reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, REST-RBAC, CE self-test\n- `references/agent-guardrails.md` — which guardrails the harness enforces for you, and a ready-to-paste system prompt for smaller / local models\n</content>\n\nFile v0.11.2:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"nutanix-aiops\",\n  \"version\": \"0.11.2\",\n  \"publishedAt\": 1789223669100\n}\n\nFile v0.11.2:references/agent-guardrails.md\n\n# Agent guardrails — running nutanix-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## What the tool now enforces — do not waste prompt budget on these\n\nAuthorization is not this tool's job — decide it via the account you connect it\nwith, or the agent's own prompt. What the harness does guarantee:\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Fetch the ETag before you change anything\" | Prism Central v4 requires an `If-Match` ETag on most mutations (optimistic concurrency). Every write tool fetches the entity's current ETag itself and sends it back. There is **no ETag parameter for the model to get wrong**, and no read it must remember to run first. |\n| \"Don't invent a value when a field is missing\" | A field Prism Central did not return comes back as `null`, never as `\"\"`. Absent and empty are distinguishable in the payload — which matters here, because v4 omits a great many fields (`description`, `hypervisorType`, host and cluster names, LCM version strings, alert `impactType`). |\n| \"Tell me if the output was cut off\" | Every list tool returns `{\"<items>\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is **measured** (one extra row is fetched), not guessed from a length coincidence. `vm_list`, `cluster_list`, `host_list`, `alert_list`, `event_list`, `audit_list`, `task_list`, `image_list`, `category_list`, `subnet_list`, `snapshot_list`, `recovery_point_list`, `protection_domain_list`, `storage_container_list`, `lcm_inventory` and `undo_list` all take a `limit` and report against it. |\n| \"Preserve the ordering / tell me what's most urgent\" | `cluster_health_rca` and `alert_triage_rca` findings carry an explicit 1-based `rank`, worst-first. Priority is in the payload, not implied by list position, and every finding cites the measured percentage or the raw Prism state string that tripped it. |\n| \"Confirm before anything destructive\" | Destructive tools (`vm_delete`, `vm_migrate`, `snapshot_delete`, `snapshot_restore`, `image_delete`, `subnet_delete`, `storage_container_delete`, `lcm_update`, `pd_failover`) take `dry_run=True` for a preview and are `risk=high`, tagged `review` on the audit row. The CLI adds a double confirmation on top. |\n| \"Run the LCM precheck before upgrading\" | `lcm_update` **refuses** unless you hand back the `taskExtId` from `lcm_precheck` as `precheck_task_ext_id` and that task reached `SUCCEEDED`. The `dry_run` preview enforces it too, so a preview can never promise an upgrade the real call would refuse. The ordering is a guarantee, not a suggestion the model can skip. |\n| \"Undo it if it goes wrong\" | Reversible writes record an inverse descriptor capturing the **prior** state (power state, CPU/memory, capacity/RF, source host). `undo_list` shows them; `undo_apply` replays one through the same governed path. Irreversible deletes still record what was there: `subnet_delete` captures the subnet's name, description, type, VLAN id, cluster and IP config/pools, so a wrongly deleted subnet can be rebuilt by hand from the audit row. |\n| \"Log what you did\" | Every call is audited to `~/.nutanix-aiops/audit.db` regardless of what the model says it did (relocatable via `NUTANIX_AIOPS_HOME`). |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate a Nutanix Prism Central (v4) environment through the nutanix-aiops\nMCP tools.\n\nTOOL USE\n- Before answering any question about the current Nutanix environment, you MUST\n  call a tool. Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nIDENTIFIERS\n- Every entity is identified by an opaque extId (a UUID). Copy an extId verbatim\n  from a tool result. Never retype, abbreviate, reformat, or reconstruct one.\n- extIds are NOT interchangeable by type. A VM extId, a cluster extId, a host\n  extId, a subnet extId, a storage-container extId, a recovery-point extId and\n  a task extId are different namespaces that look identical. Passing a cluster\n  extId where a VM extId is wanted is the single most common failure here.\n- Call cluster_list first — most other tools need a clusterExtId from it, and\n  vm_list / host_list give you the VM and host extIds.\n\nREADING RESULTS\n- Read the whole result before concluding. If a result has \"truncated\": true,\n  say so and re-run with a higher limit instead of treating the partial result\n  as complete.\n- A null field means Prism Central did not return that value. Report it as \"not\n  available\" — never infer it.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  power states, severities, fault-tolerance states, or extIds.\n- When a cluster_health_rca or alert_triage_rca result has findings, work in\n  \"rank\" order and cite the measured number in each finding's \"detail\".\n\nWRITES\n- Run the dry_run=True form of a destructive tool and show the operator what it\n  would change before running it for real.\n- Async writes return a task extId, not a result. Poll task_list for its status\n  rather than assuming the operation finished.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- Do not assert a capacity, resiliency, or performance problem unless a tool\n  result supports it.\n- Do not add generic advice that does not follow from the tool output.\n```\n\n## Nutanix-specific notes\n\n- **AHV and ESXi VMs are both visible, and they are not equivalent.** Prism\n  Central sees ESXi-backed VMs in a hypervisor-migration estate, so `vm_list`\n  returns them by default and the `hypervisor` field distinguishes them. AHV-only\n  operations (snapshot create/restore via the AHV VM API, live migrate to a\n  target AHV host) will fail against an ESXi-managed VM. Pass\n  `include_esxi=false` to `vm_list` when you only want VMs the AHV lifecycle\n  tools can act on, and check the `hypervisor` field before proposing a write.\n- **ETags are handled for you.** v4 mutations use `If-Match` for optimistic\n  concurrency. `vm_get` and `subnet_get` surface the current `_etag` if you want\n  it, but no write tool asks for one — do not prompt the model to fetch it, and\n  do not treat a missing ETag as a blocker.\n- **Writes are asynchronous.** Most v4 mutations return a task extId\n  (`taskExtId`) rather than the finished entity. A snapshot may not exist the\n  instant `snapshot_create` returns — the tool resolves the real snapshot extId\n  best-effort, and honestly records no undo when it could not.\n- **`snapshot_restore` and `pd_failover` are not undoable.** A revert overwrites\n  the VM's current state and a failover is a DR event. Both declare no inverse\n  rather than pretending to one.\n- **Storage headroom is not the same as free space.** Nutanix reserves capacity\n  to rebuild after a node or disk failure, which is why `cluster_health_rca`\n  flags containers and pools at 80% (warning) / 90% (critical) rather than\n  waiting for full.\n\n## Recommended setup for a local model\n\nAuthorization is not this tool's job, so enforce it where it actually belongs:\nconnect with a Prism Central account holding only a read-only (Viewer) role\nuntil you trust the setup — writes then fail at the server, not at a switch in\nthis tool.\n\n```bash\nnutanix-aiops doctor\n```\n\nThen, when you are ready to allow writes, point the account at a role with the\nwrite permissions it needs, and optionally set an approver so the audit trail\ncarries an accountable name:\n\n```bash\nexport NUTANIX_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport NUTANIX_AUDIT_RATIONALE=\"scheduled maintenance window 2026-07-20\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **Multi-tool workflows time out or drift.** Prefer `cluster_health_rca`,\n  `alert_triage_rca` and `analyze_alert` — each does the multi-step correlation\n  inside one call, so the model does not have to chain reads and keep extIds\n  straight across turns.\n- **The model mixes up extIds.** Ask for one entity type at a time, and use\n  `overview` first to orient before drilling in.\n- **The model ignores later tool results in a long context.** Ask narrower\n  questions and use `limit` deliberately rather than pulling whole inventories.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Nutanix-AIops](https://github.com/AIops-tools/Nutanix-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.2:references/capabilities.md\n\n# nutanix-aiops capabilities\n\n> **51 MCP tools** (24 read, 27 write) over the Nutanix\n> **Prism Central v4 REST API** (HTTPS :9440, HTTP Basic auth). Every mutation\n> handles **ETag / If-Match** automatically; every list is **paginated**\n> automatically. Paths below are the v4 API prefixes actually called; validate\n> against a live Prism Central / Community Edition before production use.\n\n## Clusters (4 read)\n\n| Tool | API path | Returns |\n|------|----------|---------|\n| `cluster_list` | `GET /api/clustermgmt/v4.0/config/clusters` | extId, name, AOS version, hypervisors, node count |\n| `cluster_health` | `GET /api/clustermgmt/v4.0/config/clusters/{extId}` | services, resiliency / fault-tolerance, upgrade state |\n| `host_list` | `GET /api/clustermgmt/v4.0/config/hosts` | host extId, cluster, hypervisor, CPU / memory |\n| `cluster_utilization` | `GET /api/clustermgmt/v4.0/config/clusters/{extId}` | point-in-time CPU / memory / storage / IOPS |\n\n## VMs (2 read, 9 write) — base `GET /api/vmm/v4.0/ahv/config/vms`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `vm_list` | read | `GET …/vms` (paginated) | VMs across **AHV + ESXi** (extId, name, cluster, power, vCPU, mem, hypervisor) |\n| `vm_get` | read | `GET …/vms/{extId}` | one VM, **surfaces its ETag** for downstream mutations |\n| `vm_power_on` | write · low | `POST …/vms/{extId}/$actions/power-on` | task ref |\n| `vm_guest_shutdown` | write · med | `POST …/vms/{extId}/$actions/shutdown` | graceful guest shutdown |\n| `vm_power_off` | write · med | `POST …/vms/{extId}/$actions/power-off` | hard power off |\n| `vm_reboot` | write · med | `POST …/vms/{extId}/$actions/reboot` | task ref |\n| `vm_create` | write · med | `POST …/vms` | new VM extId |\n| `vm_update` | write · med | `PUT …/vms/{extId}` (If-Match) | **undo captures prior CPU / memory** |\n| `vm_clone` | write · med | `POST …/vms/{extId}/$actions/clone` | clone extId |\n| `vm_delete` | write · **HIGH** | `DELETE …/vms/{extId}` | **dry_run**; double-confirm at CLI |\n| `vm_migrate` | write · **HIGH** | `POST …/vms/{extId}/$actions/migrate` | **dry_run**; **undo → prior host** |\n\n## Storage (1 read, 3 write) — base `GET /api/clustermgmt/v4.0/config/storage-containers`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `storage_container_list` | read | `GET …/storage-containers` | extId, name, cluster, capacity, usage |\n| `storage_container_create` | write · med | `POST …/storage-containers` | new container extId |\n| `storage_container_update` | write · med | `PUT …/storage-containers/{extId}` (If-Match) | **undo captures prior config** |\n| `storage_container_delete` | write · **HIGH** | `DELETE …/storage-containers/{extId}` | **dry_run** |\n\n## Network (2 read, 2 write) — base `GET /api/networking/v4.0/config/subnets`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `subnet_list` | read | `GET …/subnets` | extId, name, type, VLAN, IP config |\n| `subnet_get` | read | `GET …/subnets/{extId}` | one subnet, **surfaces ETag** |\n| `subnet_create` | write · med | `POST …/subnets` | new subnet extId |\n| `subnet_delete` | write · **HIGH** | `DELETE …/subnets/{extId}` | **dry_run** |\n\n## Catalog (2 read, 3 write)\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `image_list` | read | `GET /api/vmm/v4.0/content/images` | image extId, name, type, size |\n| `image_delete` | write · **HIGH** | `DELETE /api/vmm/v4.0/content/images/{extId}` | **dry_run** |\n| `category_list` | read | `GET /api/prism/v4.0/config/categories` | key, value, extId |\n| `category_create` | write · low | `POST /api/prism/v4.0/config/categories` | new category extId |\n| `category_assign` | write · med | `POST …/categories/{extId}/$actions/associate` | **bulk-assign** a category to many VMs |\n\n## Data protection / DR (3 read, 5 write)\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `snapshot_list` | read | `GET …/vms/{extId}` recovery points | per-VM snapshots (extId, name, created) |\n| `recovery_point_list` | read | `GET /api/dataprotection/v4.0/config/recovery-points` | recovery points across estate |\n| `protection_domain_list` | read | `GET /api/dataprotection/v4.0/config/protection-policies` | protection policies / domains |\n| `snapshot_create` | write · low | `POST …/vms/{extId}` recovery point | new snapshot extId |\n| `snapshot_delete` | write · **HIGH** | `DELETE …/recovery-points/{extId}` | **dry_run** |\n| `snapshot_restore` | write · **HIGH** | `POST …/$actions/restore` | **dry_run** |\n| `vm_protect` | write · med | `POST …/protection-policies` associate | attach a VM to a protection policy |\n| `pd_failover` | write · **HIGH** | `POST …/$actions/failover` | **dry_run** |\n\n## Alerts (4 read, 2 write)\n\n| Tool | Risk | API path | Returns |\n|------|------|----------|---------|\n| `alert_list` | read | `GET /api/monitoring/v4.0/serviceability/alerts` | active alerts (severity, impact, source) |\n| `event_list` | read | `GET /api/monitoring/v4.0/serviceability/events` | recent events |\n| `audit_list` | read | `GET /api/prism/v4.0/config/audits` | Prism audit records |\n| `analyze_alert` | read | correlates alert + related events | **RCA (flagship read)** — probable cause + suggested actions |\n| `alert_acknowledge` | write · low | `POST …/alerts/{extId}/$actions/acknowledge` | ack a live alert |\n| `alert_resolve` | write · low | `POST …/alerts/{extId}/$actions/resolve` | resolve a live alert |\n\n## LCM — upgrades (1 read, 2 write)\n\n| Tool | Risk | API path | Returns |\n|------|------|----------|---------|\n| `lcm_inventory` | read | `GET /api/lifecycle/v4.0/resources/entities` | firmware / software entities + available versions |\n| `lcm_precheck` | write · medium | `POST /api/lifecycle/v4.0/resources/$actions/perform-precheck` | precheck task ref |\n| `lcm_update` | write · **HIGH** | `POST /api/lifecycle/v4.0/resources/$actions/perform-update` | **firmware/software update**; **dry_run**; **refused unless `precheck_task_ext_id` names a precheck task that reached SUCCEEDED** |\n\n## Capacity (2 read)\n\n| Tool | API path | Returns |\n|------|----------|---------|\n| `task_list` | `GET /api/prism/v4.0/config/tasks` | recent Prism tasks (status, entity, progress) |\n| `capacity_runway` | derived from cluster utilization | **days-to-full forecast** per resource |\n\n## Diagnostics / RCA (2 read)\n\nRead-only signature analyses (`risk_level=\"low\"`). Both are **pure and\ndeterministic** — no clock, no randomness — and every finding carries the\nmeasured number or raw Prism state that tripped it, alongside a probable cause\nand a concrete action. Findings are returned worst-first\n(critical → warning → info) with the shape\n`{severity, resource, signal, detail, cause, action}`.\n\n| Tool | API paths read | Returns |\n|------|----------------|---------|\n| `cluster_health_rca` | `clusters` + `clusters/{extId}` + `hosts` + `storage-containers` | findings for degraded `faultToleranceState`, cluster storage pool and storage containers over **80% (warning) / 90% (critical)**, hosts whose `nodeStatus` is unhealthy, and clusters with fewer visible hosts than their `nodeCount`; plus a `summary` of every measured percentage |\n| `alert_triage_rca` | `serviceability/alerts` | active (unresolved) alerts grouped by severity with a per-level count, unacknowledged criticals called out, and `oldestUnresolved` (title, severity, `ageDays`) — an alert open **≥ 7 days** is flagged stale |\n\n`alert_triage_rca` is the fleet-level lens; `analyze_alert` is the per-alert\nlens (event correlation on one alert's affected entity). They compose: triage\nfirst to pick the extId, then analyze it.\n\n## Undo (1 read, 1 write)\n\n| Tool | Risk | Returns / effect |\n|------|:----:|------------------|\n| `undo_list` | low | recorded, not-yet-applied reversible writes — `undoId`, original tool, inverse tool, note |\n| `undo_apply` | medium | executes a recorded inverse descriptor; itself governed and audited, single-use, supports `dry_run` |\n\n## ETag / pagination / mixed hypervisor\n\n- **ETag / If-Match** — the v4 API rejects an update or delete without the\n  current entity's ETag. Every mutation here fetches the ETag and sends\n  `If-Match` for you (the common v4 footgun); `vm_get` / `subnet_get` surface it\n  for inspection.\n- **Pagination** — all list tools follow `$page` / `$limit` and return the full\n  set, not just page one.\n- **Mixed hypervisor** — `vm_list` returns both **AHV** and **ESXi** VMs managed\n  by the same Prism Central (relevant to hypervisor-migration estates).\n\n## Out of scope (by design, this release)\n\n- IAM / users / roles / SAML, Files / Objects / Volumes services\n- Report generation, X-Play / playbooks, calm / self-service\n- Anything outside Prism Central v4 (direct Prism Element, ncli/acli)\n\nWant one of these? Open an issue or PR — feedback and contributions welcome.\n</content>\n</invoke>\n\nFile v0.11.2:references/cli-reference.md\n\n# nutanix-aiops CLI reference\n\n> Talks to Nutanix **Prism Central v4** on HTTPS `:9440`\n> with HTTP Basic auth. The CLI is a convenience subset; the full **51-tool**\n> surface is via the MCP server (`nutanix-aiops mcp`).\n\n## Setup & diagnostics\n\n```bash\nnutanix-aiops init                      # interactive onboarding wizard\nnutanix-aiops doctor [--skip-auth]      # config + secret store + connectivity + REST-RBAC preflight\nnutanix-aiops mcp                       # start the MCP server (stdio transport)\n```\n\n`doctor` checks the config file, the encrypted secret store and its permissions,\nthat a password is present per target, and (unless `--skip-auth`) connectivity\nplus a **REST-RBAC preflight** against Prism Central — confirming the account can\nactually call the v4 APIs, not just log in to the Web UI.\n\n## Estate & clusters (read)\n\n```bash\nnutanix-aiops overview [--target <t>]              # one-shot estate summary\nnutanix-aiops cluster list                         # registered clusters (extId, AOS, hypervisors, nodes)\nnutanix-aiops cluster health <cluster_ext_id>      # services, resiliency, upgrade state\nnutanix-aiops cluster hosts                         # hosts across all clusters\nnutanix-aiops cluster util <cluster_ext_id>        # CPU / memory / storage / IOPS utilization\n```\n\n## Diagnostics / RCA (read-only)\n\n```bash\nnutanix-aiops diagnose cluster-health              # resiliency, storage >80%/>90%, nodes down — worst first\nnutanix-aiops diagnose alert-triage                # active alerts by severity + oldest unresolved\n```\n\nBoth print a worst-first findings table (severity · resource · signal · detail ·\naction) or a green all-clear line when every measured value is under threshold.\n\n## VMs\n\n```bash\nnutanix-aiops vm list [--esxi | --no-esxi]         # AHV + ESXi VMs (ESXi included by default)\nnutanix-aiops vm get <vm_ext_id>                   # one VM detail (shows its ETag)\nnutanix-aiops vm power <vm_ext_id> <on|off|shutdown|reboot> [--dry-run]\nnutanix-aiops vm delete <vm_ext_id> [--dry-run]    # (HIGH) dry-run + double confirm\nnutanix-aiops vm migrate <vm_ext_id> <target_host_ext_id> [--dry-run]   # (HIGH) dry-run + double confirm\n```\n\n## Secrets (encrypted store `~/.nutanix-aiops/secrets.enc`)\n\n```bash\nnutanix-aiops secret set <target> [--value <pw>]   # store PC password (hidden prompt if no --value)\nnutanix-aiops secret list                           # names only — values never shown\nnutanix-aiops secret rm <target>\nnutanix-aiops secret migrate                        # import legacy plaintext env (NUTANIX_<T>_PASSWORD)\nnutanix-aiops secret rotate-password                # re-encrypt the store under a new master password\n```\n\n## Common options\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default / first target)\n- `--dry-run` — print the API call that would be made, change nothing\n- `--esxi / --no-esxi` — include or exclude ESXi-managed VMs in `vm list` (default: include)\n- Destructive commands (`vm delete`, `vm migrate`) require a `--dry-run` preview and **two confirmations**\n\n## Full surface via MCP\n\nThe 51 governed tools (clusters, VMs, storage, network, catalog, data\nprotection / DR, alerts + `analyze_alert` RCA, LCM upgrades, capacity runway,\nand the `cluster_health_rca` / `alert_triage_rca` diagnostics)\nare exposed by `nutanix-aiops mcp`. Set `NUTANIX_AIOPS_MASTER_PASSWORD` so the\nencrypted store unlocks non-interactively. See `capabilities.md` for the full\ntool → API-path → returns map.\n</content>\n\nFile v0.11.2:references/setup-guide.md\n\n# nutanix-aiops setup & security guide\n\n> Currently validated against mocked v4 REST responses; see `docs/VERIFICATION.md`\n> in the repo for the live-verification checklist.\n\n## 1. Install\n\n```bash\nuv tool install nutanix-aiops          # or: pipx install nutanix-aiops\n```\n\n## 2. Prepare a Prism Central account (with REST API rights)\n\nnutanix-aiops connects to **Prism Central** on HTTPS port **9440** and\nauthenticates the v4 REST APIs with **HTTP Basic auth** (username + password).\n\n> **Important gotcha:** the account needs **REST API** rights, not just Web UI\n> access. A user that can log into the Prism Central console may still be denied\n> at the API. Give the account a role with the v4 API permissions it needs\n> (read for the estate; the relevant lifecycle/VM/storage/DR permissions for any\n> writes). `nutanix-aiops doctor` runs a REST-RBAC preflight to catch this early.\n\n## 3. Onboard\n\n```bash\nnutanix-aiops init\n```\n\nThe wizard collects the (non-secret) connection details into\n`~/.nutanix-aiops/config.yaml` and stores the **password encrypted** into\n`~/.nutanix-aiops/secrets.enc`. Example config:\n\n```yaml\ntargets:\n  - name: pc1\n    host: 10.0.0.20        # Prism Central IP / FQDN\n    port: 9440\n    username: admin        # PC account with REST API rights\n    verify_ssl: false      # self-signed lab / CE certs only\n```\n\nThe `username` is not a secret and lives in the config file; the password lives\nonly in the encrypted store.\n\n## 4. Non-interactive use (MCP server / CI / cron)\n\nExport the master password so the encrypted store unlocks without a prompt:\n\n```bash\nexport NUTANIX_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n## Credential security\n\n- The Prism Central password is **never** written to disk in plaintext. It lives\n  only in `~/.nutanix-aiops/secrets.enc`, encrypted with Fernet (AES-128-CBC +\n  HMAC), the key derived from your master password via scrypt. Only a per-store\n  random salt and the ciphertext are on disk (chmod 600); the master password\n  itself is never stored.\n- A legacy plaintext env var `NUTANIX_<TARGET_NAME_UPPER>_PASSWORD` is still\n  honoured as a fallback with a deprecation warning — migrate with\n  `nutanix-aiops secret migrate`.\n- The password is held only in memory during a session and is never logged or\n  echoed; exception text and tracebacks are scrubbed of secret-shaped strings\n  before being written to the audit log.\n\n## Optional audit annotations\n\nThe skill does not decide whether a write is permitted — that is the agent's\njudgement, or the permission of the account you connect it with (connect with\na Prism Central account holding only a read-only (Viewer) role, and writes\nfail at the server). `NUTANIX_AUDIT_APPROVED_BY` / `NUTANIX_AUDIT_RATIONALE`\noptionally annotate the audit row with who authorized a high-risk operation\nand why — they are never required and never block a call:\n\n```bash\nexport NUTANIX_AUDIT_APPROVED_BY='alice@example.com'\nexport NUTANIX_AUDIT_RATIONALE='Decommissioning migrated ESXi guest per CHG-1234'\n```\n\n## Governance harness state\n\nState lives under `~/.nutanix-aiops/` (relocate with `NUTANIX_AIOPS_HOME`):\n\n- `audit.db` — every tool call (SQLite), with risk tier and any approver/rationale supplied\n- `undo.db` — inverse descriptors for reversible writes (e.g. `vm_update` prior\n  CPU/memory, `vm_migrate` prior host)\n- budget / runaway guard — caps cumulative tool calls and wall-time; trips on\n  tight poll/retry loops\n\n## Self-test for free (Community Edition)\n\nYou can validate end-to-end at no cost with **Nutanix Community Edition (CE)**:\na single-node CE cluster plus an **X-Small Prism Central** VM. Point a `pc1`\ntarget at that PC on `:9440` and run the read tools; exercise the writes against\nthrowaway VMs / snapshots.\n\n## Verify\n\n```bash\nnutanix-aiops doctor\n```\n\n`doctor` is the fastest live check — config, encrypted store + permissions, a\npassword per target, connectivity to Prism Central `:9440`, and the REST-RBAC\npreflight.\n</content>\n\nFile v0.11.2:skill-card.md\n\n## Description:\n\nNutanix AIops helps an agent operate a Nutanix Prism Central v4 estate across cluster health, inventory, VM lifecycle, storage, networking, data protection, alerts, LCM, capacity forecasting, and diagnostics with governed MCP and CLI workflows.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, platform engineers, and operations teams use this skill to inspect and administer Nutanix Prism Central v4 environments, including health triage, VM lifecycle tasks, DR actions, LCM workflows, and capacity planning. It is intended for Nutanix Prism Central targets only and not for non-Nutanix infrastructure.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can perform destructive Nutanix infrastructure changes.\n\nMitigation: Use least-privileged or Viewer accounts first, require operator review for writes, and run destructive actions through dry-run before execution.\n\nRisk: The skill persists local credentials and can unlock them from an environment-variable master password.\n\nMitigation: Protect the local credential store and master password, avoid plaintext legacy password variables, and rotate or migrate secrets when needed.\n\nRisk: The release installs a mutable external executable package.\n\nMitigation: Prefer a pinned or otherwise verified package release before using the skill with production Prism Central credentials.\n\n## Reference(s):\n\n- [Nutanix AIops Homepage](https://github.com/AIops-tools/Nutanix-AIops)\n- [capabilities.md](references/capabilities.md)\n- [cli-reference.md](references/cli-reference.md)\n- [setup-guide.md](references/setup-guide.md)\n- [agent-guardrails.md](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown prose with inline shell commands and structured tool outputs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include Prism Central identifiers, task references, diagnostics summaries, dry-run previews, and configuration steps.]\n\n## Skill Version(s):\n\n0.11.2 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.1: 7 files, 19210 bytes\n\nFiles: references/agent-guardrails.md (9493b), references/capabilities.md (9075b), references/cli-reference.md (3528b), references/setup-guide.md (3988b), skill-card.md (2762b), SKILL.md (13171b), _meta.json (133b)\n\nFile v0.11.1:SKILL.md\n\n---\nname: nutanix-aiops\nslug: nutanix-aiops\ndisplayName: \"Nutanix AIops\"\nsummary: \"Governed Nutanix Prism Central v4 ops: clusters/VMs/storage/DR/LCM/RCA, ETag-safe, 51 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Nutanix-AIops\ntags: [aiops, mcp, governance, nutanix]\ndescription: >\n  Use this skill whenever the user needs to operate a Nutanix estate through Prism Central (v4 REST API) — an estate/cluster health overview, cluster & host inventory and utilization, VM lifecycle across AHV and ESXi (list/get/power/create/update/clone/delete/migrate), storage containers, subnets/network, images & categories, data protection / DR (snapshots, recovery points, protection domains, VM protect, failover), alerts & events with alert RCA (analyze_alert), LCM firmware/software upgrades, capacity runway forecasting, and read-only diagnostics/RCA over the whole estate (cluster_health_rca, alert_triage_rca).\n  Always use this skill for \"Nutanix\", \"Prism Central\", \"AHV\", \"cluster health\", \"list VMs\", \"power on/off a VM\", \"clone/migrate a VM\", \"delete a VM\", \"snapshot\", \"recovery point\", \"protection domain\", \"failover\", \"why did this alert fire\" / \"root cause this alert\", \"LCM upgrade / firmware\", \"days until storage is full\" / \"capacity runway\", \"what's wrong with my cluster\" / \"diagnose the estate\", \"triage my alerts\", when the context is a Nutanix cluster or Prism Central.\n  Do NOT use when the target is a non-Nutanix platform — those belong to their own AIops-tools sibling; this skill is Prism Central v4 only.\n  Governed Nutanix Prism Central operations with a built-in governance harness (audit, token budget, undo, descriptive risk-tier labels).\ninstaller:\n  kind: uv\n  package: nutanix-aiops\nargument-hint: \"[VM/cluster extId or describe your Nutanix task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"nutanix-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"NUTANIX_AIOPS_CONFIG\",\"NUTANIX_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Nutanix-AIops\",\"emoji\":\"🧊\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed Nutanix Prism Central operations. The governance harness (audit, token/runaway budget, undo, descriptive risk-tier labels) is bundled in the package — no external skill-family dependency.\n  Connects to Prism Central on HTTPS :9440 with HTTP Basic auth (username + password). The v4 REST API requires an ETag/If-Match on every mutation; nutanix-aiops fetches and sends it automatically. All list tools paginate automatically; vm_list returns both AHV and ESXi VMs.\n  All write operations are audited to a local SQLite DB under ~/.nutanix-aiops/ (relocatable via NUTANIX_AIOPS_HOME).\n  Credentials: the Prism Central password is stored ENCRYPTED in ~/.nutanix-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'nutanix-aiops init' to onboard, or 'nutanix-aiops secret set <target>' to add one. The store is unlocked by a master password from NUTANIX_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). A legacy plaintext env var NUTANIX_<TARGET_NAME_UPPER>_PASSWORD is still honoured as a fallback with a deprecation warning (migrate with 'nutanix-aiops secret migrate'). The account needs REST API rights, not just Web UI access.\n  State-changing operations require the @governed_tool decorator (budget guard + audit + risk-tier tagging). The skill does not decide whether a write is permitted — that is the agent's judgement or the connecting account's permissions. High-risk ops (vm_delete, vm_migrate, storage_container_delete, subnet_delete, snapshot_delete, snapshot_restore, pd_failover, image_delete, lcm_update) support dry_run and, at the CLI, double confirmation; reversible writes record an undo descriptor (vm_update → prior CPU/memory, vm_migrate → prior host).\n  NUTANIX_AUDIT_APPROVED_BY and NUTANIX_AUDIT_RATIONALE are optional annotations recorded on the audit row (who/why); they are never required and never block a call.\n  SSL: verify_ssl defaults to true; disable only for self-signed lab / Community Edition certificates.\n  Transitive dependencies: httpx (HTTP client) and the MCP SDK. No post-install scripts or background services.\n  Validation status: behaviour is currently validated against mocked v4 REST responses; the LCM update, PD failover, and ESXi-VM listing paths in particular still need live verification (self-testable free on Nutanix Community Edition + X-Small Prism Central). See docs/VERIFICATION.md in the repo for the live-verification checklist.\n---\n\n# Nutanix AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by Nutanix.** Product and trademark names belong to their owners. Source at [github.com/AIops-tools/Nutanix-AIops](https://github.com/AIops-tools/Nutanix-AIops) under the MIT license.\n\nGoverned Nutanix **Prism Central (v4 REST API)** operations — **51 MCP tools**, every one wrapped with the bundled `@governed_tool` harness: a local unified audit log under `~/.nutanix-aiops/`, token/runaway budget guard, undo-token recording, and descriptive risk-tier labels. The Prism Central password is stored **encrypted** (`~/.nutanix-aiops/secrets.enc`, Fernet + scrypt) — never plaintext on disk.\n\n**What sets it apart** from read-only Nutanix MCPs: (1) automatic **ETag / If-Match** on every mutation — the v4 footgun handled for you; (2) automatic **pagination**; (3) **mixed-hypervisor** VM listing (AHV + ESXi, relevant to hypervisor-migration estates); and (4) the governance harness with **dry-run + double-confirm** on destructive writes.\n\n> **Standalone**: the governance harness is bundled in the package (`nutanix_aiops.governance`) — no external skill-family dependency.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read / Write |\n|-------|-------|:-----:|:------------:|\n| **Clusters** | cluster_list, cluster_health, host_list, cluster_utilization | 4 | 4 read |\n| **VMs** | list, get, power_on, guest_shutdown, power_off, reboot, create, update, clone, delete, migrate | 11 | 2 read · 9 write |\n| **Storage** | container list / create / update / delete | 4 | 1 read · 3 write |\n| **Network** | subnet list / get / create / delete | 4 | 2 read · 2 write |\n| **Catalog** | image list / delete, category list / create / assign | 5 | 2 read · 3 write |\n| **Data protection / DR** | snapshot list/create/delete/restore, recovery_point_list, protection_domain_list, vm_protect, pd_failover | 8 | 3 read · 5 write |\n| **Alerts** | alert_list, event_list, audit_list, **analyze_alert (RCA)**, alert_acknowledge, alert_resolve | 6 | 4 read · 2 write |\n| **LCM (upgrades)** | lcm_inventory, lcm_precheck, lcm_update | 3 | 1 read · 2 write |\n| **Capacity** | task_list, capacity_runway | 2 | 2 read |\n| **Diagnostics / RCA** | **cluster_health_rca**, **alert_triage_rca** | 2 | 2 read |\n| **Undo** | `undo_list`, `undo_apply` | 2 | 1 read · 1 write |\n| **Total** | | **51** | 24 read · 27 write |\n\nThe CLI is a convenience subset; the full 51-tool surface is via the MCP server. See `references/capabilities.md` for the tool → API-path → returns map.\n\n## Quick Install\n\n```bash\nuv tool install nutanix-aiops\nnutanix-aiops init       # interactive wizard: PC host/port 9440/username + encrypted password\nnutanix-aiops doctor     # connectivity + REST-RBAC preflight\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@aiops-tools/nutanix-aiops\nopenclaw skills info nutanix-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Diagnose the estate in one shot (`diagnose cluster-health`): degraded resiliency, storage pools/containers over 80% / 90%, nodes down or missing — worst-first, each finding citing the measured number\n- Triage the alert backlog (`diagnose alert-triage`): per-severity counts, unacknowledged criticals, the oldest unresolved alert and its age\n- Inspect the estate (`overview`, `cluster health`, `cluster util`): clusters, hosts, resiliency, utilization\n- VM lifecycle across **AHV + ESXi** (`vm list/get/power/create/update/clone`), and guarded destructive ops (`vm delete`, `vm migrate`) with dry-run + double-confirm\n- Root-cause an alert (`analyze_alert`) — correlate it with related events into a probable-cause + suggested-actions summary\n- Data protection: snapshots, recovery points, protection domains, `vm_protect`, `pd_failover`\n- Upgrades (`lcm_inventory` → `lcm_precheck` → `lcm_update`) and capacity forecasting (`capacity_runway`)\n\n**Do NOT use when** the target is a non-Nutanix platform — this skill is Prism Central v4 only. For other infrastructure, use the appropriate **other AIops-tools** sibling.\n\n## Common Workflows\n\n### \"Something is wrong with the estate\" → diagnose, then act\n\n1. `nutanix-aiops diagnose cluster-health` → worst-first findings, e.g.\n   `critical · prod-cluster · storage container near full · 93.0% used >= 90.0% threshold`\n2. `storage_container_list` → confirm which container it is and what its\n   `maxCapacityBytes` / `logicalUsageBytes` actually are\n3. `recovery_point_list` / `snapshot_list <vm_ext_id>` → the usual culprit is\n   snapshot sprawl in that container\n4. `snapshot_delete <…> --dry-run` to preview, then re-run to reclaim space —\n   optionally set `NUTANIX_AUDIT_APPROVED_BY` first to annotate who authorized\n   it; each deletion is audited and records an undo descriptor\n5. Re-run `diagnose cluster-health` → the finding should drop below the 80%\n   warning threshold; the before/after percentages are your evidence\n\n### Triage a cluster alert (RCA)\n\n1. `nutanix-aiops diagnose alert-triage` (or `alert_list`) → per-severity counts and the oldest unresolved alert, so you know which extId to open first\n2. `analyze_alert <alert_ext_id>` → probable cause + suggested actions, built by correlating the alert with related `event_list` records\n3. Confirm blast radius with `cluster_health` / `cluster_utilization`, then `alert_acknowledge` (or `alert_resolve` once fixed)\n\n### Safely delete a VM (high-risk, audited)\n\n1. `vm_get <vm_ext_id>` → confirm it's the right VM (and see its ETag)\n2. `nutanix-aiops vm delete <vm_ext_id> --dry-run` → preview the exact `DELETE` call\n3. Optionally annotate who/why: `export NUTANIX_AUDIT_APPROVED_BY=… NUTANIX_AUDIT_RATIONALE=…`\n4. Re-run without `--dry-run` (double-confirm at the CLI); the call is audited with\n   tier and any approver/rationale supplied\n\n### Snapshot sprawl cleanup\n\n1. `recovery_point_list` (or per-VM `snapshot_list <vm_ext_id>`) → find stale / redundant snapshots\n2. `snapshot_delete <…> --dry-run` on each candidate → preview\n3. Re-run without dry-run (HIGH risk, double-confirm at the CLI) to reclaim space; each deletion is audited\n\n### Capacity runway\n\n1. `cluster_utilization <cluster_ext_id>` → current CPU / memory / storage / IOPS\n2. `capacity_runway` → days-to-full forecast per resource; use it to schedule an `lcm` expansion or storage add before you hit the wall\n\n### Migrate a VM to another host (reversible)\n\n1. `host_list` → pick the destination host extId\n2. `nutanix-aiops vm migrate <vm_ext_id> <target_host_ext_id> --dry-run` → preview\n3. Re-run without dry-run (HIGH, double-confirm); the **prior host is captured as an undo descriptor** so a regression can be reversed\n\n## Governance & Safety\n\nThe skill delivers reads and writes and records them; it does **not** decide whether a write is\npermitted. That is your agent's judgement, or the permission of the account you connect it with\n(connect with a Prism Central account holding only a read-only (Viewer) role — writes then fail\nat the server). There is no read-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.nutanix-aiops/audit.db` (relocatable via `NUTANIX_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- `NUTANIX_AUDIT_APPROVED_BY` / `NUTANIX_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Runaway guard** — a safety backstop, not authorization: the same call looped in a tight window trips a circuit breaker. Disable with `NUTANIX_RUNAWAY_MAX=0`.\n- Every mutation auto-handles **ETag / If-Match**; every list auto-paginates.\n- Destructive writes support `dry_run` / `--dry-run` and, at the CLI, double confirmation.\n- Reversible writes record an undo descriptor (`vm_update` → prior CPU/memory, `vm_migrate` → prior host).\n\n## References\n\n- `references/capabilities.md` — full 51-tool + API-path reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — onboarding, credentials, REST-RBAC, CE self-test\n- `references/agent-guardrails.md` — which guardrails the harness enforces for you, and a ready-to-paste system prompt for smaller / local models\n</content>\n\nFile v0.11.1:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"nutanix-aiops\",\n  \"version\": \"0.11.1\",\n  \"publishedAt\": 1789208360395\n}\n\nFile v0.11.1:references/agent-guardrails.md\n\n# Agent guardrails — running nutanix-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## What the tool now enforces — do not waste prompt budget on these\n\nAuthorization is not this tool's job — decide it via the account you connect it\nwith, or the agent's own prompt. What the harness does guarantee:\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Fetch the ETag before you change anything\" | Prism Central v4 requires an `If-Match` ETag on most mutations (optimistic concurrency). Every write tool fetches the entity's current ETag itself and sends it back. There is **no ETag parameter for the model to get wrong**, and no read it must remembe\n\nArchive v0.11.0: 7 files, 18963 bytes\n\nFiles: references/agent-guardrails.md (9493b), references/capabilities.md (9075b), references/cli-reference.md (3528b), references/setup-guide.md (3988b), skill-card.md (2608b), SKILL.md (12857b), _meta.json (133b)\n\nArchive v0.10.0: 7 files, 19091 bytes\n\nFiles: references/agent-guardrails.md (9493b), references/capabilities.md (9075b), references/cli-reference.md (3528b), references/setup-guide.md (3988b), skill-card.md (2828b), SKILL.md (12965b), _meta.json (133b)\n\nArchive v0.9.0: 7 files, 19021 bytes\n\nFiles: references/agent-guardrails.md (9493b), references/capabilities.md (9075b), references/cli-reference.md (3528b), references/setup-guide.md (3988b), skill-card.md (2812b), SKILL.md (12965b), _meta.json (132b)\n\nArchive v0.8.0: 7 files, 19289 bytes\n\nFiles: references/agent-guardrails.md (9493b), references/capabilities.md (9075b), references/cli-reference.md (3528b), references/setup-guide.md (3988b), skill-card.md (3353b), SKILL.md (12965b), _meta.json (132b)\n\nArchive v0.7.0: 7 files, 19248 bytes\n\nFiles: references/agent-guardrails.md (9493b), references/capabilities.md (9075b), references/cli-reference.md (3528b), references/setup-guide.md (3988b), skill-card.md (3189b), SKILL.md (12965b), _meta.json (132b)\n\nArchive v0.6.0: 7 files, 19309 bytes\n\nFiles: references/agent-guardrails.md (9493b), references/capabilities.md (9075b), references/cli-reference.md (3528b), references/setup-guide.md (3988b), skill-card.md (3376b), SKILL.md (12965b), _meta.json (132b)","readmeExcerpt":"Skill: nutanix-aiops Owner: zw008 Summary: Use this skill whenever the user needs to operate a Nutanix estate through Prism Central (v4 REST API) — an estate/cluster health overview, cluster & host inventory and utilization, VM lifecycle across AHV and ESXi (list/get/power/create/update/clone/delete/migrate), storage containers, subnets/network, images & categories, data protection / DR (snapshots, recovery points, p","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"uv tool install nutanix-aiops\nnutanix-aiops init       # interactive wizard: PC host/port 9440/username + encrypted password\nnutanix-aiops doctor     # connectivity + REST-RBAC preflight"},{"language":"bash","snippet":"openclaw plugins install clawhub:@zw008/nutanix-aiops\nopenclaw skills info nutanix-aiops          # expect: Visible to model: yes"},{"language":"text","snippet":"You operate a Nutanix Prism Central (v4) environment through the nutanix-aiops\nMCP tools.\n\nTOOL USE\n- Before answering any question about the current Nutanix environment, you MUST\n  call a tool. Never answer from memory or assumption.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. Never fill the gap with\n  a plausible-sounding answer.\n\nIDENTIFIERS\n- Every entity is identified by an opaque extId (a UUID). Copy an extId verbatim\n  from a tool result. Never retype, abbreviate, reformat, or reconstruct one.\n- extIds are NOT interchangeable by type. A VM extId, a cluster extId, a host\n  extId, a subnet extId, a storage-container extId, a recovery-point extId and\n  a task extId are different namespaces that look identical. Passing a cluster\n  extId where a VM extId is wanted is the single most common failure here.\n- Call cluster_list first — most other tools need a clusterExtId from it, and\n  vm_list / host_list give you the VM and host extIds.\n\nREADING RESULTS\n- Read the whole result before concluding. If a result has \"truncated\": true,\n  say so and re-run with a higher limit instead of treating the partial result\n  as complete.\n- A null field means Prism Central did not return that value. Report it as \"not\n  available\" — never infer it.\n- Report values exactly as returned. Do not normalise, translate, or prettify\n  power states, severities, fault-tolerance states, or extIds.\n- When a cluster_health_rca or alert_triage_rca result has findings, work in\n  \"rank\" order and cite the measured number in each finding's \"detail\".\n\nWRITES\n- Run the dry_run=True form of a destructive tool and show the operator what it\n  would change before running it for real.\n- Async writes return a task extId, not a result. Poll task_list for its status\n  rather than assuming the operation finished.\n\n- Only `vm_delete` and `vm_migrate` have CLI commands"},{"language":"bash","snippet":"nutanix-aiops doctor"},{"language":"bash","snippet":"export NUTANIX_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport NUTANIX_AUDIT_RATIONALE=\"scheduled maintenance window 2026-07-20\""},{"language":"bash","snippet":"nutanix-aiops init                      # interactive onboarding wizard\nnutanix-aiops doctor [--skip-auth]      # config + secret store + connectivity + REST-RBAC preflight\nnutanix-aiops mcp                       # start the MCP server (stdio transport)"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: nutanix-aiops\nslug: nutanix-aiops\ndisplayName: \"Nutanix AIops\"\nsummary: \"Governed Nutanix Prism Central v4 ops: clusters/VMs/storage/DR/LCM/RCA, ETag-safe, 51 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Nutanix-AIops\ntags: [aiops, mcp, governance, nutanix]\ndescription: >\n  Use this skill whenever the user needs to operate a Nutanix estate through Prism Central (v4 REST API) — an estate/cluster health overview, cluster & host inventory and utilization, VM lifecycle across AHV and ESXi (list/get/power/create/update/clone/delete/migrate), storage containers, subnets/network, images & categories, data protection / DR (snapshots, recovery points, protection domains, VM protect, failover), alerts & events with alert RCA (analyze_alert), LCM firmware/software upgrades, capacity runway forecasting, and read-only diagnostics/RCA over the whole estate (cluster_health_rca, alert_triage_rca).\n  Always use this skill for \"Nutanix\", \"Prism Central\", \"AHV\", \"cluster health\", \"list VMs\", \"power on/off a VM\", \"clone/migrate a VM\", \"delete a VM\", \"snapshot\", \"recovery point\", \"protection domain\", \"failover\", \"why did this alert fire\" / \"root cause this alert\", \"LCM upgrade / firmware\", \"days until storage is full\" / \"capacity runway\", \"what's wrong with my cluster\" / \"diagnose the estate\", \"triage my alerts\", when the context is a Nutanix cluster or Prism Central.\n  Do NOT use when the target is a non-Nutanix platform — those belong to their own AIops-tools sibling; this skill is Prism Central v4 only.\n  Governed Nutanix Prism Central operations with a built-in governance harness (audit, token budget, undo, descriptive risk-tier labels).\ninstaller:\n  kind: uv\n  package: nutanix-aiops\nargument-hint: \"[VM/cluster extId or describe your Nutanix task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"nutanix-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"NUTANIX_AIOPS_CONFIG\",\"NUTANIX_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Nutanix-AIops\",\"emoji\":\"🧊\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone, self-governed Nutanix Prism Central operations. The governance harness (audit, token/runaway budget, undo, descriptive risk-tier labels) is bundled in the package — no external skill-family dependency.\n  Connects to Prism Central on HTTPS :9440 with HTTP Basic auth (username + password). The v4 REST API requires an ETag/If-Match on every mutation; nutanix-aiops fetches and sends it automatically. All list tools paginate automatically; vm_list returns both AHV and ESXi VMs.\n  All write operations are audited to a local SQLite DB under ~/.nutanix-aiops/ (relocatable via NUTANIX_AIOPS_HOME).\n  Credentials: the Prism Central password is stored ENCRYPTED in ~/.nutanix-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'nutanix-aiops init' to onboard, or 'nutanix-aiops secret set <target>' to add one. The store is unlocked by a master password from NUTANIX_AIOPS_MASTER_PA"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"nutanix-aiops\",\n  \"version\": \"0.11.4\",\n  \"publishedAt\": 1789601176071\n}"},{"path":"references/agent-guardrails.md","content":"# Agent guardrails — running nutanix-aiops with a smaller / local model\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\nThe distinction matters. A guardrail in a prompt is a request. A guardrail in the\nharness is a guarantee. Anything below that we could move into the harness, we did.\n\n## What the tool now enforces — do not waste prompt budget on these\n\nAuthorization is not this tool's job — decide it via the account you connect it\nwith, or the agent's own prompt. What the harness does guarantee:\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Fetch the ETag before you change anything\" | Prism Central v4 requires an `If-Match` ETag on most mutations (optimistic concurrency). Every write tool fetches the entity's current ETag itself and sends it back. There is **no ETag parameter for the model to get wrong**, and no read it must remember to run first. |\n| \"Don't invent a value when a field is missing\" | A field Prism Central did not return comes back as `null`, never as `\"\"`. Absent and empty are distinguishable in the payload — which matters here, because v4 omits a great many fields (`description`, `hypervisorType`, host and cluster names, LCM version strings, alert `impactType`). |\n| \"Tell me if the output was cut off\" | Every list tool returns `{\"<items>\": [...], \"returned\": N, \"limit\": L, \"truncated\": true/false}`. Truncation is **measured** (one extra row is fetched), not guessed from a length coincidence. `vm_list`, `cluster_list`, `host_list`, `alert_list`, `event_list`, `audit_list`, `task_list`, `image_list`, `category_list`, `subnet_list`, `snapshot_list`, `recovery_point_list`, `protection_domain_list`, `storage_container_list`, `lcm_inventory` and `undo_list` all take a `limit` and report against it. |\n| \"Preserve the ordering / tell me what's most urgent\" | `cluster_health_rca` and `alert_triage_rca` findings carry an explicit 1-based `rank`, worst-first. Priority is in the payload, not implied by list position, and every finding cites the measured percentage or the raw Prism state string that tripped it. |\n| \"Confirm before anything destructive\" | Destructive tools (`vm_delete`, `vm_migrate`, `snapshot_delete`, `snapshot_restore`, `image_delete`, `subnet_delete`, `storage_container_delete`, `lcm_update`, `pd_failover`) take `dry_run=True` for a preview and are `risk=high`, tagged `review` on the audit row. ⚠️ **The CLI double confirmation exists only for `vm_delete` and `vm_migrate`** — the other seven have no CLI command and are reachable only over MCP, where nothing prompts. Keep your own confirmation for those. |\n| \"Run the LCM precheck before upgrading\" | `lcm_update` **refuses** unless you hand back th"},{"path":"references/capabilities.md","content":"# nutanix-aiops capabilities\n\n> **51 MCP tools** (24 read, 27 write) over the Nutanix\n> **Prism Central v4 REST API** (HTTPS :9440, HTTP Basic auth). Every mutation\n> handles **ETag / If-Match** automatically; every list is **paginated**\n> automatically. Paths below are the v4 API prefixes actually called; validate\n> against a live Prism Central / Community Edition before production use.\n\n## Clusters (4 read)\n\n| Tool | API path | Returns |\n|------|----------|---------|\n| `cluster_list` | `GET /api/clustermgmt/v4.0/config/clusters` | extId, name, AOS version, hypervisors, node count |\n| `cluster_health` | `GET /api/clustermgmt/v4.0/config/clusters/{extId}` | services, resiliency / fault-tolerance, upgrade state |\n| `host_list` | `GET /api/clustermgmt/v4.0/config/hosts` | host extId, cluster, hypervisor, CPU / memory |\n| `cluster_utilization` | `GET /api/clustermgmt/v4.0/config/clusters/{extId}` | point-in-time CPU / memory / storage / IOPS |\n\n## VMs (2 read, 9 write) — base `GET /api/vmm/v4.0/ahv/config/vms`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `vm_list` | read | `GET …/vms` (paginated) | VMs across **AHV + ESXi** (extId, name, cluster, power, vCPU, mem, hypervisor) |\n| `vm_get` | read | `GET …/vms/{extId}` | one VM, **surfaces its ETag** for downstream mutations |\n| `vm_power_on` | write · low | `POST …/vms/{extId}/$actions/power-on` | task ref |\n| `vm_guest_shutdown` | write · med | `POST …/vms/{extId}/$actions/shutdown` | graceful guest shutdown |\n| `vm_power_off` | write · med | `POST …/vms/{extId}/$actions/power-off` | hard power off |\n| `vm_reboot` | write · med | `POST …/vms/{extId}/$actions/reboot` | task ref |\n| `vm_create` | write · med | `POST …/vms` | new VM extId |\n| `vm_update` | write · med | `PUT …/vms/{extId}` (If-Match) | **undo captures prior CPU / memory** |\n| `vm_clone` | write · med | `POST …/vms/{extId}/$actions/clone` | clone extId |\n| `vm_delete` | write · **HIGH** | `DELETE …/vms/{extId}` | **dry_run**; double-confirm at CLI |\n| `vm_migrate` | write · **HIGH** | `POST …/vms/{extId}/$actions/migrate` | **dry_run**; **undo → prior host** |\n\n## Storage (1 read, 3 write) — base `GET /api/clustermgmt/v4.0/config/storage-containers`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `storage_container_list` | read | `GET …/storage-containers` | extId, name, cluster, capacity, usage |\n| `storage_container_create` | write · med | `POST …/storage-containers` | new container extId |\n| `storage_container_update` | write · med | `PUT …/storage-containers/{extId}` (If-Match) | **undo captures prior config** |\n| `storage_container_delete` | write · **HIGH** | `DELETE …/storage-containers/{extId}` | **dry_run** |\n\n## Network (2 read, 2 write) — base `GET /api/networking/v4.0/config/subnets`\n\n| Tool | Risk | API path | Returns / undo |\n|------|------|----------|----------------|\n| `subnet_list` | read | `GET …/subnets` | extId, name, type, VLAN,"},{"path":"references/cli-reference.md","content":"# nutanix-aiops CLI reference\n\n> Talks to Nutanix **Prism Central v4** on HTTPS `:9440`\n> with HTTP Basic auth. The CLI is a convenience subset; the full **51-tool**\n> surface is via the MCP server (`nutanix-aiops mcp`).\n\n## Setup & diagnostics\n\n```bash\nnutanix-aiops init                      # interactive onboarding wizard\nnutanix-aiops doctor [--skip-auth]      # config + secret store + connectivity + REST-RBAC preflight\nnutanix-aiops mcp                       # start the MCP server (stdio transport)\n```\n\n`doctor` checks the config file, the encrypted secret store and its permissions,\nthat a password is present per target, and (unless `--skip-auth`) connectivity\nplus a **REST-RBAC preflight** against Prism Central — confirming the account can\nactually call the v4 APIs, not just log in to the Web UI.\n\n## Estate & clusters (read)\n\n```bash\nnutanix-aiops overview [--target <t>]              # one-shot estate summary\nnutanix-aiops cluster list                         # registered clusters (extId, AOS, hypervisors, nodes)\nnutanix-aiops cluster health <cluster_ext_id>      # services, resiliency, upgrade state\nnutanix-aiops cluster hosts                         # hosts across all clusters\nnutanix-aiops cluster util <cluster_ext_id>        # CPU / memory / storage / IOPS utilization\n```\n\n## Diagnostics / RCA (read-only)\n\n```bash\nnutanix-aiops diagnose cluster-health              # resiliency, storage >80%/>90%, nodes down — worst first\nnutanix-aiops diagnose alert-triage                # active alerts by severity + oldest unresolved\n```\n\nBoth print a worst-first findings table (severity · resource · signal · detail ·\naction) or a green all-clear line when every measured value is under threshold.\n\n## VMs\n\n```bash\nnutanix-aiops vm list [--esxi | --no-esxi]         # AHV + ESXi VMs (ESXi included by default)\nnutanix-aiops vm get <vm_ext_id>                   # one VM detail (shows its ETag)\nnutanix-aiops vm power <vm_ext_id> <on|off|shutdown|reboot> [--dry-run]\nnutanix-aiops vm delete <vm_ext_id> [--dry-run]    # (HIGH) dry-run + double confirm\nnutanix-aiops vm migrate <vm_ext_id> <target_host_ext_id> [--dry-run]   # (HIGH) dry-run + double confirm\n```\n\n## Secrets (encrypted store `~/.nutanix-aiops/secrets.enc`)\n\n```bash\nnutanix-aiops secret set <target> [--value <pw>]   # store PC password (hidden prompt if no --value)\nnutanix-aiops secret list                           # names only — values never shown\nnutanix-aiops secret rm <target>\nnutanix-aiops secret migrate                        # import legacy plaintext env (NUTANIX_<T>_PASSWORD)\nnutanix-aiops secret rotate-password                # re-encrypt the store under a new master password\n```\n\n## Common options\n\n- `--target, -t <name>` — target name from `config.yaml` (omit to use the default / first target)\n- `--dry-run` — print the API call that would be made, change nothing\n- `--esxi / --no-esxi` — include or exclude ESXi-managed VMs in `vm list` (default: include)\n- Destructive commands (`vm delete`"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2236,"uniquenessScore":36,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T00:59:20.333Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T00:59:20.333Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T07:42:11.303Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}