VMware Log Insight
PYPI · VMWARE-LOG-INSIGHT · SCANNED SEP 20
Read-only VMware Aria Operations for Logs (Log Insight): search + aggregation. 7 MCP tools.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs hatchling.build at install time, a recognised native-build step with no shell scripting around it. View diagnostics → Pass
- 3 of 40 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency35
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- License check failed: the license (MIT License) isn't a recognized OSI-approved license. See how to fix → Fail
- Actively maintained (last published 0 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability67
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2103 tokens (~300/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management70
- Stability observed for 21 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 7 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the VMware Log Insight MCP server?
VMware Log Insight runs locally as a PyPI package, launched with uvx vmware-log-insight. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · vmware-log-insight
claude mcp add vmware-skills-vmware-log-insight -- uvx vmware-log-insight
{
"mcpServers": {
"vmware-skills-vmware-log-insight": {
"command": "uvx",
"args": [
"vmware-log-insight"
]
}
}
} {
"servers": {
"vmware-skills-vmware-log-insight": {
"command": "uvx",
"args": [
"vmware-log-insight"
]
}
}
} codex mcp add vmware-skills-vmware-log-insight -- uvx vmware-log-insight
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"vmware-skills-vmware-log-insight": {
"type": "local",
"command": [
"uvx",
"vmware-log-insight"
],
"enabled": true
}
}
} openclaw mcp add vmware-skills-vmware-log-insight --command uvx --arg vmware-log-insight
mcp_servers:
vmware-skills-vmware-log-insight:
command: "uvx"
args: ["vmware-log-insight"] {
"McpServers": {
"vmware-skills-vmware-log-insight": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"vmware-log-insight"
]
}
}
} assistant mcp add vmware-skills-vmware-log-insight -t stdio -c uvx -a vmware-log-insight
{
"mcpServers": {
"vmware-skills-vmware-log-insight": {
"command": "uvx",
"args": [
"vmware-log-insight"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +15
- Tool safety: pass → unverified ▼ security
- Stability: 0.67 → unverified ▼ security
- Malware scan: unverified → pass ▲ security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
- Package version: 1.8.17 → 1.9.0 functional
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −14
- Malware scan: pass → unverified ▼ security
- 16 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 15 Sept 26 −14
- Malware scan: pass → unverified ▼ security
- Package version: 1.8.16 → 1.8.17 functional
- 14 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 0
- Package version: 1.8.15 → 1.8.16 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed pypi/vmware-log-insight@1.9.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | pypi |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | hatchling.build |
Background: Why install scripts are a supply-chain risk →
Dependencies 40 packages
| Packages resolved | 40 |
|---|---|
| Stale | 3 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
alert_get ~202
[READ] Get the stored definition of one alert. Use this after alert_list. Returns the same sanitized {id, name, enabled, info} projection as an alert_list row plus 'raw_keys' — the sorted key names the appliance actually sent — so you can see what else the definition carries without this skill guessing at its shape. For when the alert fired, use alert_history. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| alert_id | string | yes | The alert id exactly as returned in an alert_list row's 'id' field (not the alert's name). An empty string is refused with a message telling you to run alert_list; a well-formed but unknown id comes… |
| target | – | – | Log Insight target name as spelled in ~/.vmware-log-insight/config.yaml. Omit to use that file's default_target — with no default configured, omitting it is an error that lists the configured names. |
No output schema declared.
No examples provided.
alert_history ~242
[READ] List recent trigger-history records for an alert. Use this for when an alert fired, not how it's defined. Returns the family list envelope {items, returned, limit, total, truncated, hint}; each item is {timestamp_ms, info}. total is the real history-record count, so truncated answers whether older records were left behind — raise limit when true. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| alert_id | string | yes | The alert id exactly as returned in an alert_list row's 'id' field (not the alert's name). An empty string is refused with a message telling you to run alert_list first. |
| limit | integer | – | Maximum history records returned, most recent first as the appliance orders them (default 50). There is no offset — the appliance hands back the whole history in one call and this slices it, so when… |
| target | – | – | Log Insight target name as spelled in ~/.vmware-log-insight/config.yaml. Omit to use that file's default_target — with no default configured, omitting it is an error that lists the configured names. |
No output schema declared.
No examples provided.
alert_list ~244
[READ] List defined Log Insight alerts. Returns the family list envelope {items, returned, limit, total, truncated, hint}; each item is {id, name, enabled, info}. Start here, then pass an id to alert_get or alert_history. total is the real count matching name_filter, so truncated answers whether more exist; raise limit or narrow name_filter when true. Read-only — this skill never creates/edits/deletes alerts.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Maximum items in the page (default 50). It slices the matches after filtering; 'total' still reports every match, so a small limit never hides how many alerts exist. |
| name_filter | – | – | Case-insensitive substring matched against the alert's name only (not its id or description). Omit to list every defined alert. The appliance returns the whole collection either way and the filter ru… |
| target | – | – | Log Insight target name as spelled in ~/.vmware-log-insight/config.yaml. Omit to use that file's default_target — with no default configured, omitting it is an error that lists the configured names. |
No output schema declared.
No examples provided.
log_aggregate ~473
[READ] Aggregate matching events into a time series and detect spikes. WHEN: to find when/whether log volume burst without pulling raw events. Follow up with log_search on the spike window. RETURNS: {aggregation, bin_width_ms, constraints, bins:[{timestamp_ms, value}], spikes:[{timestamp_ms, value, zscore}]}. A bin is flagged as a spike when it sits at least 2 standard deviations above the mean; a series of fewer than 3 bins, or a flat one, reports no spikes rather than calling everything a spike — so an empty 'spikes' list is not evidence of calm when the window is short. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| aggregation | string | – | The function applied within each bin — exactly one of COUNT, UCOUNT, AVG, MIN, MAX, SUM, STDDEV, VARIANCE, SAMPLE (lower case is accepted and upper-cased). Anything else raises a ValueError listing t… |
| begin_ms | – | – | Absolute window start as epoch milliseconds. Usable on its own; cannot be combined with last. |
| bin_width_ms | integer | – | Width of each time bin in milliseconds, must be positive (default 60000 = one minute). It sets the resolution of both the series and the spike test: bins much wider than the burst average it away, bi… |
| end_ms | – | – | Absolute window end as epoch milliseconds. Usable on its own; cannot be combined with last. |
| last | – | – | Relative window ending now — "30m", "2h", "7d" (units s/m/h/d) or a bare number of seconds. Cannot be combined with begin_ms/end_ms. Omit all three and the window defaults to the last hour. |
| target | – | – | Log Insight target name as spelled in ~/.vmware-log-insight/config.yaml. Omit to use that file's default_target — with no default configured, omitting it is an error that lists the configured names. |
| text | – | – | Free-text substring matched with CONTAINS, exactly as in log_search. Omit to aggregate every event in the window. |
No output schema declared.
No examples provided.
log_fields ~190
[READ] List the extracted fields available to use in query filters. Use this to discover valid field names before filtering log_search / log_aggregate. Returns the family list envelope {items, returned, limit, total, truncated, hint}; each item is {name}. No limit — every matching field is returned, so truncated is always false: this is the complete field list, not a page. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| name_filter | – | – | Case-insensitive substring matched against the field name. Omit to return every field this appliance extracts. Field extraction is deployment-specific, so a name absent here does not exist for this t… |
| target | – | – | Log Insight target name as spelled in ~/.vmware-log-insight/config.yaml. Omit to use that file's default_target — with no default configured, omitting it is an error that lists the configured names. |
No output schema declared.
No examples provided.
log_search ~442
[READ] Search Log Insight events within a time window. WHEN: to find the actual log lines behind an incident (e.g. what vmkernel logged during a storage event). For "where did logs burst?" use log_aggregate instead; for vCenter alarms use vmware-monitor. RETURNS: {count, complete (False if truncated), constraints, events: [{timestamp_ms, text, fields}]}. Feed events to vmware-debug incident_timeline to correlate across sources. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| begin_ms | – | – | Absolute window start as epoch milliseconds (not seconds). May be given without end_ms, which then means "from this instant onwards". Cannot be combined with last. |
| end_ms | – | – | Absolute window end as epoch milliseconds (not seconds). May be given without begin_ms, which then means "everything up to this instant". Cannot be combined with last. |
| last | – | – | Relative window ending now, as a quantity plus a unit suffix — s, m, h or d ("30m", "2h", "7d") — or a bare number of seconds. Anything else raises a ValueError naming the accepted forms. Cannot be c… |
| limit | integer | – | Maximum events returned, 1..20000, default 50. Out-of-range values are silently clamped into that range rather than refused. Narrow the window or the text rather than raising this — raw events are th… |
| target | – | – | Log Insight target name as spelled in ~/.vmware-log-insight/config.yaml. Omit to use that file's default_target — with no default configured, omitting it is an error that lists the configured names. |
| text | – | – | Free-text substring matched against the event message with the CONTAINS operator — not a regex and not a full query expression. Omit to match every event in the window. To filter on an extracted fiel… |
No output schema declared.
No examples provided.
log_version ~125
[READ] Return the Log Insight appliance version/build (diagnostics and query-syntax compatibility). Returns {version, release_name, build}. Use this first when a query behaves unexpectedly, to confirm the appliance version before trusting log_search. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| target | – | – | Log Insight target name as spelled in ~/.vmware-log-insight/config.yaml. Omit to use that file's default_target — with no default configured, omitting it is an error that lists the configured names.… |
No output schema declared.
No examples provided.
What is the VMware Log Insight MCP server?
VMware Log Insight is an MCP server listed in the public MCP registry as io.github.vmware-skills/vmware-log-insight. Read-only VMware Aria Operations for Logs (Log Insight): search + aggregation. 7 MCP tools. This page covers its PyPI package (vmware-log-insight).
Is the VMware Log Insight MCP server safe to use?
VMware Log Insight scores 77 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the VMware Log Insight MCP server expose?
VMware Log Insight exposes 7 tools: alert_list, alert_get, alert_history, log_search, log_aggregate, and 2 more. Their descriptions and schemas cost roughly 1,918 tokens of context every time the server is loaded.
Is the VMware Log Insight MCP server still maintained?
VMware Log Insight is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.