VMware Harden MCP Server

AI-native VMware compliance and baseline enforcement. Sibling to the vmware- skill family. It runs locally over stdio via the published package.

People who work with agent skills, ai skill and automation and want it reachable from Claude, Cursor, VS Code, or another MCP client. The project is written in Python.

VERIFIED ACTIVE

LAST COMMIT 2026-09-16 · ★ 3 · #50 OF 227 MAINTAINED AUTOMATION · VERIFIED 2026-09-18

MIT · Python servers · how we verify → /methodology

01 · Install VMware Harden

before you install - you'll need

Set VMWARE_HARDEN_LAB_TARGET before connecting. ANTHROPIC_API_KEY is optional or environment-specific per the README.

Claude Code

claude mcp add zw008-vmware-harden -- uvx vmware-harden

Claude Desktop / Cursor / VS Code - add to config

{
  "mcpServers": {
    "zw008-vmware-harden": {
      "command": "uvx",
      "args": [
        "vmware-harden"
      ]
    }
  }
}

Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.

Using another client? Same JSON, different key

Claude Desktop · mcpServers

Cursor · mcpServers

VS Code · servers

Windsurf · mcpServers

Zed · context_servers

Cline · mcpServers

Roo Code · mcpServers

Continue · mcpServers

LibreChat · mcpServers

Gemini CLI · mcpServers

Codex CLI · mcp_servers

Full setup guides: every client.

02 · Evidence

Security posture

What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.

runs as local process (stdio) - runs on your machine with your user's permissions

license MIT - declared in the repository

pypi package vmware-harden - check the name against the project README before installing (PyPI has no namespace ownership)

registry namespace io.github.zw008 is GitHub-verified and matches the repo owner

03 · What VMware Harden can do

Prose above is summarized from the project's README and registry record - no invented capabilities.

Latest releases

v1.10.10 · 2026-09-16

Both problems below were found in scenario tests against the lab on 2026-09-15/16. · A collector that cannot run costs its own node types, not the whole scan. scan_target with · dengbao-2.0-level3-vmware died with…

v1.10.9 · 2026-09-15

No CLI read wrote ~/.vmware/audit.db - only MCP calls and CLI writes (@guarded) did. A live · vmware-aria resource list left the audit row count unchanged while the same read over MCP added a row. · Every CLI command…

v1.10.8 · 2026-09-14

v1.10.8 - reports say which scan they read · Reports say which scan they read, and warn when later scans failed. A failed scan is marked · failed and kept out of reports - correctly - so vmware-harden report then shows…

04 · Who maintains VMware Harden

VMware Harden is maintained by zw008. We track 13 MCP servers from zw008 - 13 actively maintained, 114 combined GitHub stars, oldest repo from Feb 2026. Full record: all servers from zw008.

  1. VMware AIops AI-powered VMware vCenter/ESXi VM lifecycle and deployment with 31 MCP tools. ★ 73
  2. VMware Monitor Read-only VMware vCenter/ESXi monitoring with 27 MCP tools. Code-level safety. ★ 12
  3. VMware VKS vSphere with Tanzu (VKS): Namespace and TanzuKubernetesCluster lifecycle. Requires vSphere 8.x+. ★ 5
  4. VMware NSX Security VMware NSX security: DFW policies, security groups, tags, Traceflow, IDPS - 21 MCP tools. ★ 4
  5. VMware NSX VMware NSX networking management with 31 MCP tools: segments, gateways, NAT, routing, IPAM. ★ 5
  6. VMware Aria Operations VMware Aria Operations: metrics, alerts, capacity, anomaly detection - 18 MCP tools. ★ 2

05 · Facts

category
automation - ranked #50 of 227 actively-maintained automation servers as of 2026-09-18.
release cadence
10+ releases in the last 90 days (latest 2026-09-16)
registry
io.github.zw008/vmware-harden (active, first published 2026-05-04 · 31 versions)
packages
pypi:vmware-harden

06 · VMware Harden FAQ

What is VMware Harden?

AI-native VMware compliance and baseline enforcement. Sibling to the vmware- skill family. It runs locally over stdio via the published package.

Is VMware Harden still maintained?

Yes - as of 2026-09-18, its last commit was 2026-09-16 and it shipped 10+ releases in the last 90 days. We re-verify nightly.

How do I install VMware Harden?

Run `uvx vmware-harden`. The README documents 2 environment variables (ANTHROPIC_API_KEY, VMWARE_HARDEN_LAB_TARGET) to set first. Set VMWARE_HARDEN_LAB_TARGET before connecting. ANTHROPIC_API_KEY is optional or environment-specific per the README. You can also paste the ready-made client config above.

Does VMware Harden run locally?

Yes - it's a stdio server: it runs on your machine (via uvx) with your user's permissions. Your data stays local unless the server itself calls external APIs.

07 · Alternatives to VMware Harden