Back to plugin

Security audit

Veeam AIops

Security checks for vulnerabilities and agentic risk

Overview

This plugin is a clearly scoped Veeam operations tool with disclosed credentials, audit logging, and write capabilities, but users should restrict the connected Veeam account because it can perform real backup and restore actions.

Install this only for users who should operate Veeam Backup & Replication. Use a dedicated least-privilege Veeam account, prefer read-only roles for observation, keep VEEAM_AIOPS_MASTER_PASSWORD out of long-lived shells when possible, and require operators to review dry-run previews before any restore or stop action.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
skills/veeam-aiops/references/agent-guardrails.md:43
Evidence
Copy this into your agent's system prompt: