Unified audit logging, policy enforcement, and input sanitization for the entire VMware MCP skill family. Use when querying audit logs, managing policy rules, or when any VMware skill needs audit/policy infrastructure. Provides the @vmware_tool decorator that wraps all 156+ MCP tools across 8 skills. Use when user asks to "show audit log", "check denied operations", "view policy rules", "audit stats", or "query audit trail". For VM lifecycle use vmware-aiops, for monitoring use vmware-monitor, for networking use vmware-nsx, for load balancing use vmware-avi.
The policy engine no longer fails open when rules.yaml cannot be read; secret redaction went from 41.7% to 100% of measured leak shapes.