Skip to main content
Glama
vmware-skills

VMware-Monitor

active_sessions

Read-onlyIdempotent

Lists currently authenticated vCenter/ESXi sessions with user details, login time, IP, and client, helping identify who is logged in and attribute changes to a specific person.

Instructions

[READ] Currently authenticated vCenter/ESXi sessions (who is logged in).

Returns the list envelope with a real total; each row has user_name, full_name, login_time, last_active, ip_address, user_agent (which client — e.g. Aria's adapter shows VMware vim-java), call_count, kind (user/service) and a current flag for this skill's own session. vCenter's own solution users (vpxd-extension-<machine id> and similar) are folded by default and counted in service_sessions. Requires the Sessions privilege; low-privilege accounts get a single explanatory row instead of a traceback.

Use this to attribute a change to a person — pair it with active_tasks, which names the user who started each task. Read-only — terminating a session is not supported here.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
limitNoMax session rows to return (None = all).
targetNovCenter/ESXi target from config (default if omitted).
include_serviceNoList vCenter's own solution-user sessions too. On a lab vCenter they were 24 of 33 sessions.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changedv1.14.0
    • addedInput schema / properties / include_service
      Added value: +{
      +  "default": false,
      +  "description": "List vCenter's own solution-user sessions too. On a lab vCenter they were 24 of 33 sessions.",
      +  "title": "Include Service",
      +  "type": "boolean"
      +}
  2. Changed4 schema fields changedv1.9.2
    • addedInput schema / additionalProperties
      Added value: +false
    • addedInput schema / properties / limit / description
      Added value: +"Max session rows to return (None = all)."
    • addedInput schema / properties / target / description
      Added value: +"vCenter/ESXi target from config (default if omitted)."
    • changedOutput schema / (root)
      Previous value: -{
      -  "properties": {
      -    "result": {
      -      "items": {
      -        "additionalProperties": true,
      -        "type": "object"
      -      },
      -      "title": "Result",
      -      "type": "array"
      -    }
      -  },
      -  "required": [
      -    "result"
      -  ],
      -  "title": "active_sessionsOutput",
      -  "type": "object"
      -}New value: +null
  3. Addedv1.6.1

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, and destructiveHint false, but the description adds substantial behavioral context: it requires the Sessions privilege, low-privilege accounts get a single explanatory row instead of a traceback, vCenter solution users are folded by default and counted in service_sessions, and it explicitly says terminating a session is not supported. These details go well beyond the annotations and give the agent a clear model of the tool's behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is somewhat long but every sentence adds value: purpose, return fields, privilege behavior, folding details, and usage pairing with active_tasks. It is front-loaded with the purpose and then provides necessary context. It could be trimmed slightly (e.g., the list of fields is detailed but helpful), but it is well-structured and not redundant.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only tool with no output schema, the description comprehensively covers the return envelope, row fields, privilege requirements, error fallback, and pairing with a sibling. It also implicitly addresses the limit parameter via the schema. Nothing an agent needs to correctly call this tool is missing; the description is complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the parameters (limit, target, include_service) are already fully documented in the schema. The description does not add extra parameter semantics beyond what the schema provides; it only mentions include_service implicitly through the folding behavior. Given the high coverage, a baseline of 3 is appropriate, and the description does not need to compensate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb+resource: 'Currently authenticated vCenter/ESXi sessions (who is logged in).' It clearly states what the tool returns and distinguishes itself from the sibling active_tasks by explicitly naming it and its different focus. The read-only nature is also stated, so an agent knows exactly what this tool does.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It explicitly tells the agent when to use it: 'Use this to attribute a change to a person — pair it with active_tasks, which names the user who started each task.' This gives a concrete use case and points to an alternative, making it clear how to choose between the two. It also notes privilege requirements and the fallback behavior for low-privilege accounts, further guiding appropriate invocation.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.