Back to skill

Security audit

Proxmox Dc Lifecycle

Security checks across malware telemetry and agentic risk

Overview

This is a high-impact but coherent Active Directory/Proxmox runbook that discloses its privileged actions and includes safety gates rather than hidden behavior.

Install only if you intend to let an agent assist with real Proxmox and Active Directory administration. Treat it as privileged operational guidance: fill in the environment config carefully, verify VM IDs and AD state before every phase, provide credentials only through the documented stdin path, and require human confirmation before AD object deletion or disk wipe steps.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The skill’s stated purpose is narrowly scoped to domain controller lifecycle management, but the documented behavior explicitly includes a reusable QEMU guest agent execution path that can run arbitrary PowerShell inside Windows guests and pass secrets via stdin. That broader capability materially expands the trust boundary: if invoked with attacker-influenced inputs or against the wrong VM, it becomes a privileged remote-execution mechanism on domain infrastructure rather than just a constrained rebuild workflow.

VirusTotal

7/63 vendors flagged this skill as malicious, and 56/63 flagged it as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.