Back to skill

Security audit

Proxmox VE

Security checks for vulnerabilities and agentic risk

Overview

This Proxmox skill is mostly purpose-aligned, but its bundled API client sends powerful Proxmox tokens with TLS verification disabled by default.

Review before installing. Use this only in trusted Proxmox administration contexts, prefer the local `pvesh`, `qm`, and `pct` commands, and do not use the bundled remote API helpers with production tokens unless TLS verification is fixed or explicitly configured. Use narrowly scoped Proxmox API tokens and avoid broad cluster-admin credentials.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/pve_api.py:13
Finding

Proxmox API Credentials Transmitted Without TLS Certificate Verification by Default

Content
View full analysis
Dict[str, Any]: url = f"{self.base_url}{path}" payload = None headers = {"Authorization": self.auth_header} if data is not None: payload = urllib.parse.urlencode(data).encode() headers["Content-Type"] = "application/x-www-form-urlencoded" req = urllib.request.Request(url, data=payload, headers=headers, method=method.upper()) with urllib.request.urlopen(req, context=self._context(), timeout=30) as resp: return json.loads(resp.read().decode("utf-8")) ``` `scripts/pve_api.py:50-56`: ```python def build_client(verify_ssl: bool = False) -> ProxmoxAPI: return ProxmoxAPI( host=env_or_die("PVE_HOST"), user=env_or_die("PVE_USER"), token_id=env_or_die("PVE_TOKEN_ID"), token_secret=env_or_die("PVE_TOKEN_SECRET"), verify_ssl=verify_ssl, ) ``` `scripts/pve_api.py:64-75`: ```python parser.add_argument("path", help="API path, e.g. /nodes or /cluster/resources") parser.add_argument(" ...[truncated 4081 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/commands-and-auth.md (reported line 99)May include surrounding context.

export PVE_TOKEN_SECRET='replace-me' export PVE_AUTH_HEADER="PVEAPIToken=${PVE_USER}!${PVE_TOKEN_ID}=${PVE_TOKEN_SECRET}"

curl -sk
-H "Authorization: ${PVE_AUTH_HEADER}"
"https://${PVE_HOST}/api2/json/nodes"

text

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill implements its own direct HTTPS client to the Proxmox API even though the manifest declares use of only pvesh, qm, and pct. This undisclosed capability bypasses the expected trust boundary, enables direct authenticated cluster actions with token-based credentials, and can surprise operators who would not expect the skill to make network requests or consume API secrets.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs use of local CLI commands and bundled Python helpers that rely on environment variables and may perform remote API access, but it declares no explicit tool scope or permissions boundary. That mismatch can cause an agent runtime to expose environment data or permit networked actions without clear least-privilege constraints, increasing the risk of unintended secret access or unauthorized changes to Proxmox infrastructure.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/list_nodes.py (reported line 6)May include surrounding context.

python
import json

client = build_client()
json.dump(client.get('/nodes'), fp=__import__('sys').stdout, indent=2)
print()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

TLS certificate verification is disabled by default via _create_unverified_context(), and the user receives no warning unless they inspect the code. This makes the authenticated Proxmox API traffic vulnerable to man-in-the-middle interception or redirection, which can expose API tokens and allow unauthorized control over VMs, containers, and cluster operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says this skill uses the pvesh, qm, and pct CLIs for Proxmox operations, but this file implements a separate HTTPS API client that depends on PVE_HOST, PVE_USER, PVE_TOKEN_ID, and PVE_TOKEN_SECRET from the environment. Accessing secret-bearing environment variables is a materially different capability than invoking the declared CLIs and is not described in the skill purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code builds an API client and performs a network request to the Proxmox endpoint, then prints the full response to stdout. There is no confirmation prompt, comment, docstring, or user-facing message warning that the script will contact the server and emit potentially sensitive system status data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.