Back to skill

Security audit

Proxmox VE

Security checks across malware telemetry and agentic risk

Overview

This Proxmox administration skill is coherent, but its bundled API client handles privileged tokens with TLS certificate verification disabled by default.

Install only if you want the agent to help administer Proxmox. Prefer local pvesh/qm/pct access, use least-privilege API tokens, enable TLS verification before using the bundled remote API scripts, and require explicit confirmation for VM/container stops, resets, rollbacks, deletes, or POST API actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
This client disables TLS certificate verification by default by passing an unverified SSL context unless --verify-ssl is explicitly set. Because the script sends a Proxmox API token in the Authorization header, a machine-in-the-middle attacker could intercept credentials and API requests, enabling unauthorized access to cluster, VM, or container management functions.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal