Back to skill

Security audit

Proxmox VE Manager

Security checks for vulnerabilities and agentic risk

Overview

This Proxmox management skill is purpose-aligned, but it deserves review because it can change infrastructure state and handles API tokens in unsafe ways.

Install only if you are comfortable with an agent running authenticated Proxmox administrative actions. Use a narrowly scoped, revocable API token, avoid the sourced credential file where possible, require explicit confirmation before stop/reboot/rollback/delete/backup actions, and do not use the default -k/-ks TLS behavior on any untrusted network.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/pve.sh:17
Finding

Administrative API Token Exposed by Disabled TLS Certificate Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/pve.sh:5
Finding

Credential File Is Executed as Arbitrary Shell Code

Content
View full analysis
/dev/null ``` ### Technical Analysis Bash `source` does not treat the target as a passive key-value configuration file. It parses and executes every command, expansion, function, redirection, and other shell construct in the file within the current shell process. The script checks only whether the path passes `-f`. It does not verify that the file is owned by the current user, reject symbolic links, enforce restrictive permissions, or validate that the content contains only the three expected credential assignments. Therefore, any attacker who can replace, modify, or redirect `~/.proxmox-credentials` can execute arbitrary commands with the privileges of the user running `pve.sh`. The documented `chmod 600` reduces ordinary cross-user access when correctly applied, but the script does not enforce that protection and still treats credential data as executable code. ### Attack Path 1. An attacker obtains the ability to influence `~/.proxmox-credentials`, such as through another compromised process running as the user, an unsafe home-directory restoration, an insecure provisioning process, unintended permissions, or a manipulated symbolic link. 2. The attacker inserts a shell command into the file, for example: ```bash PROXMOX_HOST=https://proxmox.example:8006 PROXMOX_TOKEN_ID=user@pam!token PROXMOX_TOKEN_SECRET=secret malicious_command ``` 3. The user invokes `scripts/pve.sh` for a legitimate Proxmox operation. 4. Bash executes the file through `source` before validating the required ...[truncated 815 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Snapshot rollback and deletion are potentially irreversible or service-disrupting actions, yet the examples are presented without warnings, precondition checks, or confirmation guidance. This increases the risk that an agent or operator executes a destructive recovery step casually, causing data loss or downtime.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The skill demonstrates mutating shell commands with unsanitized placeholders such as {vmid} and {storage}, creating a risk that agent-substituted or user-influenced values are passed directly into shell/API parameters. In a shell-based execution path, poor validation can lead to targeting the wrong resource, malformed requests, or command/argument injection depending on how wrappers like scripts/pve.sh construct calls.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

curl -ks -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/storage/{storage}/content?content=backup" | jq

Start backup

curl -ks -X POST -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/vzdump"
-d "vmid={vmid}" -d "storage={storage}" -d "mode=snapshot"

text

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill exposes shell-based operational capabilities but does not declare any explicit tool restrictions or permission scope. In an agent environment, this can enable broader-than-necessary shell use and increase the chance of unintended or unsafe infrastructure actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill instructs users to store long-lived API credentials in environment variables or a local file, creating session persistence and increasing the risk of credential reuse, accidental disclosure, or unauthorized future actions. In an agent context, persistent credentials can silently empower repeated infrastructure modifications across sessions.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: proxmox
description: Manage Proxmox VE clusters via REST API. Use when user asks to list, start, stop, restart VMs or LXC containers, check node status, create snapshots, view tasks, or manage Proxmox infrastructure. Requires API token or credentials configured.
---

# Proxmox VE Management

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description advertises start, stop, restart, snapshot, and general infrastructure management actions without clearly warning that these operations can disrupt services or alter production systems. In an autonomous or semi-autonomous agent setting, lack of impact signaling can lead to unsafe execution on user prompts that are ambiguous or insufficiently authorized.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

PROXMOX_TOKEN_ID=user@pam!monitoring PROXMOX_TOKEN_SECRET=your-token-secret EOF chmod 600 ~/.proxmox-credentials

text

Create API token in Proxmox: Datacenter → Permissions → API Tokens → Add

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
curl -ks -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/qemu/{vmid}/snapshot" | jq

# Create snapshot
curl -ks -X POST -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/qemu/{vmid}/snapshot" \
  -d "snapname=snap1" -d "description=Before update"

# Rollback

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

curl -ks -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/storage/{storage}/content?content=backup" | jq

Start backup

curl -ks -X POST -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/vzdump"
-d "vmid={vmid}" -d "storage={storage}" -d "mode=snapshot"

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sources credentials from ~/.proxmox-credentials and uses PROXMOX_TOKEN_ID and PROXMOX_TOKEN_SECRET to authenticate outbound API requests, but there is no comment, log message, or prompt warning the user that sensitive tokens will be read from disk and sent over the network. The help text lists required environment variables, but it does not disclose the privacy or credential-handling implications of using them.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/pve.sh (reported line 137)May include surrounding context.

sh
stop <vmid>         Force stop VM/LXC
  shutdown <vmid>     Graceful shutdown VM/LXC
  reboot <vmid>       Reboot VM/LXC
  snap <vmid> [name]  Create snapshot
  snapshots <vmid>    List snapshots
  tasks <node>        Show recent tasks
  storage <node>      Show storage status

Static analysis

No suspicious patterns detected.