T09 · Insecure Skill Coding Practices
- Location
scripts/pve.sh:17- Finding
Administrative API Token Exposed by Disabled TLS Certificate Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Proxmox management skill is purpose-aligned, but it deserves review because it can change infrastructure state and handles API tokens in unsafe ways.
Install only if you are comfortable with an agent running authenticated Proxmox administrative actions. Use a narrowly scoped, revocable API token, avoid the sourced credential file where possible, require explicit confirmation before stop/reboot/rollback/delete/backup actions, and do not use the default -k/-ks TLS behavior on any untrusted network.
scripts/pve.sh:17Administrative API Token Exposed by Disabled TLS Certificate Verification
scripts/pve.sh:5Credential File Is Executed as Arbitrary Shell Code
Snapshot rollback and deletion are potentially irreversible or service-disrupting actions, yet the examples are presented without warnings, precondition checks, or confirmation guidance. This increases the risk that an agent or operator executes a destructive recovery step casually, causing data loss or downtime.
The skill demonstrates mutating shell commands with unsanitized placeholders such as {vmid} and {storage}, creating a risk that agent-substituted or user-influenced values are passed directly into shell/API parameters. In a shell-based execution path, poor validation can lead to targeting the wrong resource, malformed requests, or command/argument injection depending on how wrappers like scripts/pve.sh construct calls.
curl -ks -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/storage/{storage}/content?content=backup" | jq
curl -ks -X POST -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/vzdump"
-d "vmid={vmid}" -d "storage={storage}" -d "mode=snapshot"
The skill exposes shell-based operational capabilities but does not declare any explicit tool restrictions or permission scope. In an agent environment, this can enable broader-than-necessary shell use and increase the chance of unintended or unsafe infrastructure actions.
The skill instructs users to store long-lived API credentials in environment variables or a local file, creating session persistence and increasing the risk of credential reuse, accidental disclosure, or unauthorized future actions. In an agent context, persistent credentials can silently empower repeated infrastructure modifications across sessions.
---
name: proxmox
description: Manage Proxmox VE clusters via REST API. Use when user asks to list, start, stop, restart VMs or LXC containers, check node status, create snapshots, view tasks, or manage Proxmox infrastructure. Requires API token or credentials configured.
---
# Proxmox VE Management
The description advertises start, stop, restart, snapshot, and general infrastructure management actions without clearly warning that these operations can disrupt services or alter production systems. In an autonomous or semi-autonomous agent setting, lack of impact signaling can lead to unsafe execution on user prompts that are ambiguous or insufficiently authorized.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
PROXMOX_TOKEN_ID=user@pam!monitoring PROXMOX_TOKEN_SECRET=your-token-secret EOF chmod 600 ~/.proxmox-credentials
Create API token in Proxmox: Datacenter → Permissions → API Tokens → Add
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -ks -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/qemu/{vmid}/snapshot" | jq
# Create snapshot
curl -ks -X POST -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/qemu/{vmid}/snapshot" \
-d "snapname=snap1" -d "description=Before update"
# Rollback
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -ks -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/storage/{storage}/content?content=backup" | jq
curl -ks -X POST -H "$AUTH" "$PROXMOX_HOST/api2/json/nodes/{node}/vzdump"
-d "vmid={vmid}" -d "storage={storage}" -d "mode=snapshot"
The script sources credentials from ~/.proxmox-credentials and uses PROXMOX_TOKEN_ID and PROXMOX_TOKEN_SECRET to authenticate outbound API requests, but there is no comment, log message, or prompt warning the user that sensitive tokens will be read from disk and sent over the network. The help text lists required environment variables, but it does not disclose the privacy or credential-handling implications of using them.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
stop <vmid> Force stop VM/LXC
shutdown <vmid> Graceful shutdown VM/LXC
reboot <vmid> Reboot VM/LXC
snap <vmid> [name] Create snapshot
snapshots <vmid> List snapshots
tasks <node> Show recent tasks
storage <node> Show storage status
No suspicious patterns detected.