proximoBLOCK
The Proxmox MCP you can hand the keys. All four products: PVE, PBS, PMG, PDM.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
5a2381abfbe9OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add proximo-proxmox -- uvx proximo-proxmox==0.44.1
Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
_redact_probe_int | read | READ-ONLY: probe. |
audit_verify | read | Verify the tamper-evident audit ledger |
Trust audit
BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
("ct_", "Container exec (opt-in)"),enable_exec: bool = False # OFF by default (API-only, safe). True enables ssh->pct exec (root-grant tradeoff).
"NOT 'safe' (a read can still exfiltrate). The absence of a HIGH flag is not a safety signal. "
"PROXIMO_API_BASE_URL": "https://127.0.0.1:8006/api2/json", # unreachable on purpose
secret = "super-secret-password" # noqa: S105 — test sentinel, not a real credential
out = server.pbs_tape_key_create(password="sentinel-password-value", confirm=False)
organization="myorg", token="sentinel-token-value", verify_tls=False,
plan = plan_influxdb_http_create("met1", "https://x:8086", token="sentinel-token-value").gitleaks.toml
mod = importlib.import_module(f"proximo.{name}")_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"sys.path.insert(0, os.path.join(os.path.dirname(__file__), "../../src"))
sys.path.insert(0, os.path.join(os.path.dirname(__file__), "../../src"))
tfa_get(api, "root@pam", "../../x")
tfa_delete(api, "root@pam", "../../zones/x")
plan = plan_sdn_vnet_update("myvnet", options={"tag": "999", "alias": "exfil-net"})assert "tag" in blast and "999" in blast and "alias" in blast and "exfil-net" in blast
acme_tos(api, directory="http://169.254.169.254/latest/meta-data")
PROXIMO_API_BASE_URL='https://127.0.0.1:1/api2/json' \
PUBLIC_URL = "http://10.1.2.3:41241/"
card = build_agent_card("http://127.0.0.1:41241/", secured=True)card = build_agent_card("http://127.0.0.1:41241/")[](https://cursor.com/install-mcp?name=proximo&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJwcm94aW1vLXBy
key = bytes.fromhex(text)
decoded = base64.b64decode(raw, validate=True).decode("utf-8") if isinstance(raw, str) else NoneGates applied: no_behavioural_pass.
5a2381abfbe9full audit observations/trust-audit/mcp-server/john-broadway__proximo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 5a2381abfbe9 | BLOCK | F | 56 | first audit |
Questions
What is the proximo MCP server?
The Proxmox MCP you can hand the keys. All four products: PVE, PBS, PMG, PDM.
What tools does proximo expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is proximo safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (56/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does proximo need?
It reads PROXIMO_AUDIT_ANCHOR_TOKEN_PATH, PROXIMO_AUDIT_KEYED, PROXIMO_AUDIT_KEY_PATH, PROXIMO_CALLER_KEYS_DIR, PROXIMO_PBS_TOKEN_PATH, PROXIMO_PDM_TOKEN_PATH, PROXIMO_PMG_PASSWORD_PATH, PROXIMO_TOKEN_PATH and SMOKE_CRUD_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does proximo run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as proximo-proxmox.
How current is this page?
The grade is for one exact copy of the source (5a2381abfbe9), read on 2026-10-08. The repository is watched and re-audited when it changes.