Atlas / MCP servers / john-broadway / proximo

proximoBLOCK

mcp/john-broadway/proximo

The Proxmox MCP you can hand the keys. All four products: PVE, PBS, PMG, PDM.

Verdict
BLOCK
Grade
F
Trust score
56 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
52
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Read from source at commit 5a2381abfbe9OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add proximo-proxmox -- uvx proximo-proxmox==0.44.1
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
_redact_probe_intreadREAD-ONLY: probe.
audit_verifyreadVerify the tamper-evident audit ledger
04

Trust audit

BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (7 observation(s))
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/gen_tools_doc.py:29
("ct_", "Container exec (opt-in)"),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/proximo/config.py:323
enable_exec: bool = False  # OFF by default (API-only, safe). True enables ssh->pct exec (root-grant tradeoff).
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/proximo/planning.py:37
"NOT 'safe' (a read can still exfiltrate). The absence of a HIGH flag is not a safety signal. "
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/pypi_smoke.py:78
"PROXIMO_API_BASE_URL": "https://127.0.0.1:8006/api2/json",  # unreachable on purpose
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_access_governance.py:1165
secret = "super-secret-password"  # noqa: S105 — test sentinel, not a real credential
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_confirm_sweep_pbs_tape_media.py:258
out = server.pbs_tape_key_create(password="sentinel-password-value", confirm=False)
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_pbs_metrics.py:393
organization="myorg", token="sentinel-token-value", verify_tls=False,
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_pbs_metrics.py:631
plan = plan_influxdb_http_create("met1", "https://x:8086", token="sentinel-token-value")
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_validate.py:98
mod = importlib.import_module(f"proximo.{name}")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packaging/lxc/ct/proximo.sh:11
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/live-smoke/pmg-smoke.py:48
sys.path.insert(0, os.path.join(os.path.dirname(__file__), "../../src"))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/live-smoke/pmg-wave8-smoke.py:36
sys.path.insert(0, os.path.join(os.path.dirname(__file__), "../../src"))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_access_governance.py:1132
tfa_get(api, "root@pam", "../../x")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_access_governance.py:1157
tfa_delete(api, "root@pam", "../../zones/x")
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
tests/test_network.py:1291
plan = plan_sdn_vnet_update("myvnet", options={"tag": "999", "alias": "exfil-net"})
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
tests/test_network.py:1293
assert "tag" in blast and "999" in blast and "alias" in blast and "exfil-net" in blast
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/test_pbs_acme.py:323
acme_tos(api, directory="http://169.254.169.254/latest/meta-data")
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
debian/tests/smoke:32
PROXIMO_API_BASE_URL='https://127.0.0.1:1/api2/json' \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_a2a_auth.py:28
PUBLIC_URL = "http://10.1.2.3:41241/"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_a2a_auth.py:131
card = build_agent_card("http://127.0.0.1:41241/", secured=True)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_a2a_auth.py:138
card = build_agent_card("http://127.0.0.1:41241/")
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:113
[![Install in Cursor](https://img.shields.io/badge/Cursor-Install_Proximo-000000?style=flat-square)](https://cursor.com/install-mcp?name=proximo&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJwcm94aW1vLXBy
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/proximo/audit.py:151
key = bytes.fromhex(text)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/proximo/file_restore.py:99
decoded = base64.b64decode(raw, validate=True).decode("utf-8") if isinstance(raw, str) else None

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 5a2381abfbe9full audit observations/trust-audit/mcp-server/john-broadway__proximo.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-085a2381abfbe9BLOCKF56first audit
06

Questions

What is the proximo MCP server?

The Proxmox MCP you can hand the keys. All four products: PVE, PBS, PMG, PDM.

What tools does proximo expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is proximo safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (56/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does proximo need?

It reads PROXIMO_AUDIT_ANCHOR_TOKEN_PATH, PROXIMO_AUDIT_KEYED, PROXIMO_AUDIT_KEY_PATH, PROXIMO_CALLER_KEYS_DIR, PROXIMO_PBS_TOKEN_PATH, PROXIMO_PDM_TOKEN_PATH, PROXIMO_PMG_PASSWORD_PATH, PROXIMO_TOKEN_PATH and SMOKE_CRUD_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does proximo run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as proximo-proxmox.

How current is this page?

The grade is for one exact copy of the source (5a2381abfbe9), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement