pve-mcp
PyPI
v1.3.0
Published by ahmetem — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
Token-efficient MCP server for Proxmox VE (guests, snapshots, backups, storage, LVM/ZFS, guest/host exec, dry-run + tamper-evident audit)
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 23.1 = 77. What the published surface and source actually contain:
| Points | What was found | Category |
|---|---|---|
| −23.1 | Shell command embedded in tool metadata ×2 MTC-INJ-CMD-1 | injection |
2. Client adoption risk — 77 − 11 = 66. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −10 | capability blast radius (critical) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
This server (without client built-ins) exposes a complete data-exfiltration chain: proxmox_get_disk_smart → proxmox_vm_list_hosts → proxmox_host_exec. Untrusted input is ingested, private data is read, and it can be sent to an external sink via the agent composing the tools (→). Static analysis proves the primitive exists, not that a specific run will occur.
Fix: Remove one leg of the trifecta: isolate untrusted-input tools from secret-reading tools and from egress tools, or require human approval between them.
Location: flow proxmox_get_disk_smart → proxmox_vm_list_hosts → proxmox_host_exec
Shell command embedded in tool metadata detected in the description of tool "proxmox_host_exec". Instruction-like content in tool metadata is executed by the model, not the human, and is the primary tool-poisoning vector.
Evidence: rm -rf
Fix: Tool descriptions should describe behavior, not instruct the assistant. Treat imperative / secrecy / sequencing language in metadata as hostile.
Location: tool proxmox_host_exec · description
Shell command embedded in tool metadata detected in the description of tool "proxmox_vm_exec". Instruction-like content in tool metadata is executed by the model, not the human, and is the primary tool-poisoning vector.
Evidence: rm -rf
Fix: Tool descriptions should describe behavior, not instruct the assistant. Treat imperative / secrecy / sequencing language in metadata as hostile.
Location: tool proxmox_vm_exec · description
Tool "proxmox_host_read_exec" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool proxmox_host_read_exec
Tool "proxmox_host_exec" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool proxmox_host_exec
Tool "proxmox_lxc_exec" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool proxmox_lxc_exec
Tool "proxmox_vm_exec" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool proxmox_vm_exec
In the server's implementation (`proxmox_mcp/tools/host_read.py:1`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: """Read-only host shell exec (allow-listed). `proxmox_host_exec` runs arbitrary commands and can destroy things, so i
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server proxmox_mcp/tools/host_read.py
In the server's implementation (`proxmox_mcp/vm_ssh.py:8`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: y opted into full shell exec (see chat log). Safety is reduced to: - confirm=true on every exec - regex
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server proxmox_mcp/vm_ssh.py
Tool "proxmox_host_read_exec" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool proxmox_host_read_exec
Tool "proxmox_host_exec" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool proxmox_host_exec
Tool "proxmox_lxc_exec" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool proxmox_lxc_exec
Tool "proxmox_vm_exec" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool proxmox_vm_exec
Each tool and what it can reach — statically extracted from the published source.
proxmox_get_disk_smartingests untrusted inputproxmox_host_execruns code / shellproxmox_host_read_execruns code / shellproxmox_lxc_execruns code / shellproxmox_vm_execruns code / shellproxmox_vm_list_hostsreads sensitive dataproxmox_vm_read_filereads sensitive dataproxmox_cleanup_vzdump_snapshotsno sensitive capabilityproxmox_clone_vmno sensitive capabilityproxmox_create_backupno sensitive capabilityproxmox_ct_log_tailno sensitive capabilityproxmox_ct_service_actionno sensitive capabilityproxmox_get_vm_statusno sensitive capabilityproxmox_list_backupsno sensitive capabilityproxmox_list_cluster_storageno sensitive capabilityproxmox_list_isosno sensitive capabilityproxmox_list_lvm_thinno sensitive capabilityproxmox_list_nodesno sensitive capabilityproxmox_list_snapshotsno sensitive capabilityproxmox_list_storageno sensitive capabilityproxmox_list_vmsno sensitive capabilityproxmox_list_zfsno sensitive capabilityproxmox_lvm_manageno sensitive capabilityproxmox_move_diskno sensitive capabilityproxmox_resize_vmno sensitive capabilityproxmox_restore_backupno sensitive capabilityproxmox_snapshotno sensitive capabilityproxmox_storage_configno sensitive capabilityproxmox_storage_usage_detailno sensitive capabilityproxmox_zfs_create_snapshotno sensitive capabilityproxmox_zfs_datasetno sensitive capabilityproxmox_zfs_destroy_snapshots_by_patternno sensitive capabilityproxmox_zfs_list_datasetsno sensitive capabilityproxmox_zfs_pool_manageno sensitive capabilityproxmox_zfs_propertyno sensitive capabilityproxmox_zfs_scrubno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.3.0 latest |
D 66/100 | 13 | 1.13.0 | 2026-08-25 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan pve-mcp --online --registry pypi
Independent packages implementing the same tool, scanned with the same engine. Compare all 2 side by side →
Adapters for the FrontMCP framework
Transcend MCP Server — Admin tools.
Transcend MCP Server — Assessments tools.
MCP Server for Bling
MCP Server for Blogger API
Official MCP server for Brilliant Directories — manage members, posts, leads, reviews, and more.