Critical-risk tools in Proxmox MCP Server
28 of the 286 tools in Proxmox MCP Server are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
convert_container_to_templateDestructiveConvert a container into a template (irreversible).
-
convert_vm_to_templateDestructiveConvert a VM into a template (irreversible).
-
delete_backup_jobDestructiveDelete a scheduled backup job.
-
delete_cluster_firewall_ruleDestructiveDelete a cluster-level firewall rule.
-
delete_containerDestructivedelete_container
-
delete_container_snapshotDestructiveDelete a container snapshot.
-
delete_firewall_aliasDestructiveDelete a firewall alias.
-
delete_firewall_ipset_entryDestructiveRemove an IP/CIDR from an IP set.
-
delete_groupDestructiveDelete a group.
-
delete_ha_groupDestructiveDelete an HA group.
-
delete_ha_resourceDestructiveRemove a resource from HA management.
-
delete_poolDestructiveDelete a resource pool.
-
delete_replication_jobDestructiveDelete a replication job.
-
delete_roleDestructiveDelete a role.
-
delete_sdn_vnetDestructiveDelete an SDN VNet.
-
delete_sdn_zoneDestructiveDelete an SDN zone.
-
delete_storageDestructiveDelete a storage pool configuration (does not delete data on the backend).
-
delete_storage_volumeDestructiveDelete a volume from storage.
-
delete_userDestructiveDelete a user.
-
delete_user_tokenDestructiveDelete an API token.
-
delete_vmDestructiveDelete a VM. The VM must be stopped first.
-
delete_vm_snapshotDestructiveDelete a VM snapshot.
-
initialize_gptDestructiveInitialize a disk with GPT partition table (WARNING: destroys all data).
-
prune_storage_backupsDestructiveprune_storage_backups
-
rollback_container_snapshotDestructiveRollback a container to a previous snapshot.
-
rollback_vm_snapshotDestructiveRollback a VM to a previous snapshot (current state will be lost).
-
shutdown_vmDestructiveshutdown_vm
-
stopall_nodeDestructiveStop all VMs and containers on a node.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.