High-risk tools in MCP Proxmox Server
33 of the 124 tools in MCP Proxmox Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
proxmox_ai_scalingExecuteAI-powered predictive scaling based on usage patterns
-
proxmox_ansible_playbookExecuteExecute Ansible playbooks against Proxmox VMs
-
proxmox_api_gatewayExecuteDeploy API gateway for enhanced API management
-
proxmox_auto_optimizeExecuteAutomatically optimize VM configurations based on usage patterns
-
proxmox_create_docker_swarmExecuteCreate Docker Swarm cluster with manager and worker nodes.
-
proxmox_create_docker_swarm_presetExecuteCreate Docker Swarm cluster with preset configurations (web, development, production).
-
proxmox_deploy_openshift_clusterExecuteDeploy complete OpenShift cluster (bootstrap + masters + workers).
-
proxmox_deploy_openshift_snoExecuteDeploy OpenShift Single Node Openshift (SNO) cluster.
-
proxmox_deploy_vpn_serverExecuteDeploy VPN server for secure remote access
-
proxmox_docker_execute_commandExecuteExecute Docker command on cluster node.
-
proxmox_docker_service_createExecuteCreate Docker Swarm service.
-
proxmox_docker_service_scaleExecuteScale Docker Swarm service.
-
proxmox_docker_swarm_initExecuteInitialize Docker Swarm on primary manager node.
-
proxmox_docker_swarm_joinExecuteJoin node to existing Docker Swarm cluster.
-
proxmox_gitops_syncExecuteSync infrastructure state with Git repository
-
proxmox_guest_execExecuteproxmox_guest_exec
-
proxmox_integrate_serviceExecuteIntegrate with external services for notifications and automation
-
proxmox_migrate_storageExecuteMigrate VM storage between different storage backends
-
proxmox_migrate_vmExecuteproxmox_migrate_vm
-
proxmox_reboot_vmExecuteproxmox_reboot_vm
-
proxmox_setup_monitoringExecuteDeploy comprehensive monitoring stack
-
proxmox_start_lxcExecuteproxmox_start_lxc
-
proxmox_start_vmExecuteproxmox_start_vm
-
proxmox_stop_lxcExecuteproxmox_stop_lxc
-
proxmox_stop_vmExecuteproxmox_stop_vm
-
proxmox_terraform_planExecuteExecute Terraform plans for infrastructure as code
-
proxmox_wait_taskExecuteproxmox_wait_task
-
proxmox_windows_configure_rdpExecuteConfigure Windows Remote Desktop Protocol.
-
proxmox_windows_domain_joinExecuteJoin Windows VM to Active Directory domain.
-
proxmox_windows_execute_commandExecuteExecute command on Windows VM via QEMU guest agent.
-
proxmox_windows_install_appsExecuteInstall applications on Windows VM.
-
proxmox_windows_servicesExecuteManage Windows services (list, restart).
-
proxmox_windows_updatesExecuteInstall Windows updates via PowerShell.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.