High-risk tools in Proxmox MCP Server
37 of the 286 tools in Proxmox MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
apply_sdn_changesExecuteApply pending SDN configuration changes to all nodes.
-
bulk_migrate_guestsExecuteBulk migrate guests to a target node.
-
bulk_shutdown_guestsExecuteBulk shutdown guests across the cluster.
-
bulk_start_guestsExecuteBulk start guests across the cluster.
-
create_vzdumpExecutecreate_vzdump
-
get_vm_spiceproxyExecuteCreate a SPICE proxy connection for a VM console.
-
get_vm_vncproxyExecuteCreate a VNC proxy connection ticket for a VM (for console access).
-
join_clusterExecutejoin_cluster
-
manage_node_serviceExecuteStart, stop, restart, or reload a system service on a node.
-
migrate_containerExecutemigrate_container
-
migrate_ha_resourceExecuteRequest migration of an HA resource to a different node.
-
migrate_vmExecutemigrate_vm
-
order_node_certificateExecuteOrder/renew ACME certificate for a node.
-
proxmox_api_rawExecuteMake an arbitrary Proxmox API call for any endpoint not covered by specific tools.
-
reboot_containerExecuteReboot a container.
-
reboot_vmExecuteReboot a VM via ACPI.
-
relocate_ha_resourceExecuteRequest relocation of an HA resource to a different node.
-
reset_vmExecuteHard reset a VM (like pressing the reset button).
-
resume_containerExecuteResume a suspended container.
-
resume_vmExecuteResume a suspended/paused VM.
-
run_apt_updateExecuteRefresh the package index on a node (apt update).
-
send_vm_keyExecuteSend a key event to a VM (e.g. ctrl-alt-del).
-
send_vm_monitor_commandExecuteSend a QEMU monitor command to a VM (advanced/low-level).
-
set_ceph_flagsExecuteSet a Ceph global flag.
-
shutdown_containerExecuteGracefully shut down a container.
-
start_containerExecuteStart a container.
-
start_vmExecuteStart a VM.
-
startall_nodeExecuteStart all VMs and containers on a node (respecting boot order).
-
stop_containerExecuteHard-stop a container (immediate, like power off).
-
stop_taskExecuteStop (abort) a running task.
-
stop_vmExecuteHard-stop a VM (like pulling the power plug). Prefer shutdown_vm for graceful stop.
-
suspend_containerExecuteSuspend (freeze) a container.
-
suspend_vmExecuteSuspend a VM (pause execution or hibernate to disk).
-
test_notification_targetExecuteSend a test notification to a target.
-
vm_agent_execExecuteExecute a command inside a VM via the QEMU Guest Agent.
-
vm_agent_set_passwordExecuteSet a user password inside a VM via the guest agent.
-
wakeonlan_nodeExecuteSend a Wake-on-LAN magic packet to a node.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.