proxmox-ve
Warn
Audited by Socket on Aug 8, 2026
1 alert found:
AnomalyAnomalysamples/api-automation.md
LOWAnomalyLOW
samples/api-automation.md
No clear malicious payload, exfiltration mechanism, persistence mechanism, or obfuscation is present in the shown fragment; it is consistent with legitimate Proxmox VE admin automation. The main risks are operational and supply-chain related: an API token is embedded/shown in code, and curl uses -k/-sk to disable TLS certificate verification for authenticated control-plane requests. Because the example includes powerful write operations (start/stop workloads, create containers, create users, change cluster options), exposure or tampering of the token/script would create high-impact abuse potential.
Confidence: 62%Severity: 52%
Audit Metadata