proxmox-ve

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Anomaly
AnomalyLOW
samples/api-automation.md

No clear malicious payload, exfiltration mechanism, persistence mechanism, or obfuscation is present in the shown fragment; it is consistent with legitimate Proxmox VE admin automation. The main risks are operational and supply-chain related: an API token is embedded/shown in code, and curl uses -k/-sk to disable TLS certificate verification for authenticated control-plane requests. Because the example includes powerful write operations (start/stop workloads, create containers, create users, change cluster options), exposure or tampering of the token/script would create high-impact abuse potential.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Aug 8, 2026, 09:29 PM
Package URL
pkg:socket/skills-sh/fandhe-ai%2Fagent-reference-skills%2Fproxmox-ve%2F@20706c03fde15e9db17bc39f6bc0f68dd436aeca96450f8d43809bfea657f052
Security Audit — socket — proxmox-ve