{
  "schema_version": "2.0",
  "slug": "john-broadway-proximo",
  "name": "Proximo",
  "agent_url": "https://john-broadway.github.io/proximo/",
  "repo_url": "https://github.com/john-broadway/proximo",
  "category": "Infrastructure",
  "run_id": "run-2aae75e32a79fa1f-john-broadway-github-io",
  "run_at": "2026-08-13T20:30:35.710Z",
  "reviewed_at": "2026-08-14",
  "generated_at": "2026-08-14T21:33:25Z",
  "editor": "Hlido Editor",
  "editorial_method": "public-surface-tier-2+editorial-narrative-v2",
  "methodology_version": "2026.08",
  "methodology_url": "/methodology/public-surface-tier-1/",
  "engine": "public-surface",
  "evidence_tier": "screenshot",
  "score": 76,
  "tier": "STEADY",
  "laddoo_score": 76,
  "confidence": "medium",
  "review_url": "/reviews/john-broadway-proximo/",
  "hlido_opinion": {
    "headline": "A Proxmox MCP server whose landing page includes a section listing what it cannot protect you from — including that its own risk ratings are 'advice, not armor'. The prose is theatrical; the safety thinking underneath is not.",
    "body": "Proximo wraps Proxmox virtualisation management in an explicit safety model: PLAN returns the blast radius of every mutation and nothing executes until confirm=true; PROVE writes to a keyed, hash-chained ledger where altering one line breaks the chain at that line, with an off-box head pin so truncation is also detectable; UNDO takes a snapshot before risky operations wherever the platform supports it; DIAGNOSE is a read-only evidence battery that reports what it could not see, so silence never reads as a clean result. Six further controls — consent, kill-switch, lease, scope, envelope, taint-guard — are described as opt-in, with the important caveat stated plainly: each becomes a real wall only once its state lives beyond the agent's own reach. That last point is the sort of thing most tools in this category never say, and it recurs. The page carries an explicit disclosure section — 'the helmet comes off' — that states risk ratings are advice rather than armour, that LOW means 'no state change' and never 'safe', and that the absence of a HIGH flag is not a safety signal. A vendor volunteering the limits of its own guardrails is rare and worth crediting. The costs are that the gladiatorial framing is laid on heavily enough to slow down a reader trying to extract facts, and that the safety machinery — like MikroMCP's — is described rather than demonstrated: no sample ledger entry, no worked plan output, no verification walkthrough. The design intent is unusually sound; the evidence for it remains assertion.",
    "voice": "Hlido Editor",
    "as_of": "2026-08-14",
    "editor_signature_pending": true
  },
  "tier_rationale": "STEADY because the public surface does something genuinely rare — it states the boundaries of its own protections rather than only their strengths — and because the four standard controls are specific and mechanically described rather than gestured at. Held out of the top band because none of it is demonstrated with sample output, the six optional controls are explicitly conditional on external state that the user must arrange, and the heavy stylistic framing raises the cost of evaluating the tool.",
  "what_it_does_well": [
    "Publishes what its guardrails do NOT protect against — including that risk ratings are advice, not armour",
    "Plan-before-execute with an explicit confirm=true gate on every mutation",
    "Hash-chained, keyed ledger with an off-box head pin, so both alteration and truncation are detectable",
    "Snapshot-first undo wherever the platform supports snapshots",
    "Diagnostics report what could not be observed, so silence is never mistaken for a clean result",
    "States that the optional controls only become real once their state lives outside the agent's reach"
  ],
  "what_it_fails_at": [
    "No sample ledger entry, plan output or verification walkthrough — the safety model is described, never shown",
    "Six of the ten controls are opt-in and conditional on user-arranged external state",
    "The gladiatorial framing is heavy enough to slow factual evaluation",
    "No version, changelog or release-cadence signal on the reviewed surface",
    "No tool inventory or client compatibility list published"
  ],
  "best_for": [
    "Proxmox operators who want agent assistance but require a plan-and-confirm gate before any mutation",
    "Teams that need a tamper-evident audit trail of what an agent did to their infrastructure",
    "Anyone who has rejected AI infrastructure tooling on safety grounds and wants to see the limits stated up front"
  ],
  "not_recommended_for": [
    "Readers who need to extract facts quickly; the styling materially slows evaluation",
    "Non-Proxmox environments — this is platform-specific by design",
    "Teams wanting demonstrated rather than described safety guarantees before production use"
  ],
  "red_flags": [
    "The safety machinery is described in detail but never demonstrated — no sample ledger, plan or rollback appears anywhere on the surface.",
    "Six of the ten advertised controls are opt-in and only become effective once their state is held outside the agent's reach. The page says so honestly, but a reader skimming the feature list could easily count ten protections when four are active by default."
  ],
  "compared_to": [
    {
      "slug": "alikarami-mikromcp",
      "verdict_diff": "The closest philosophical sibling — both lead with change-safety for infrastructure agents. MikroMCP covers RouterOS network gear and publishes a larger typed tool surface; Proximo covers Proxmox and goes further in disclosing where its own guarantees stop.",
      "preferred_for_axis": "platform-and-disclosure-depth"
    },
    {
      "slug": "nwiizo-tfmcp",
      "verdict_diff": "Both hand an agent infrastructure mutation rights. Proximo publishes a detailed plan/prove/undo model; tfmcp publishes none. If safety posture drives the decision, this is the clearer of the two.",
      "preferred_for_axis": "published-safety-model"
    }
  ],
  "agent_relevance": {
    "has_api": false,
    "has_cli": false,
    "has_mcp": true,
    "has_webhook": false,
    "has_sdk": false,
    "behavioral_testable": true,
    "agent_integration_path": "MCP server built around agent operation: mutations return blast radius first and require an explicit confirm flag, which is a well-shaped propose-then-commit pattern for autonomous callers. Diagnostics are read-only and explicitly report observation gaps. No published tool inventory, so capability discovery happens at connect time.",
    "agent_friendly_score": 8
  },
  "claims": [
    {
      "id": "C01",
      "claim": "Homepage publicly accessible and value proposition clearly stated",
      "required": true,
      "verdict": "pass",
      "evidence": "Loads without auth; states it is a Proxmox MCP server and describes the plan/prove/undo/diagnose model in the first screens.",
      "source_surface": "homepage"
    },
    {
      "id": "C02",
      "claim": "Pricing page discoverable in 2 clicks from homepage",
      "required": false,
      "verdict": "unverified",
      "evidence": "Open-source project with a public repository; no pricing surface expected.",
      "source_surface": "homepage"
    },
    {
      "id": "C03",
      "claim": "Documentation or live demo accessible without login",
      "required": true,
      "verdict": "partial_pass",
      "evidence": "Substantial conceptual documentation of each control plus an explicit limitations page, but no install guide, reference or worked example on the reviewed surface.",
      "source_surface": "homepage"
    },
    {
      "id": "C04",
      "claim": "Integration list or supported frameworks documented",
      "required": true,
      "verdict": "fail",
      "evidence": "No MCP client list, tool inventory or transport detail published.",
      "source_surface": "homepage"
    },
    {
      "id": "C05",
      "claim": "Authentication / data handling claims publicly stated",
      "required": false,
      "verdict": "partial_pass",
      "evidence": "The ledger, consent, lease and scope controls are described, and their limits disclosed, but Proxmox credential handling itself is not addressed.",
      "source_surface": "homepage"
    }
  ],
  "evidence_urls": [
    {
      "claim": "Homepage publicly accessible and value proposition clearly stated",
      "source": "https://john-broadway.github.io/proximo/",
      "tested_at": "2026-08-14",
      "verified": true
    },
    {
      "claim": "Pricing page discoverable in 2 clicks from homepage",
      "source": "https://john-broadway.github.io/proximo/",
      "tested_at": "2026-08-14",
      "verified": false
    },
    {
      "claim": "Documentation or live demo accessible without login",
      "source": "https://john-broadway.github.io/proximo/",
      "tested_at": "2026-08-14",
      "verified": false
    },
    {
      "claim": "Integration list or supported frameworks documented",
      "source": "https://john-broadway.github.io/proximo/",
      "tested_at": "2026-08-14",
      "verified": false
    },
    {
      "claim": "Authentication / data handling claims publicly stated",
      "source": "https://john-broadway.github.io/proximo/",
      "tested_at": "2026-08-14",
      "verified": false
    }
  ],
  "marking_signal": {
    "not_applicable": true,
    "rationale": "Virtualisation management server; it operates existing Proxmox infrastructure and does not generate synthetic media, so Article 50(4) marking duties do not attach.",
    "checked_at": "2026-08-14"
  },
  "evidence_images": {
    "run_id": "run-2aae75e32a79fa1f-john-broadway-github-io",
    "base": "https://images.hlido.eu/reviews/john-broadway-proximo/run-2aae75e32a79fa1f-john-broadway-github-io",
    "files": [
      "home.png",
      "page_kit.png"
    ],
    "urls": [
      "https://images.hlido.eu/reviews/john-broadway-proximo/run-2aae75e32a79fa1f-john-broadway-github-io/home.png",
      "https://images.hlido.eu/reviews/john-broadway-proximo/run-2aae75e32a79fa1f-john-broadway-github-io/page_kit.png"
    ]
  },
  "pricing_facts": {
    "schema": "pricing-facts/1",
    "model": [
      "open-source"
    ],
    "free_tier": true,
    "last_verified": "2026-08-13",
    "basis": "Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page.",
    "derived_at": "2026-08-21"
  }
}
