Proximo
Infrastructure · tested 2026-08-14 · by the Hlido desk, not the vendor
In short: A Proxmox MCP server whose landing page includes a section listing what it cannot protect you from — including that its own risk ratings are 'advice, not armor'. The prose is theatrical; the safety thinking underneath is not.
Quick answer
Proximo scores 76/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-14). STEADY because the public surface does something genuinely rare — it states the boundaries of its own protections rather than only their strengths — and because the four standard controls are specific and mechanically de Pricing: Open source (free entry point documented).
Proximo wraps Proxmox virtualisation management in an explicit safety model: PLAN returns the blast radius of every mutation and nothing executes until confirm=true; PROVE writes to a keyed, hash-chained ledger where altering one line breaks the chain at that line, with an off-box head pin so truncation is also detectable; UNDO takes a snapshot before risky operations wherever the platform supports it; DIAGNOSE is a read-only evidence battery that reports what it could not see, so silence never reads as a clean result. Six further controls — consent, kill-switch, lease, scope, envelope, taint-guard — are described as opt-in, with the important caveat stated plainly: each becomes a real wall only once its state lives beyond the agent's own reach. That last point is the sort of thing most tools in this category never say, and it recurs. The page carries an explicit disclosure section — 'the helmet comes off' — that states risk ratings are advice rather than armour, that LOW means 'no state change' and never 'safe', and that the absence of a HIGH flag is not a safety signal. A vendor volunteering the limits of its own guardrails is rare and worth crediting. The costs are that the gladiatorial framing is laid on heavily enough to slow down a reader trying to extract facts, and that the safety machinery — like MikroMCP's — is described rather than demonstrated: no sample ledger entry, no worked plan output, no verification walkthrough. The design intent is unusually sound; the evidence for it remains assertion.
Why STEADY
STEADY because the public surface does something genuinely rare — it states the boundaries of its own protections rather than only their strengths — and because the four standard controls are specific and mechanically described rather than gestured at. Held out of the top band because none of it is demonstrated with sample output, the six optional controls are explicitly conditional on external state that the user must arrange, and the heavy stylistic framing raises the cost of evaluating the tool.
What we saw
2 screenshots captured by the Hlido engine during the reviewed run (run-2aae75e32a79fa1f-john-broadway-github-io). Our own captures — not vendor marketing material.
What it does well
- Publishes what its guardrails do NOT protect against — including that risk ratings are advice, not armour
- Plan-before-execute with an explicit confirm=true gate on every mutation
- Hash-chained, keyed ledger with an off-box head pin, so both alteration and truncation are detectable
- Snapshot-first undo wherever the platform supports snapshots
- Diagnostics report what could not be observed, so silence is never mistaken for a clean result
- States that the optional controls only become real once their state lives outside the agent's reach
What it fails at
- No sample ledger entry, plan output or verification walkthrough — the safety model is described, never shown
- Six of the ten controls are opt-in and conditional on user-arranged external state
- The gladiatorial framing is heavy enough to slow factual evaluation
- No version, changelog or release-cadence signal on the reviewed surface
- No tool inventory or client compatibility list published
Red flags
- The safety machinery is described in detail but never demonstrated — no sample ledger, plan or rollback appears anywhere on the surface.
- Six of the ten advertised controls are opt-in and only become effective once their state is held outside the agent's reach. The page says so honestly, but a reader skimming the feature list could easily count ten protections when four are active by default.
Best for
- Proxmox operators who want agent assistance but require a plan-and-confirm gate before any mutation
- Teams that need a tamper-evident audit trail of what an agent did to their infrastructure
- Anyone who has rejected AI infrastructure tooling on safety grounds and wants to see the limits stated up front
Not recommended for
- Readers who need to extract facts quickly; the styling materially slows evaluation
- Non-Proxmox environments — this is platform-specific by design
- Teams wanting demonstrated rather than described safety guarantees before production use
Pricing & access
- ModelOpen source
- Free entry pointYes — a free tier or open-source edition is documented
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-13.
Compared to
-
MikroMCP
platform-and-disclosure-depth
The closest philosophical sibling — both lead with change-safety for infrastructure agents. MikroMCP covers RouterOS network gear and publishes a larger typed tool surface; Proximo covers Proxmox and goes further in disclosing where its own guarantees stop.
-
tfmcp
published-safety-model
Both hand an agent infrastructure mutation rights. Proximo publishes a detailed plan/prove/undo model; tfmcp publishes none. If safety posture drives the decision, this is the clearer of the two.
Agent relevance
MCP Behavioral-testable
Agentic-Commerce Readiness 46/100 · SURFACE-ONLY
Independent readiness for agent delegation & transaction. How it’s scored · check live
MCP server built around agent operation: mutations return blast radius first and require an explicit confirm flag, which is a well-shaped propose-then-commit pattern for autonomous callers. Diagnostics are read-only and explicitly report observation gaps. No published tool inventory, so capability discovery happens at connect time.
Agent-friendly score: 8/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Homepage publicly accessible and value proposition clearly stated — source (2026-08-14) verified
- Pricing page discoverable in 2 clicks from homepage — source (2026-08-14)
- Documentation or live demo accessible without login — source (2026-08-14)
- Integration list or supported frameworks documented — source (2026-08-14)
- Authentication / data handling claims publicly stated — source (2026-08-14)

