pve_overbroad_grants
Detect over-broad ACL grants where administrator roles are assigned on the root path, enabling least-privilege diagnosis. Read-only report returns flagged entries.
Instructions
READ-ONLY: surface over-broad ACL grants — Administrator-role assignments or grants on the root '/' path — as a least-privilege diagnostic.
No state change; this only reports, it does not revoke anything. Returns a list of the flagged ACL entries (empty when none). Use pve_acl_list for the full ACL and pve_acl_modify to tighten a finding.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| proximo_target | No | Which configured Proxmox target to run this call against — a target name from your multi-target config (a specific PVE/PBS/PMG/PDM box). Omit to use the single/default target from the environment; the selection applies only to this call. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |