hcloud-networking
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions facilitate the ingestion of untrusted data which could be used to influence agent behavior through configuration poisoning.
- Ingestion points:
SKILL.mddefines commands such ashcloud firewall create --rules-file <file>andhcloud firewall replace-rules --rules-file <file>that read from external JSON files or stdin. - Boundary markers: Absent. The documentation does not provide instructions to the agent to treat these external files as untrusted or to validate their contents.
- Capability inventory: The skill has the capability to perform wide-ranging network configuration changes (firewalls, load balancers, network routes) using the
hcloudCLI. - Sanitization: Absent. There is no evidence of input validation or escaping for the data read from external rule files.
- [COMMAND_EXECUTION]: The skill provides numerous templates for executing shell commands via the
hcloudCLI tool. - Evidence: The commands in
SKILL.mdincorporate many user-supplied placeholders like<name>,<cidr>, and<ips>. This creates a surface for command injection if the agent does not properly sanitize these values before execution.
Audit Metadata