hcloud-security
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as certificate files, public key files, and labels from Hetzner Cloud resources. These ingestion points (e.g.,
--public-key-from-file,--cert-file, and label selectors) lack explicit boundary markers or instructions to ignore embedded commands. This creates an attack surface where a malicious input could potentially influence the agent's behavior. - Ingestion points:
--public-key-from-fileinhcloud ssh-key create,--cert-fileand--key-fileinhcloud certificate create, and label values retrieved duringhcloud server list -loperations. - Boundary markers: None detected in the documentation to isolate processed content from agent instructions.
- Capability inventory: The skill uses
hcloudCLI commands to write sensitive files (keys/certs) and delete cloud resources. - Sanitization: No evidence of sanitization for labels or file contents before they are handled by the agent context.
- [DATA_EXFILTRATION]: While the skill does not contain direct network exfiltration logic, it provides commands to read and upload private cryptographic material (
--key-fileinhcloud certificate create). An agent using this skill could potentially be manipulated into reading sensitive local files and transmitting their content if not restricted. - [COMMAND_EXECUTION]: The skill documentation provides shell command templates for the
hcloudCLI. If the agent populates these templates using unvalidated user input or data from external resource labels, it could lead to command injection, particularly in fields like--name,--label, or<id-or-name>.
Audit Metadata