hcloud-servers

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to use the hcloud command-line tool. These commands perform administrative operations on cloud infrastructure, including creating, deleting, and modifying servers and network configurations.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies multiple points where untrusted user input (such as server names, image IDs, and file paths) is interpolated into shell commands. This represents a potential attack surface if the agent does not properly sanitize these inputs before execution.
  • Ingestion points: Placeholders for command arguments and flags throughout SKILL.md (e.g., <name>, <server>, <file>, <label>).
  • Boundary markers: None are specified in the skill's instructions to delimit user input from command logic.
  • Capability inventory: The skill enables full management of cloud infrastructure, including shell access via hcloud server ssh and password resets via hcloud server reset-password.
  • Sanitization: No explicit sanitization or validation logic is provided within the skill; security relies on the agent's underlying execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:30 PM
Security Audit — agent-trust-hub — hcloud-servers