hcloud-servers
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to use the
hcloudcommand-line tool. These commands perform administrative operations on cloud infrastructure, including creating, deleting, and modifying servers and network configurations. - [INDIRECT_PROMPT_INJECTION]: The skill identifies multiple points where untrusted user input (such as server names, image IDs, and file paths) is interpolated into shell commands. This represents a potential attack surface if the agent does not properly sanitize these inputs before execution.
- Ingestion points: Placeholders for command arguments and flags throughout
SKILL.md(e.g.,<name>,<server>,<file>,<label>). - Boundary markers: None are specified in the skill's instructions to delimit user input from command logic.
- Capability inventory: The skill enables full management of cloud infrastructure, including shell access via
hcloud server sshand password resets viahcloud server reset-password. - Sanitization: No explicit sanitization or validation logic is provided within the skill; security relies on the agent's underlying execution environment.
Audit Metadata