hcloud-storage
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the management of Hetzner Cloud infrastructure by providing templates for the
hcloudcommand-line utility. These templates cover administrative tasks such as volume creation, storage box management, and snapshot operations.\n- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data by listing and describing cloud resources, which creates an inherent attack surface for indirect prompt injection if those resources contain malicious content.\n - Ingestion points: Commands such as
hcloud volume listandhcloud storage-box describeingest data from the Hetzner Cloud API (SKILL.md).\n - Boundary markers: The skill does not define specific delimiters to separate untrusted cloud data from agent instructions.\n
- Capability inventory: The agent can perform high-impact actions including deleting storage volumes, resetting passwords, and modifying subaccount access permissions via the
hcloudCLI.\n - Sanitization: No explicit input validation or output sanitization logic is provided for handling resource labels, names, or descriptions before they are used in command arguments.
Audit Metadata