hcloud-storage

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the management of Hetzner Cloud infrastructure by providing templates for the hcloud command-line utility. These templates cover administrative tasks such as volume creation, storage box management, and snapshot operations.\n- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data by listing and describing cloud resources, which creates an inherent attack surface for indirect prompt injection if those resources contain malicious content.\n
  • Ingestion points: Commands such as hcloud volume list and hcloud storage-box describe ingest data from the Hetzner Cloud API (SKILL.md).\n
  • Boundary markers: The skill does not define specific delimiters to separate untrusted cloud data from agent instructions.\n
  • Capability inventory: The agent can perform high-impact actions including deleting storage volumes, resetting passwords, and modifying subaccount access permissions via the hcloud CLI.\n
  • Sanitization: No explicit input validation or output sanitization logic is provided for handling resource labels, names, or descriptions before they are used in command arguments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:30 PM
Security Audit — agent-trust-hub — hcloud-storage