hetzner-server
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill includes a pre-configured command for server creation that uses
user-datato download and execute a shell script directly from an untrusted external repository (https://raw.githubusercontent.com/connorads/dotfiles/master/install.sh). This script is piped directly intobashand executed with root privileges on the target server. - [COMMAND_EXECUTION]: The skill makes extensive use of local shell commands via the
hcloudCLI and remote command execution viassh. These commands are used for infrastructure management, server configuration, and monitoring installation progress. - [EXTERNAL_DOWNLOADS]: The provisioning process involves fetching external content from GitHub's raw content servers, which introduces a dependency on untrusted third-party code for the initial server setup.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/connorads/dotfiles/master/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata