hetzner-server
Fail
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to create a server using a user-data configuration that fetches and executes a remote shell script from an untrusted source.
- Evidence:
curl -fsSL https://raw.githubusercontent.com/connorads/dotfiles/master/install.sh | bashinSKILL.md. - Source: The script is hosted in a personal GitHub repository ('connorads') which is not associated with the skill author ('LucasDuarteInacio') or any trusted vendor.
- Impact: This script runs with root privileges during the initial boot of the cloud server, enabling arbitrary code execution.
- [COMMAND_EXECUTION]: The skill relies on the execution of multiple shell commands to manage infrastructure and local configuration.
- It uses the
hcloudCLI for server lifecycle and resource management. - It uses
sshto perform administrative tasks on remote servers, including modifying system files usingsudo(e.g.,/etc/fstabfor swap configuration). - It references a custom command
hcsshto modify the user's local SSH configuration file (~/.ssh/config), which is an external dependency not contained within the skill.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/connorads/dotfiles/master/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata