hetzner-server

Fail

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to create a server using a user-data configuration that fetches and executes a remote shell script from an untrusted source.
  • Evidence: curl -fsSL https://raw.githubusercontent.com/connorads/dotfiles/master/install.sh | bash in SKILL.md.
  • Source: The script is hosted in a personal GitHub repository ('connorads') which is not associated with the skill author ('LucasDuarteInacio') or any trusted vendor.
  • Impact: This script runs with root privileges during the initial boot of the cloud server, enabling arbitrary code execution.
  • [COMMAND_EXECUTION]: The skill relies on the execution of multiple shell commands to manage infrastructure and local configuration.
  • It uses the hcloud CLI for server lifecycle and resource management.
  • It uses ssh to perform administrative tasks on remote servers, including modifying system files using sudo (e.g., /etc/fstab for swap configuration).
  • It references a custom command hcssh to modify the user's local SSH configuration file (~/.ssh/config), which is an external dependency not contained within the skill.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/connorads/dotfiles/master/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — hetzner-server