Agent skill

Hetzner Cloud

by HybridAIOne in HybridAIOne/hybridclaw

Read and operate Hetzner Cloud servers, server types, locations, networks, volumes, snapshots, and cost estimates through gateway-proxied API requests.

MITAuto-check passed

Install Hetzner Cloud

skills CLI
$ npx skills add HybridAIOne/hybridclaw --skill hetzner-cloud -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HybridAIOne/hybridclaw hetzner-cloud --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hetzner-cloud .claude/skills/hetzner-cloud && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hetzner-cloud
GitHub stars
158
Token cost
~2.4k tokens
SKILL.md length
669 words
Files
5 (incl. references)
Skills in repo
71
Repo updated
First seen
Licence
MIT

At a glance

Read and operate Hetzner Cloud servers, server types, locations, networks, volumes, snapshots, and cost estimates through gateway-proxied API requests.

  • Works in 11 steps: Start read-only: list servers,… → Use plan for natural-language requests… → Treat hetzner_cloud.cjs as the API… → …
  • SKILL.md covers Default Workflow, Command Contract, Working Rules and Eval Suite, plus 1 more section
  • Runs JavaScript scripts from its folder; calls node and python3; needs HETZNER_API_TOKEN

What it does

Hetzner Cloud is an agent skill from HybridAIOne/hybridclaw. Read and operate Hetzner Cloud servers, server types, locations, networks, volumes, snapshots, and cost estimates through gateway-proxied API requests.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `evals/scenarios.json` and `references/operator-setup.md`).

The repository describes itself as: Enterprise-ready self-hosted AI assistant runtime with sandboxed execution, secure credentials, approvals, and memory. The licence is MIT.

Example prompts

  • “/hetzner-cloud”

Requirements

  • Python 3
  • A credential in HETZNER_API_TOKEN

Workflow steps

11 steps, taken from the first numbered list in SKILL.md.

  1. Start read-only: list servers, locations, server types, images, prices,
  2. Use plan for natural-language requests before building any write request.
  3. Treat hetzner_cloud.cjs as the API wrapper. Do not handcraft Hetzner Cloud
  4. For prompt/user testing, stop after plan or after helper http-request
  5. For real user requests that need live Hetzner API data, use helper run.
  6. Use http-request only when you need to inspect the generated gateway
  7. If a live helper run or http_request call returns 401 or 403, stop after
  8. Require an explicit operator grant before any changing action, including
  9. Use --project acme for project-scoped inventory and provisioning. The
  10. Never paste, print, or inspect HETZNER_API_TOKEN; the gateway injects it
  11. Do not repeat the same read call unless the previous result was ambiguous or

What it can do on your machine

Read from SKILL.md and the folder at commit 3624072. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • HETZNER_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hetzner Cloud loads about 2.4k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 41 tokens; SKILL.md has 669 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HybridAIOne/hybridclaw at commit 3624072, republished under its MIT licence (© HybridAIOne). 669 words, ~2,379 tokens.

Download SKILL.mdSave it as .claude/skills/hetzner-cloud/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hetzner-cloud
description
Read and operate Hetzner Cloud servers, server types, locations, networks, volumes, snapshots, and cost estimates through gateway-proxied API requests.
user-invocable
true
requires.bins
node

Hetzner Cloud

Use this skill for Hetzner Cloud VPS inventory, provisioning, network and volume inspection, cost estimates, and snapshot lifecycle work.

Default Workflow

  1. Start read-only: list servers, locations, server types, images, prices, volumes, and networks.
  2. Use plan for natural-language requests before building any write request.
  3. Treat hetzner_cloud.cjs as the API wrapper. Do not handcraft Hetzner Cloud API URLs, JSON bodies, tiers, or secret refs from memory.
  4. For prompt/user testing, stop after plan or after helper http-request payload generation. Do not call helper run or the built-in http_request tool.
  5. For real user requests that need live Hetzner API data, use helper run. The helper constructs the request, sends it through the HybridClaw gateway, and the gateway injects bearerSecretName: "HETZNER_API_TOKEN" server-side. Do not rewrite that secret reference into secretHeaders, preflight it, inspect it, or ask the model for the token.
  6. Use http-request only when you need to inspect the generated gateway payload or when the active runtime cannot give the helper gateway access.
  7. If a live helper run or http_request call returns 401 or 403, stop after that first failure. Do not retry, do not fan out to more endpoints, and ask the operator to set or verify HETZNER_API_TOKEN.
  8. Require an explicit operator grant before any changing action, including delete, upgrade, downgrade, buy/create, restore, attach, detach, snapshot, network, or volume mutation. Pass --operator-grant only after that grant.
  9. Use --project acme for project-scoped inventory and provisioning. The helper converts it to project=acme label selectors or labels where the Hetzner API supports them.
  10. Never paste, print, or inspect HETZNER_API_TOKEN; the gateway injects it server-side with bearerSecretName: "HETZNER_API_TOKEN".
  11. Do not repeat the same read call unless the previous result was ambiguous or stale. For a named resize, one list-servers --project <project> --name <name> call is enough to resolve the server id.

See references/operator-setup.md for operator setup, token scope, autonomy defaults, and cost-reporting expectations.

Command Contract

Run the helper:

bash
node skills/hetzner-cloud/hetzner_cloud.cjs --help

Plan a request without contacting Hetzner:

bash
node skills/hetzner-cloud/hetzner_cloud.cjs --format json plan "Create a demo VPS in Falkenstein until Monday"

Run live read requests:

bash
node skills/hetzner-cloud/hetzner_cloud.cjs --format json run list-servers --project acme
node skills/hetzner-cloud/hetzner_cloud.cjs --format json run list-server-types
node skills/hetzner-cloud/hetzner_cloud.cjs --format json run list-locations
node skills/hetzner-cloud/hetzner_cloud.cjs --format json run list-prices --project acme
node skills/hetzner-cloud/hetzner_cloud.cjs --format json run list-volumes --project acme
node skills/hetzner-cloud/hetzner_cloud.cjs --format json run list-networks --project acme

Run guarded live write requests:

bash
node skills/hetzner-cloud/hetzner_cloud.cjs --format json run create-server \
  --name acme-demo --server-type cax11 --image ubuntu-24.04 --location fsn1 \
  --project acme --label ttl=2026-05-18 --operator-grant

node skills/hetzner-cloud/hetzner_cloud.cjs --format json run create-snapshot \
  --project acme --server-id 123456 --description "pre-deploy" --operator-grant

node skills/hetzner-cloud/hetzner_cloud.cjs --format json run restore-snapshot \
  --server-id 123456 --snapshot-id 987654 --operator-grant

node skills/hetzner-cloud/hetzner_cloud.cjs --format json run attach-network \
  --server-id 123456 --network-id 555 --ip 10.0.0.12 --operator-grant

node skills/hetzner-cloud/hetzner_cloud.cjs --format json run attach-volume \
  --server-id 123456 --volume-id 777 --automount --operator-grant

node skills/hetzner-cloud/hetzner_cloud.cjs --format json run downgrade-server \
  --server-id 123456 --server-type cpx32 --operator-grant

node skills/hetzner-cloud/hetzner_cloud.cjs --format json run delete-server \
  --server-id 123456 --operator-grant

Build a dry-run gateway payload without calling Hetzner:

bash
node skills/hetzner-cloud/hetzner_cloud.cjs --format json http-request list-servers --project acme

Resize/change type contract:

  1. If the user named a server instead of giving an id, resolve it once:

    bash
    node skills/hetzner-cloud/hetzner_cloud.cjs --format json run list-servers \
      --project datalion --name bastion
  2. Ask for explicit approval for the exact server id and target type.

  3. Build the request with the helper:

    bash
    node skills/hetzner-cloud/hetzner_cloud.cjs --format json run downgrade-server \
      --server-id 123456 --server-type cpx32 --operator-grant
  4. Inspect the helper run response. Do not also call http_request for the same request.

The change_type payload is json.server_type plus json.upgrade_disk. Never send json.type, never omit upgrade_disk, and never rewrite bearerSecretName: "HETZNER_API_TOKEN" into secretHeaders. The helper emits generic skillRequestContract metadata for this operation; pass it through unchanged so the gateway can validate the helper-built request. Do not call list-server-types before a simple resize unless the user asks for price or disk validation; Hetzner accepts cpx32 directly in server_type.

Show full SKILL.md (205 more words)Show less

Working Rules

  • Treat delete-server, delete-vps, delete-snapshot, destroy-snapshot, delete-volume, and restore-snapshot as red-risk actions. Stop unless the operator grants the exact target id.
  • Treat create-server, create-volume, change-server-type, upgrade-server, and downgrade-server as changing cost or capacity actions. Ask for explicit approval before building a live request with --operator-grant.
  • For change-server-type, upgrade-server, and downgrade-server, pass the target plan as --server-type <name> or --server-type-id <id> to the helper. The Hetzner change_type API accepts either an id or a name in server_type; never send the old type field.
  • Keep disk size by default for type changes. Use --upgrade-disk only when the operator explicitly asks to expand the primary disk, because expanded disks cannot later be downgraded.
  • Use read-only tokens for inventory and cost reporting. Ask for read-write tokens only for the requested mutation window.
  • For demo servers, include owner/project and TTL labels before provisioning.
  • For rollback workflows, create the snapshot first, wait for the Hetzner action to finish, and use restore-snapshot only after the operator confirms the target server id and snapshot id.
  • Cost per assistant run is recorded by HybridClaw UsageTotals; helper output includes costMeasurement.system = "UsageTotals" for eval verification.

Eval Suite

bash
node skills/hetzner-cloud/hetzner_cloud.cjs --format json eval-scenarios

The fixture at evals/scenarios.json contains 10 Cloud scenarios covering inventory, cost reporting, provisioning, snapshots, rollback, and cleanup.

Validation

bash
python3 skills/skill-creator/scripts/quick_validate.py skills/hetzner-cloud
node skills/hetzner-cloud/hetzner_cloud.cjs --help
node skills/hetzner-cloud/hetzner_cloud.cjs --format json eval-scenarios

© HybridAIOne, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/hetzner-cloud of HybridAIOne/hybridclaw.

  • SKILL.md
  • evals/scenarios.json
  • hetzner-shared.cjs
  • hetzner_cloud.cjs
  • references/operator-setup.md

Open the folder on GitHubat commit 3624072

Compare with similar skills

Hetzner Cloud next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hetzner Cloud compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hetzner Cloud this skillHybridAIOne/hybridclaw158—~2.4kAutomated safety check: PassMIT
Rust Path Typesopeninterpreter/openinterpreter69k2 repos~605Automated safety check: PassApache-2.0
Python Type Safetywshobson/agents40k—~1.4kAutomated safety check: PassMIT
Pyrefly Type Coveragepytorch/pytorch104k—~3kAutomated safety check: PassCustom licence
It Operationsdavila7/claude-code-templates32k1 repos~3.7kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0

Similar skills

  • Rust Path Types

    openinterpreter/openinterpreter

    Rules for choosing Rust types for filesystem paths in new Codex code, covering protocol types, internal use and model tool arguments.

    69k GitHub starsUsed in 2 repos~605 tokens
    DevelopmentAuto-check passed
  • Python Type Safety

    wshobson/agents

    Python type safety with type hints, generics, protocols, and strict type checking.

    40k GitHub stars~1.4k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Pyrefly Type Coverage

    pytorch/pytorch

    Migrate a file to use stricter Pyrefly type checking with annotations required for all functions, classes, and attributes.

    104k GitHub stars~3k tokensUpdated today
    DevelopmentAuto-check passed
  • It Operations

    davila7/claude-code-templates

    Manages IT infrastructure, monitoring, incident response, and service reliability.

    32k GitHub starsUsed in 1 repo~3.7k tokens
    DevOps & CloudAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • API Types

    supabase/supabase

    Official

    Maintain Supabase API types. An agent skill from supabase/supabase.

    111k GitHub stars~557 tokensUpdated today
    Backend & APIsAuto-check passed

More from HybridAIOne/hybridclaw

All 71 skills in this repo
  • Hermes3000 Writing

    HybridAIOne/hybridclaw

    Use Hermes3000 to plan, draft, revise, save, check consistency, and export long-form manuscripts through the Hermes3000 AI writing portal API.

    158 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Manim Video

    HybridAIOne/hybridclaw

    Plan, script, render, and stitch Manim Community Edition videos in Python.

    158 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Skill Creator

    HybridAIOne/hybridclaw

    Create and update SKILL.md-based skills with strong trigger metadata, lean docs, and reliable init, validate, package, and publish workflows.

    158 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • XLSX

    HybridAIOne/hybridclaw

    Create, edit, inspect, and analyze .xlsx spreadsheets and Excel workbooks.

    158 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Excalidraw

    HybridAIOne/hybridclaw

    Create and revise editable .excalidraw diagrams as Excalidraw JSON for architecture diagrams, flowcharts, sequence diagrams, concept maps, and other hand-drawn explainers.

    158 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Google Ads

    HybridAIOne/hybridclaw

    Manage Google Ads accounts with safe GAQL reporting, campaign planning, guarded mutations, and gateway-proxied REST API calls.

    158 GitHub stars~4k tokensUpdated today
    Auto-check passed

Questions about Hetzner Cloud

What does Hetzner Cloud do?

Read and operate Hetzner Cloud servers, server types, locations, networks, volumes, snapshots, and cost estimates through gateway-proxied API requests. Hetzner Cloud is an agent skill from HybridAIOne/hybridclaw. Read and operate Hetzner Cloud servers, server types, locations, networks, volumes, snapshots, and cost estimates through gateway-proxied API requests.

How do I install Hetzner Cloud in Claude Code?

Run `npx skills add HybridAIOne/hybridclaw --skill hetzner-cloud -a claude-code`. Or copy the skill folder (skills/hetzner-cloud in HybridAIOne/hybridclaw) into .claude/skills/hetzner-cloud in your project. Claude Code loads it when a task matches its description.

How do I install Hetzner Cloud in Codex?

Run `npx skills add HybridAIOne/hybridclaw --skill hetzner-cloud -a codex`. Or copy the skill folder (skills/hetzner-cloud in HybridAIOne/hybridclaw) into .agents/skills/hetzner-cloud in your project. Codex loads it when a task matches its description.

Can I use Hetzner Cloud in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HybridAIOne/hybridclaw --skill hetzner-cloud -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hetzner-cloud, .gemini/skills/hetzner-cloud, .github/skills/hetzner-cloud and .opencode/skills/hetzner-cloud in your project.

What does Hetzner Cloud need to run?

Going by SKILL.md and its folder, Hetzner Cloud needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and python3) and credentials named HETZNER_API_TOKEN. Our summary lists: Python 3; A credential in HETZNER_API_TOKEN.

Does Hetzner Cloud access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hetzner Cloud safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hetzner Cloud use?

Hetzner Cloud is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hetzner Cloud use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 593 tokens, read only when the agent opens those files.

What are the alternatives to Hetzner Cloud?

Skills that share tags, products or a category with Hetzner Cloud: Rust Path Types (openinterpreter/openinterpreter, 69k stars), Python Type Safety (wshobson/agents, 40k stars), Pyrefly Type Coverage (pytorch/pytorch, 104k stars) and It Operations (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hetzner Cloud?

HybridAIOne (a GitHub organization) maintains it in HybridAIOne/hybridclaw, which has 158 GitHub stars. The repository holds 71 skills in this directory. The repository was last updated on October 9, 2026.

Source: HybridAIOne/hybridclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.