Agent skill

Hetzner DNS

by HybridAIOne in HybridAIOne/hybridclaw

Read and manage Hetzner DNS zones and records through gateway-proxied DNS API requests with guarded A, AAAA, CNAME, and TXT changes.

MITAuto-check passed

Install Hetzner DNS

skills CLI
$ npx skills add HybridAIOne/hybridclaw --skill hetzner-dns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HybridAIOne/hybridclaw hetzner-dns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hetzner-dns .claude/skills/hetzner-dns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hetzner-dns
GitHub stars
159
Token cost
~1.4k tokens
SKILL.md length
370 words
Files
5 (incl. references)
Skills in repo
72
Repo updated
First seen
Licence
MIT

At a glance

Read and manage Hetzner DNS zones and records through gateway-proxied DNS API requests with guarded A, AAAA, CNAME, and TXT changes.

  • Works in 9 steps: Read first: list zones, then list… → The DNS API is record-id based. Use… → Use plan before mutations so the… → …
  • SKILL.md covers Default Workflow, Command Contract, Working Rules and Eval Suite, plus 1 more section
  • Runs JavaScript scripts from its folder; calls node and python3; needs HETZNER_DNS_API_TOKEN

What it does

Hetzner DNS is an agent skill from HybridAIOne/hybridclaw. Read and manage Hetzner DNS zones and records through gateway-proxied DNS API requests with guarded A, AAAA, CNAME, and TXT changes.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `evals/scenarios.json` and `references/operator-setup.md`).

The repository describes itself as: Enterprise-ready self-hosted AI assistant runtime with sandboxed execution, secure credentials, approvals, and memory. The licence is MIT.

Example prompts

  • “/hetzner-dns”

Requirements

  • Python 3
  • A credential in HETZNER_DNS_API_TOKEN

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Read first: list zones, then list records for the target zone id.
  2. The DNS API is record-id based. Use list-rrsets to discover existing record
  3. Use plan before mutations so the operator can see the tier and required
  4. Treat hetzner_dns.cjs as the API wrapper. Do not handcraft Hetzner DNS API
  5. For prompt/user testing, stop after plan or after helper http-request
  6. For real user requests that need live Hetzner DNS reads, pass the
  7. If a live http_request call returns 401 or 403, stop after that first
  8. Require explicit operator grant before creating, updating, adding, removing,
  9. Never paste, print, or inspect HETZNER_DNS_API_TOKEN; the gateway injects

What it can do on your machine

Read from SKILL.md and the folder at commit 8162701. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • HETZNER_DNS_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hetzner DNS loads about 1.4k tokens when it runs, and up to ~1.9k if it reads all its reference files. Until then it costs about 36 tokens; SKILL.md has 370 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HybridAIOne/hybridclaw at commit 8162701, republished under its MIT licence (© HybridAIOne). 370 words, ~1,364 tokens.

Download SKILL.mdSave it as .claude/skills/hetzner-dns/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hetzner-dns
description
Read and manage Hetzner DNS zones and records through gateway-proxied DNS API requests with guarded A, AAAA, CNAME, and TXT changes.
user-invocable
true
requires.bins
node

Hetzner DNS

Use this skill for Hetzner DNS zone discovery and A, AAAA, CNAME, TXT, and other record management through the Hetzner DNS API.

Default Workflow

  1. Read first: list zones, then list records for the target zone id.
  2. The DNS API is record-id based. Use list-rrsets to discover existing record ids before update or delete requests.
  3. Use plan before mutations so the operator can see the tier and required grant.
  4. Treat hetzner_dns.cjs as the API wrapper. Do not handcraft Hetzner DNS API URLs, JSON bodies, tiers, or secret refs from memory.
  5. For prompt/user testing, stop after plan or after helper http-request payload generation. Do not call the built-in http_request tool.
  6. For real user requests that need live Hetzner DNS reads, pass the helper-emitted httpRequest object unchanged to http_request. The secretHeaders entry for Auth-API-Token is the secret reference; do not preflight it, inspect it, or ask the model for the token.
  7. If a live http_request call returns 401 or 403, stop after that first failure. Do not retry, do not fan out to more endpoints, and ask the operator to set or verify HETZNER_DNS_API_TOKEN.
  8. Require explicit operator grant before creating, updating, adding, removing, or deleting records. Pass --operator-grant only after that grant.
  9. Never paste, print, or inspect HETZNER_DNS_API_TOKEN; the gateway injects it server-side as Auth-API-Token.

See references/operator-setup.md for DNS token setup, scope, autonomy defaults, and record-id handling.

Show full SKILL.md (135 more words)Show less

Command Contract

bash
node skills/hetzner-dns/hetzner_dns.cjs --help

Plan a DNS request without contacting Hetzner:

bash
node skills/hetzner-dns/hetzner_dns.cjs --format json plan "Point demo-acme.example.com at the demo VPS"

Build read requests:

bash
node skills/hetzner-dns/hetzner_dns.cjs --format json http-request list-zones
node skills/hetzner-dns/hetzner_dns.cjs --format json http-request list-rrsets --zone-id zone123 --name demo --type A
node skills/hetzner-dns/hetzner_dns.cjs --format json http-request get-rrset --record-id record123

Build guarded write requests:

bash
node skills/hetzner-dns/hetzner_dns.cjs --format json http-request create-rrset \
  --zone-id zone123 --name demo --type A --ttl 300 --record 203.0.113.10 \
  --operator-grant

node skills/hetzner-dns/hetzner_dns.cjs --format json http-request update-rrset \
  --record-id record123 --zone-id zone123 --name demo --type A --ttl 300 --record 203.0.113.11 \
  --operator-grant

node skills/hetzner-dns/hetzner_dns.cjs --format json http-request delete-record \
  --record-id record123 --operator-grant

Working Rules

  • create-rrset and add-record emit one DNS API record create request. For multiple values, build one request per value.
  • Use update-rrset only with an exact --record-id from a prior read.
  • Use remove-record, delete-record, or delete-rrset only with an exact --record-id.
  • Do not modify generated SOA records or default NS records.
  • Use @ for apex records when the API requires a record name.
  • Stop before red actions (delete-record, delete-rrset, delete-zone) unless the operator grants the exact record id or zone id target.
  • Cost per assistant run is recorded by HybridClaw UsageTotals; helper output includes costMeasurement.system = "UsageTotals" for eval verification.

Eval Suite

bash
node skills/hetzner-dns/hetzner_dns.cjs --format json eval-scenarios

The fixture at evals/scenarios.json contains 10 DNS scenarios covering zone reads, record reads, A/AAAA/CNAME/TXT changes, and guarded deletes.

Validation

bash
python3 skills/skill-creator/scripts/quick_validate.py skills/hetzner-dns
node skills/hetzner-dns/hetzner_dns.cjs --help
node skills/hetzner-dns/hetzner_dns.cjs --format json eval-scenarios

© HybridAIOne, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/hetzner-dns of HybridAIOne/hybridclaw.

  • SKILL.md
  • evals/scenarios.json
  • hetzner-shared.cjs
  • hetzner_dns.cjs
  • references/operator-setup.md

Open the folder on GitHubat commit 8162701

Compare with similar skills

Hetzner DNS next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hetzner DNS compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hetzner DNS this skillHybridAIOne/hybridclaw159—~1.4kAutomated safety check: PassMIT
Performing DNS Enumeration And Zone Transfermukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Detecting DNS Exfiltration With DNS Query Analysismukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0
Homelab Pihole DNSaffaan-m/ECC276k1 repos~2.4kAutomated safety check: WarnMIT
DNS Managementsickn33/agentic-awesome-skills47k2 repos~2.7kAutomated safety check: PassMIT
Recordingcodewhale-hq/Codewhale41k—~540Automated safety check: PassMIT

Similar skills

  • Performing DNS Enumeration And Zone Transfer

    mukul975/Anthropic-Cybersecurity-Skills

    Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting DNS Exfiltration With DNS Query Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detect data exfiltration via DNS tunneling (tools like iodine, dnscat2, dns2tcp) by analyzing query entropy, subdomain length, query volume to single domains, TXT/CNAME/NULL record abuse, and…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Homelab Pihole DNS

    affaan-m/ECC

    Pi-hole installation, blocklist management, DNS-over-HTTPS setup, DHCP integration, local DNS records, and troubleshooting broken DNS resolution on a home network.

    276k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check: warnings
  • DNS Management

    sickn33/agentic-awesome-skills

    Configure DNS zones and records. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.7k tokens
    DevOps & CloudAuto-check passed
  • Recording

    codewhale-hq/Codewhale

    Capture screenshots on registered computers, record on macOS or HarmonyOS, and manage saved captures.

    41k GitHub stars~540 tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Hunting For DNS Based Persistence

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts for DNS-based persistence mechanisms such as DNS hijacking, dangling CNAME records enabling subdomain takeover, wildcard DNS abuse, and unauthorized zone or NS delegation changes, using…

    34k GitHub stars~790 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from HybridAIOne/hybridclaw

All 72 skills in this repo
  • Hermes3000 Writing

    HybridAIOne/hybridclaw

    Use Hermes3000 to plan, draft, revise, save, check consistency, and export long-form manuscripts through the Hermes3000 AI writing portal API.

    159 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Manim Video

    HybridAIOne/hybridclaw

    Plan, script, render, and stitch Manim Community Edition videos in Python.

    159 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Skill Creator

    HybridAIOne/hybridclaw

    Create and update SKILL.md-based skills with strong trigger metadata, lean docs, and reliable init, validate, package, and publish workflows.

    159 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • XLSX

    HybridAIOne/hybridclaw

    Create, edit, inspect, and analyze .xlsx spreadsheets and Excel workbooks.

    159 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Excalidraw

    HybridAIOne/hybridclaw

    Create and revise editable .excalidraw diagrams as Excalidraw JSON for architecture diagrams, flowcharts, sequence diagrams, concept maps, and other hand-drawn explainers.

    159 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Google Ads

    HybridAIOne/hybridclaw

    Manage Google Ads accounts with safe GAQL reporting, campaign planning, guarded mutations, and gateway-proxied REST API calls.

    159 GitHub stars~4k tokensUpdated today
    Auto-check passed

Questions about Hetzner DNS

What does Hetzner DNS do?

Read and manage Hetzner DNS zones and records through gateway-proxied DNS API requests with guarded A, AAAA, CNAME, and TXT changes. Hetzner DNS is an agent skill from HybridAIOne/hybridclaw. Read and manage Hetzner DNS zones and records through gateway-proxied DNS API requests with guarded A, AAAA, CNAME, and TXT changes.

How do I install Hetzner DNS in Claude Code?

Run `npx skills add HybridAIOne/hybridclaw --skill hetzner-dns -a claude-code`. Or copy the skill folder (skills/hetzner-dns in HybridAIOne/hybridclaw) into .claude/skills/hetzner-dns in your project. Claude Code loads it when a task matches its description.

How do I install Hetzner DNS in Codex?

Run `npx skills add HybridAIOne/hybridclaw --skill hetzner-dns -a codex`. Or copy the skill folder (skills/hetzner-dns in HybridAIOne/hybridclaw) into .agents/skills/hetzner-dns in your project. Codex loads it when a task matches its description.

Can I use Hetzner DNS in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HybridAIOne/hybridclaw --skill hetzner-dns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hetzner-dns, .gemini/skills/hetzner-dns, .github/skills/hetzner-dns and .opencode/skills/hetzner-dns in your project.

What does Hetzner DNS need to run?

Going by SKILL.md and its folder, Hetzner DNS needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and python3) and credentials named HETZNER_DNS_API_TOKEN. Our summary lists: Python 3; A credential in HETZNER_DNS_API_TOKEN.

Does Hetzner DNS access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hetzner DNS safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hetzner DNS use?

Hetzner DNS is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hetzner DNS use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 527 tokens, read only when the agent opens those files.

What are the alternatives to Hetzner DNS?

Skills that share tags, products or a category with Hetzner DNS: Performing DNS Enumeration And Zone Transfer (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting DNS Exfiltration With DNS Query Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Homelab Pihole DNS (affaan-m/ECC, 276k stars) and DNS Management (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hetzner DNS?

HybridAIOne (a GitHub organization) maintains it in HybridAIOne/hybridclaw, which has 159 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 9, 2026.

Source: HybridAIOne/hybridclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.