Agent skill

Hetzner Storage Box

by HybridAIOne in HybridAIOne/hybridclaw

Read and operate Hetzner Storage Boxes through Hetzner API management calls and WebDAV file requests with gateway-injected credentials.

MITAuto-check passed

Install Hetzner Storage Box

skills CLI
$ npx skills add HybridAIOne/hybridclaw --skill hetzner-storage-box -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HybridAIOne/hybridclaw hetzner-storage-box --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HybridAIOne/hybridclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hetzner-storage-box .claude/skills/hetzner-storage-box && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hetzner-storage-box
GitHub stars
159
Token cost
~2k tokens
SKILL.md length
488 words
Files
5 (incl. references)
Skills in repo
72
Repo updated
First seen
Licence
MIT

At a glance

Read and operate Hetzner Storage Boxes through Hetzner API management calls and WebDAV file requests with gateway-injected credentials.

  • Works in 9 steps: Use Hetzner API reads… → Use WebDAV reads (list-files,… → Use plan before any management, file… → …
  • SKILL.md covers Default Workflow, Secret Setup, Command Contract and Working Rules, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls node and python3; needs HETZNER_API_TOKEN and HETZNER_DNS_API_TOKEN

What it does

Hetzner Storage Box is an agent skill from HybridAIOne/hybridclaw. Read and operate Hetzner Storage Boxes through Hetzner API management calls and WebDAV file requests with gateway-injected credentials.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `evals/scenarios.json` and `references/operator-setup.md`).

The repository describes itself as: Enterprise-ready self-hosted AI assistant runtime with sandboxed execution, secure credentials, approvals, and memory. The licence is MIT.

Example prompts

  • “/hetzner-storage-box”

Requirements

  • Python 3
  • A credential in HETZNER_API_TOKEN
  • A credential in HETZNER_DNS_API_TOKEN

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Use Hetzner API reads (list-storage-boxes, get-storage-box) for inventory
  2. Use WebDAV reads (list-files, download-file) for file inspection.
  3. Use plan before any management, file write, or public-link request.
  4. Treat hetzner_storage_box.cjs as the API/WebDAV wrapper. Do not handcraft
  5. For prompt/user testing, stop after plan or after helper payload
  6. For real user requests that need live Storage Box API or WebDAV reads, pass
  7. If a live http_request call returns 401 or 403, stop after that first
  8. Require explicit operator grant before creating boxes, changing settings,
  9. Never paste, print, or inspect HETZNER_API_TOKEN or Storage Box passwords.

What it can do on your machine

Read from SKILL.md and the folder at commit 8162701. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • HETZNER_API_TOKEN
    • HETZNER_DNS_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hetzner Storage Box loads about 2k tokens when it runs, and up to ~2.6k if it reads all its reference files. Until then it costs about 39 tokens; SKILL.md has 488 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HybridAIOne/hybridclaw at commit 8162701, republished under its MIT licence (© HybridAIOne). 488 words, ~2,003 tokens.

Download SKILL.mdSave it as .claude/skills/hetzner-storage-box/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hetzner-storage-box
description
Read and operate Hetzner Storage Boxes through Hetzner API management calls and WebDAV file requests with gateway-injected credentials.
user-invocable
true
requires.bins
node

Hetzner Storage Box

Use this skill for Storage Box inventory, lifecycle and snapshot management, plus WebDAV file reads and guarded uploads/archives.

Default Workflow

  1. Use Hetzner API reads (list-storage-boxes, get-storage-box) for inventory and metadata.
  2. Use WebDAV reads (list-files, download-file) for file inspection.
  3. Use plan before any management, file write, or public-link request.
  4. Treat hetzner_storage_box.cjs as the API/WebDAV wrapper. Do not handcraft Hetzner Storage Box API URLs, WebDAV URLs, JSON bodies, tiers, or secret refs from memory.
  5. For prompt/user testing, stop after plan or after helper payload generation. Do not call the built-in http_request tool.
  6. For real user requests that need live Storage Box API or WebDAV reads, pass the helper-emitted httpRequest object unchanged to http_request. The bearerSecretName or secretHeaders field is the secret reference; do not rewrite it, preflight it, inspect it, or ask the model for the secret.
  7. If a live http_request call returns 401 or 403, stop after that first failure. Do not retry, do not fan out to more endpoints or paths, and ask the operator to set or verify the relevant secret.
  8. Require explicit operator grant before creating boxes, changing settings, snapshots, uploads, archives, directory creation, public sharing, or deletes.
  9. Never paste, print, or inspect HETZNER_API_TOKEN or Storage Box passwords. The gateway injects API bearer tokens and WebDAV Basic auth server-side.

Secret Setup

API management calls use HETZNER_API_TOKEN. Set or update it in this order:

  1. Browser admin: open the active HybridClaw admin URL ending in /admin/secrets.
  2. Browser /chat or TUI fallback: /secret set HETZNER_API_TOKEN "<hetzner-console-api-token>".
  3. Local console fallback:
bash
hybridclaw secret set HETZNER_API_TOKEN "<hetzner-console-api-token>"

HETZNER_API_TOKEN is the Hetzner Console token for Cloud and Storage Box management APIs. DNS uses its own HETZNER_DNS_API_TOKEN because Hetzner DNS is served by a separate DNS API and Auth-API-Token header.

WebDAV file operations use a Basic-auth secret containing only the base64 encoded username:password payload. Set it in the same order:

  1. Browser admin: open the active HybridClaw admin URL ending in /admin/secrets.
  2. Browser /chat or TUI fallback: /secret set HETZNER_STORAGE_BOX_BASIC_AUTH "<base64-username-password>".
  3. Local console fallback:
bash
printf '%s' 'u00000:storage-box-password' | base64
hybridclaw secret set HETZNER_STORAGE_BOX_BASIC_AUTH "<base64-username-password>"

See references/operator-setup.md for operator setup, scope, and autonomy defaults.

Show full SKILL.md (139 more words)Show less

Command Contract

bash
node skills/hetzner-storage-box/hetzner_storage_box.cjs --help

Build management API requests:

bash
node skills/hetzner-storage-box/hetzner_storage_box.cjs --format json http-request list-storage-boxes
node skills/hetzner-storage-box/hetzner_storage_box.cjs --format json http-request get-storage-box --box-id 123456
node skills/hetzner-storage-box/hetzner_storage_box.cjs --format json http-request create-snapshot --box-id 123456 --description "pre-archive" --operator-grant

Build WebDAV file requests:

bash
node skills/hetzner-storage-box/hetzner_storage_box.cjs --format json webdav-request list-files \
  --host u00000.your-storagebox.de --path /archives

node skills/hetzner-storage-box/hetzner_storage_box.cjs --format json webdav-request upload-text \
  --host u00000.your-storagebox.de --path /archives/q4-invoices/manifest.txt \
  --body "Archived Q4 invoices" --operator-grant

node skills/hetzner-storage-box/hetzner_storage_box.cjs --format json public-url \
  --host u00000.your-storagebox.de --path /archives/q4-invoices.zip

node skills/hetzner-storage-box/hetzner_storage_box.cjs --format json share-public-link \
  --host u00000.your-storagebox.de --path /archives/q4-invoices.zip \
  --expires-at 2026-06-30 --operator-grant

Working Rules

  • Prefer read-only API tokens and read-only Storage Box subaccounts for file inspection.
  • Treat delete-storage-box, delete-snapshot, and delete-path as red-risk actions requiring exact target confirmation.
  • Use WebDAV over HTTPS for file operations unless the operator explicitly asks for SFTP/rsync outside this helper.
  • public-url only constructs the URL for a path that is already public. share-public-link is the guarded operator handoff for publishing a path and recording its intended expiration. Storage Box file access is credentialed by default, so do not present a path as public until the operator confirms the serving configuration.
  • Cost per assistant run is recorded by HybridClaw UsageTotals; helper output includes costMeasurement.system = "UsageTotals" for eval verification.

Eval Suite

bash
node skills/hetzner-storage-box/hetzner_storage_box.cjs --format json eval-scenarios

The fixture at evals/scenarios.json contains 10 scenarios covering inventory, snapshots, WebDAV list/download/upload/archive, public links, and deletes.

Validation

bash
python3 skills/skill-creator/scripts/quick_validate.py skills/hetzner-storage-box
node skills/hetzner-storage-box/hetzner_storage_box.cjs --help
node skills/hetzner-storage-box/hetzner_storage_box.cjs --format json eval-scenarios

© HybridAIOne, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/hetzner-storage-box of HybridAIOne/hybridclaw.

  • SKILL.md
  • evals/scenarios.json
  • hetzner-shared.cjs
  • hetzner_storage_box.cjs
  • references/operator-setup.md

Open the folder on GitHubat commit 8162701

Compare with similar skills

Hetzner Storage Box next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hetzner Storage Box compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hetzner Storage Box this skillHybridAIOne/hybridclaw159—~2kAutomated safety check: PassMIT
Boxasgeirtj/system_prompts_leaks69k—~1.1kAutomated safety check: PassCC0-1.0
Object Storagesickn33/agentic-awesome-skills47k2 repos~2.6kAutomated safety check: PassMIT
It Operationsdavila7/claude-code-templates33k1 repos~3.7kAutomated safety check: PassMIT
Box Automationdavepoon/buildwithclaude3.6k7 repos~3.1kAutomated safety check: PassMIT
Neon Object Storagesickn33/agentic-awesome-skills47k1 repos~2.9kAutomated safety check: NotesApache-2.0

Similar skills

  • Box

    asgeirtj/system_prompts_leaks

    Search, read, upload, download, move, rename, delete, restore, and share Box content; manage comments and metadata.

    69k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Object Storage

    sickn33/agentic-awesome-skills

    Configure object storage with S3, GCS, and MinIO. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.6k tokens
    Backend & APIsAuto-check passed
  • It Operations

    davila7/claude-code-templates

    Manages IT infrastructure, monitoring, incident response, and service reliability.

    33k GitHub starsUsed in 1 repo~3.7k tokens
    DevOps & CloudAuto-check passed
  • Box Automation

    davepoon/buildwithclaude

    Automate Box cloud storage operations including file upload/download, search, folder management, sharing, collaborations, and metadata queries via Rube MCP (Composio).

    3.6k GitHub starsUsed in 7 repos~3.1k tokens
    Productivity & AutomationAuto-check passed
  • Neon Object Storage

    sickn33/agentic-awesome-skills

    S3-compatible object storage that branches with your Neon project, so files and the database stay in sync across every branch.

    47k GitHub starsUsed in 1 repo~2.9k tokens
    Backend & APIsAuto-check: notes
  • Operator approval contract with internal filing notices for agent-drafted outbound messages, hashed drafts, epoch-keyed decisions, durable delivery claims and receipts, and a pre-draft baseline gate.

    277k GitHub stars~3.3k tokensUpdated today
    Auto-check passed

More from HybridAIOne/hybridclaw

All 72 skills in this repo
  • Hermes3000 Writing

    HybridAIOne/hybridclaw

    Use Hermes3000 to plan, draft, revise, save, check consistency, and export long-form manuscripts through the Hermes3000 AI writing portal API.

    159 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Manim Video

    HybridAIOne/hybridclaw

    Plan, script, render, and stitch Manim Community Edition videos in Python.

    159 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Skill Creator

    HybridAIOne/hybridclaw

    Create and update SKILL.md-based skills with strong trigger metadata, lean docs, and reliable init, validate, package, and publish workflows.

    159 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • XLSX

    HybridAIOne/hybridclaw

    Create, edit, inspect, and analyze .xlsx spreadsheets and Excel workbooks.

    159 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Excalidraw

    HybridAIOne/hybridclaw

    Create and revise editable .excalidraw diagrams as Excalidraw JSON for architecture diagrams, flowcharts, sequence diagrams, concept maps, and other hand-drawn explainers.

    159 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Google Ads

    HybridAIOne/hybridclaw

    Manage Google Ads accounts with safe GAQL reporting, campaign planning, guarded mutations, and gateway-proxied REST API calls.

    159 GitHub stars~4k tokensUpdated today
    Auto-check passed

Questions about Hetzner Storage Box

What does Hetzner Storage Box do?

Read and operate Hetzner Storage Boxes through Hetzner API management calls and WebDAV file requests with gateway-injected credentials. Hetzner Storage Box is an agent skill from HybridAIOne/hybridclaw. Read and operate Hetzner Storage Boxes through Hetzner API management calls and WebDAV file requests with gateway-injected credentials.

How do I install Hetzner Storage Box in Claude Code?

Run `npx skills add HybridAIOne/hybridclaw --skill hetzner-storage-box -a claude-code`. Or copy the skill folder (skills/hetzner-storage-box in HybridAIOne/hybridclaw) into .claude/skills/hetzner-storage-box in your project. Claude Code loads it when a task matches its description.

How do I install Hetzner Storage Box in Codex?

Run `npx skills add HybridAIOne/hybridclaw --skill hetzner-storage-box -a codex`. Or copy the skill folder (skills/hetzner-storage-box in HybridAIOne/hybridclaw) into .agents/skills/hetzner-storage-box in your project. Codex loads it when a task matches its description.

Can I use Hetzner Storage Box in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HybridAIOne/hybridclaw --skill hetzner-storage-box -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hetzner-storage-box, .gemini/skills/hetzner-storage-box, .github/skills/hetzner-storage-box and .opencode/skills/hetzner-storage-box in your project.

What does Hetzner Storage Box need to run?

Going by SKILL.md and its folder, Hetzner Storage Box needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and python3) and credentials named HETZNER_API_TOKEN and HETZNER_DNS_API_TOKEN. Our summary lists: Python 3; A credential in HETZNER_API_TOKEN; A credential in HETZNER_DNS_API_TOKEN.

Does Hetzner Storage Box access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hetzner Storage Box safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hetzner Storage Box use?

Hetzner Storage Box is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hetzner Storage Box use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 603 tokens, read only when the agent opens those files.

What are the alternatives to Hetzner Storage Box?

Skills that share tags, products or a category with Hetzner Storage Box: Box (asgeirtj/system_prompts_leaks, 69k stars), Object Storage (sickn33/agentic-awesome-skills, 47k stars), It Operations (davila7/claude-code-templates, 33k stars) and Box Automation (davepoon/buildwithclaude, 3.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hetzner Storage Box?

HybridAIOne (a GitHub organization) maintains it in HybridAIOne/hybridclaw, which has 159 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 9, 2026.

Source: HybridAIOne/hybridclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.