railway
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill facilitates the installation of the Railway CLI by fetching a shell script from the official railway.com domain and executing it via bash.
- [EXTERNAL_DOWNLOADS]: The skill references external resources for tooling installation, specifically the @railway/cli package via NPM and an installer script from the Railway website.
- [COMMAND_EXECUTION]: The skill core functionality relies on executing Railway CLI commands to manage cloud infrastructure, including service provisioning, deployment logs, and environment variable configuration.
- [DYNAMIC_EXECUTION]: The included scripts/verify.sh utility performs structural validation of configuration files by generating and executing a Python script at runtime.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface. Ingestion points: The agent reads and processes user-controlled files including railway.json, railway.toml, and application source code. Boundary markers: The skill provides instructions for the agent to follow 'Verification' and 'Anti-patterns' checklists, though it lacks explicit delimiters for external content. Capability inventory: The skill uses subprocess calls to run CLI commands (railway up, railway run) and performs network operations for deployment. Sanitization: The scripts/verify.sh tool provides basic structural validation for JSON/TOML files but does not sanitize natural language content within those files.
Audit Metadata