prod-debug

Fail

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill executes a command to read a sensitive credential file located at /root/.secrets/railway_token. Accessing such paths is a high-risk activity as it exposes platform authentication tokens.
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell commands including cat, curl, and git to perform diagnostic and deployment tasks. This includes reading sensitive files and pushing code to remote repositories.
  • [DATA_EXFILTRATION]: Authenticated network requests are made to the official Railway API domain using the extracted RAILWAY_TOKEN. While the destination is a known service, the sequence of reading a local secret from a restricted path and transmitting it over the network is a data exfiltration pattern.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by fetching and processing external web content from health endpoints and login pages via curl and piping the output to diagnostic tools like grep. This content is untrusted and there are no boundary markers or sanitization steps used to isolate it from the agent context. Ingestion points: $URL/health and $URL/login. Boundary markers: Absent. Capability inventory: cat, curl, git. Sanitization: Absent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 18, 2026, 11:58 PM
Security Audit — agent-trust-hub — prod-debug