prod-debug
Fail
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill executes a command to read a sensitive credential file located at
/root/.secrets/railway_token. Accessing such paths is a high-risk activity as it exposes platform authentication tokens. - [COMMAND_EXECUTION]: The skill makes extensive use of shell commands including
cat,curl, andgitto perform diagnostic and deployment tasks. This includes reading sensitive files and pushing code to remote repositories. - [DATA_EXFILTRATION]: Authenticated network requests are made to the official Railway API domain using the extracted
RAILWAY_TOKEN. While the destination is a known service, the sequence of reading a local secret from a restricted path and transmitting it over the network is a data exfiltration pattern. - [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by fetching and processing external web content from health endpoints and login pages via
curland piping the output to diagnostic tools likegrep. This content is untrusted and there are no boundary markers or sanitization steps used to isolate it from the agent context. Ingestion points:$URL/healthand$URL/login. Boundary markers: Absent. Capability inventory:cat,curl,git. Sanitization: Absent.
Recommendations
- AI detected serious security threats
Audit Metadata