railway-ops

Fail

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The file references/services.md contains multiple hardcoded cleartext credentials in a service map, specifically ADMIN_PASSWORD values for the 'Alexander AI Support Dashboard' and 'EcDash' services.
  • [COMMAND_EXECUTION]: The script scripts/railway_api.py uses the subprocess.run function to execute shell commands (curl) to interact with the Railway GraphQL API.
  • [DATA_EXFILTRATION]: The skill identifies and accesses a sensitive authentication token at a specific system path (/root/.secrets/railway_token) in both SKILL.md and scripts/railway_api.py to authenticate API requests.
  • [PROMPT_INJECTION]: The skill implements a workflow to fetch deployment logs via the deploymentLogs query. This ingested data from an external source lacks boundary markers or sanitization, creating an indirect prompt injection surface where malicious log content could influence agent behavior.
  • Ingestion points: deploymentLogs GraphQL query in SKILL.md
  • Boundary markers: Absent
  • Capability inventory: Shell command execution via subprocess.run in scripts/railway_api.py; environment variable modification via variableCollectionUpsert mutation
  • Sanitization: Absent; log messages are processed as raw text
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 19, 2026, 05:56 PM
Security Audit — agent-trust-hub — railway-ops