railway-ops
Fail
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The file
references/services.mdcontains multiple hardcoded cleartext credentials in a service map, specificallyADMIN_PASSWORDvalues for the 'Alexander AI Support Dashboard' and 'EcDash' services. - [COMMAND_EXECUTION]: The script
scripts/railway_api.pyuses thesubprocess.runfunction to execute shell commands (curl) to interact with the Railway GraphQL API. - [DATA_EXFILTRATION]: The skill identifies and accesses a sensitive authentication token at a specific system path (
/root/.secrets/railway_token) in bothSKILL.mdandscripts/railway_api.pyto authenticate API requests. - [PROMPT_INJECTION]: The skill implements a workflow to fetch deployment logs via the
deploymentLogsquery. This ingested data from an external source lacks boundary markers or sanitization, creating an indirect prompt injection surface where malicious log content could influence agent behavior. - Ingestion points:
deploymentLogsGraphQL query inSKILL.md - Boundary markers: Absent
- Capability inventory: Shell command execution via
subprocess.runinscripts/railway_api.py; environment variable modification viavariableCollectionUpsertmutation - Sanitization: Absent; log messages are processed as raw text
Recommendations
- AI detected serious security threats
Audit Metadata