railway-ops
Audited by Snyk on Jun 19, 2026
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required runtime workflow (“Debug a Failed Deploy” / “Update an Env Var”) calls the Railway GraphQL API and ingests the returned
deploymentLogs { message ... }(free-text log lines) into the agent context; those logs are produced by the deployed app/runtime and are not authored by the operating user, so they count as outsider-authored free text.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill makes runtime GraphQL calls to https://backboard.railway.app/graphql/v2 (via curl/urllib) to perform mutations like deploymentRedeploy and variableCollectionUpsert, which execute remote actions and are required for the skill to function.
HIGH W008: Secret detected in skill content (API keys, tokens, passwords).
- Secret detected (high risk: 1.00). I scanned the skill content for high-entropy, literal credentials. I ignored identifiers and placeholders such as UUIDs (project/service/env IDs), the token path (/root/.secrets/railway_token), environment variable names (e.g., JWT_SECRET, BRAIN_SYNC_TOKEN) and repo/URL strings because these are not usable secrets.
I flagged two explicit environment variable assignments that contain actual password values:
- ADMIN_PASSWORD=Treetop121570!
- ADMIN_PASSWORD=Mhall001!
These are literal password values (not placeholders) stored as env var values in the documentation. They appear to be real credentials for admin access to services and therefore meet the definition of a secret to be treated as sensitive.
No API keys, bearer tokens, private key blocks, or other high-entropy tokens are present elsewhere in the document.
Issues (3)
Third-party content exposure detected (indirect prompt injection risk).
Unverifiable external dependency detected (runtime URL that controls agent).
Secret detected in skill content (API keys, tokens, passwords).