skills/mnlt/teleport/railway/Gen Agent Trust Hub

railway

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl to interact with the Railway GraphQL API and jq to parse the JSON responses. These are standard operations for the skill's intended purpose of managing cloud infrastructure.
  • [CREDENTIALS_UNSAFE]: The skill properly handles the $RAILWAY_TOKEN environment variable. It includes an explicit warning to never echo the variable directly and provides a remediation path using a setup tool (teleport-setup add-key railway) rather than suggesting manual edits to configuration files.
  • [EXTERNAL_DOWNLOADS]: References the backboard.railway.com GraphQL endpoint, which is the official domain for Railway's API services. This is a well-known service and does not escalate the security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 10:46 PM
Security Audit — agent-trust-hub — railway