manage-railcode-org

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the official Railcode CLI package from the public npm registry and administrative skills from the vendor's GitHub organization.
  • [COMMAND_EXECUTION]: Executes administrative commands using the railcode CLI to manage organization resources, access policies, and data connections.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill ingests untrusted data from the organization's application logs, key-value stores, and file storage via CLI read commands described in references/cli-management.md.
  • Boundary markers: The skill body and reference files do not contain explicit instructions or delimiters to treat data from the CLI as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill grants the agent administrative control over the organization, including role mutation, credential rotation, and live data modification.
  • Sanitization: There is no documented evidence of input validation or sanitization for data returned from CLI operations before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 10:00 AM
Security Audit — agent-trust-hub — manage-railcode-org