use-railway

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONOBFUSCATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the Railway CLI using curl | sh and bash process substitution from railway.com and agents.railway.com. These are official domains owned by the skill's author and are used for legitimate tool installation.
  • [COMMAND_EXECUTION]: Multiple Python and Bash scripts (dal.py, analyze-postgres.py, enable-pg-stats.py, etc.) execute Railway CLI commands and database client binaries (psql, mysql, redis-cli, mongosh) via subprocess. These are used to automate infrastructure management and database introspection. The scripts demonstrate good security awareness by reading from /dev/tty for user confirmation and passing sensitive headers via secure configurations.
  • [INDIRECT_PROMPT_INJECTION]: The database analysis functionality ingests database logs and SQL query text from the running environment for diagnostic purposes. Because this content originates from external application logs, it represents a surface for indirect prompt injection, where malicious instructions could be embedded in logs to attempt to influence the agent's analysis.
  • [OBFUSCATION]: Several Python scripts use Base64 encoding to wrap SQL query payloads before passing them to CLI tools. This is implemented as a functional measure to ensure query integrity and prevent shell command injection or parsing errors, rather than as a technique to hide malicious logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 03:59 PM
Security Audit — agent-trust-hub — use-railway