use-railway

Warn

Audited by Socket on Sep 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/dal.py

No clear evidence of intentionally malicious behavior (no obfuscation, no backdoor/persistence, no explicit data exfiltration to external hosts) is present in the visible fragment. However, the module provides a powerful remote execution wrapper: run_ssh_query forwards an arbitrary command string into a Railway CLI SSH execution path without apparent validation/allowlisting. Additionally, run_psql_query executes an external script with a constructed query payload and parses untrusted JSON. The snippet also appears incomplete/buggy (undefined identifiers and an incorrect final return), which limits assurance and could cause unexpected behavior. Treat this code as high-impact/needs strict input controls and thorough review of the calling context.

Confidence: 52%Severity: 56%
Audit Metadata
Analyzed At
Sep 29, 2026, 04:00 PM
Package URL
pkg:socket/skills-sh/railwayapp%2Frailway-skills%2Fuse-railway%2F@a61a999c293d4f0afe10fbe35ddd0123d4bf8a51c784ae8e5f91071af348a993
Security Audit — socket — use-railway