use-railway

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/dal.py

No clear evidence of intentionally malicious behavior (no obfuscation, no backdoor/persistence, no explicit data exfiltration to external hosts) is present in the visible fragment. However, the module provides a powerful remote execution wrapper: run_ssh_query forwards an arbitrary command string into a Railway CLI SSH execution path without apparent validation/allowlisting. Additionally, run_psql_query executes an external script with a constructed query payload and parses untrusted JSON. The snippet also appears incomplete/buggy (undefined identifiers and an incorrect final return), which limits assurance and could cause unexpected behavior. Treat this code as high-impact/needs strict input controls and thorough review of the calling context.

Confidence: 52%Severity: 56%
Audit Metadata
Analyzed At
Aug 1, 2026, 11:05 AM
Package URL
pkg:socket/skills-sh/Sarthib7%2Fagentsmith%2Fuse-railway%2F@2cd376c8f410785df6145accb13064d789b480147ca651c3bc6c0b896e1a1890
Security Audit — socket — use-railway