environment

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured and unstructured data from the Railway CLI which could contain attacker-controlled content.
  • Ingestion points: Data is ingested via railway status --json, railway environment config --json, and railway variables --json as described in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded within the environment variables or configuration values.
  • Capability inventory: The agent has the capability to execute shell commands via the Railway CLI and modify environment configurations (including build/start commands and secrets) using railway environment edit in SKILL.md.
  • Sanitization: There is no mention of sanitizing or escaping the output of the configuration commands before processing or displaying them to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 10:56 PM