environment
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes structured and unstructured data from the Railway CLI which could contain attacker-controlled content.
- Ingestion points: Data is ingested via
railway status --json,railway environment config --json, andrailway variables --jsonas described inSKILL.md. - Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded within the environment variables or configuration values.
- Capability inventory: The agent has the capability to execute shell commands via the Railway CLI and modify environment configurations (including build/start commands and secrets) using
railway environment editinSKILL.md. - Sanitization: There is no mention of sanitizing or escaping the output of the configuration commands before processing or displaying them to the user.
Audit Metadata