deploying-to-railway

Warn

Audited by Socket on Feb 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Download or install from free hosting/deployment platform detected The code fragment is a coherent, benign deployment guide with best-practice notes for securely provisioning and linking Railway services using pgvector. While not malicious, it highlights risk areas around secret management, template trust, and cross-service variable exposure that should be mitigated through affirmed templates, log sanitization, and secrets governance. LLM verification: This SKILL.md file is a legitimate deployment guide for Railway and does not contain active malicious code or obvious supply-chain backdoors. The main security concerns are operational: unpinned pip dependencies, global package installation trust, and the normal risk of exposing secrets if Railway variables are misused. No evidence of obfuscation or explicit credential-harvesting behavior is present.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 13, 2026, 09:48 PM
Package URL
pkg:socket/skills-sh/cpfiffer%2Fcentral%2Fdeploying-to-railway%2F@ce49b6811ae3d4bbba10e9915854409b7cee598d