railway-deploy

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This README-style deployment guide does not contain direct malicious code or obvious obfuscated payloads. The main risks are operational: mishandling high-value Railway tokens and project files (railway.json), creating public repositories which may expose secrets, and configuring payment routing to an unvetted third-party FACILITATOR_URL. These choices can enable credential theft, project takeover, or payment redirection if the developer or the deployed service is negligent or malicious. Treat the package as medium risk in the supply chain: safe if users follow secure practices (private repos, do not commit secrets, vet third parties, rotate tokens) but risky otherwise.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 02:17 PM
Package URL
pkg:socket/skills-sh/daydreamsai%2Fskills-market%2Frailway-deploy%2F@dd2002728ebaa4e359091c42b30b0582744509bb