Official Railway MCP server
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport stdio counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
No tools enumerated yet for this server.
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed v0.1.11 · analyzer v33 · 4w ago
danger signals1
- dynamic code execution new Function() package/dist/vi.bdSIJ99Y-CjNqA1ej.js :11749
new Function("exports", snapshotContents)(data);
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 124
filesystem 2
- fs package/dist/auth-fMu9JRb4.js :1
import { readFileSync } from "node:fs"; - fs package/dist/utils-Cvxm88Gr.js :1
import { readFileSync } from "fs";
shell / exec 2
- shell package/dist/core-6w3_SQE-.js :2
import { execFile } from "node:child_process"; - shell package/dist/vi.bdSIJ99Y-CjNqA1ej.js :14671
if (config$1?.toFake?.includes("nextTick") || workerState.config?.fakeTimers?.toFake?.includes("nextTick")) throw new Error("vi.useFakeTimers({ toFake: [\"nextTick\"] }) is not supported in node:child
declared dependencies 13
- @modelcontextprotocol/sdk@^1.17.1
- fuse.js@^7.1.0
- graphql-request@^7.2.0
- semver@^7.7.2
- zod@^3.25.76
- @biomejs/biome@^2.1.3
- @rolldown/binding-darwin-arm64@1.0.0-beta.40
- @smithery/cli@^1.2.17
- @types/node@^24.1.0
- @types/semver@^7.7.1
- tsdown@^0.15.4
- typescript@^5.9.2
show 1 more
- vitest@^3.2.4