inngest-api

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the Inngest OpenAPI specification and documentation from the vendor's official domain (api-docs.inngest.com).\n- [COMMAND_EXECUTION]: Uses curl to interact with API endpoints and suggests the use of the inngest-cli via npx for account and environment management.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation and API responses which could potentially contain adversarial instructions.\n
  • Ingestion points: OpenAPI specs and Markdown documentation from api-docs.inngest.com, and JSON responses from api.inngest.com.\n
  • Boundary markers: The instructions provide context for summary and output handling but do not define strict boundary markers for untrusted content.\n
  • Capability inventory: The skill is capable of performing network requests, executing CLI tools, and performing resource mutations such as creating webhooks and syncing apps.\n
  • Sanitization: The skill mandates strict redaction of API keys, signing keys, and secrets from all outputs and logs.\n- [DYNAMIC_EXECUTION]: Documents the Insights API and webhook endpoints which allow for server-side execution of dynamic content like SQL queries and JavaScript transforms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:50 PM
Security Audit — agent-trust-hub — inngest-api