inngest-cloud
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data which constitutes a vulnerability surface.
- Ingestion points: Event payloads, run outputs, logs, and tool results (SKILL.md).
- Boundary markers: Explicitly instructs the agent to treat this data as data, not instructions.
- Capability inventory: Includes operations like
send_event,rerun,cancel_run, andquery_insights. - Sanitization: Instructions to redact credentials and personal data before reporting results.
- [CREDENTIALS_UNSAFE]: The skill follows security best practices by instructing the agent not to request tokens or API keys in chat and to avoid fetching sensitive signing keys or webhook secrets.
Audit Metadata