inngest-middleware
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents the creation of middleware that intercepts and processes event payloads and function results, establishing a potential attack surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through middleware hooks like
transformInput(accessingctx.event.data) andtransformOutput(accessingresult.data) as shown inSKILL.md,references/built-in-middleware.md, andreferences/dependency-injection.md. - Boundary markers: None are present in the provided examples to delimit external content or instruct the model to ignore embedded instructions.
- Capability inventory: The documented middleware patterns possess capabilities for network operations (
fetchcalls inreportError), database interactions (viadbclient), and external logging/tracing (Sentry integration). - Sanitization: The examples do not demonstrate explicit sanitization, validation, or filtering of the processed event data before it is logged or sent to external services.
- [EXTERNAL_DOWNLOADS]: The skill references several external packages and services necessary for the described middleware functionality. These are documented as follows:
- Recommends installation of official vendor packages:
@inngest/middleware-encryptionand@inngest/middleware-sentry. - Recommends well-known service clients and libraries:
@sentry/node,openai,stripe,@prisma/client, andredis. - [COMMAND_EXECUTION]: The documentation includes standard shell commands for package management (e.g.,
npm install) to facilitate the setup of the described middleware components.
Audit Metadata