inngest-middleware

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents the creation of middleware that intercepts and processes event payloads and function results, establishing a potential attack surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent context through middleware hooks like transformInput (accessing ctx.event.data) and transformOutput (accessing result.data) as shown in SKILL.md, references/built-in-middleware.md, and references/dependency-injection.md.
  • Boundary markers: None are present in the provided examples to delimit external content or instruct the model to ignore embedded instructions.
  • Capability inventory: The documented middleware patterns possess capabilities for network operations (fetch calls in reportError), database interactions (via db client), and external logging/tracing (Sentry integration).
  • Sanitization: The examples do not demonstrate explicit sanitization, validation, or filtering of the processed event data before it is logged or sent to external services.
  • [EXTERNAL_DOWNLOADS]: The skill references several external packages and services necessary for the described middleware functionality. These are documented as follows:
  • Recommends installation of official vendor packages: @inngest/middleware-encryption and @inngest/middleware-sentry.
  • Recommends well-known service clients and libraries: @sentry/node, openai, stripe, @prisma/client, and redis.
  • [COMMAND_EXECUTION]: The documentation includes standard shell commands for package management (e.g., npm install) to facilitate the setup of the described middleware components.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:17 AM
Security Audit — agent-trust-hub — inngest-middleware