inngest-local
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill suggests an automated setup method using
curl -sL joelclaw.com/scripts/inngest-setup.sh | bash. Executing a remote script directly in the shell is a high-risk pattern that bypasses local review of the script's behavior. - [PERSISTENCE]: The instructions guide the user to create a macOS launchd agent at
~/Library/LaunchAgents/com.you.inngest-worker.plistto ensure the background worker starts automatically on system boot and remains running. While documented as a durability feature, this is a system persistence mechanism. - [INDIRECT_PROMPT_INJECTION]: The worker implementation pattern in
src/functions/process-task.tscreates a surface for indirect injection. - Ingestion points: The worker processes events received via a Hono HTTP endpoint (
/api/inngest) defined insrc/serve.ts. - Boundary markers: The code example lacks delimiters or explicit instructions to treat fetched content as untrusted data.
- Capability inventory: The function uses
fetchfor network requests andBun.write/Bun.file().text()for file system operations. - Sanitization: There is no evidence of sanitization or validation of the content fetched from external URLs before processing.
- [COMMAND_EXECUTION]: The skill requires the execution of multiple shell commands, including
docker runfor container management,kubectl applyfor Kubernetes deployments, andopensslfor cryptographic key generation. - [EXTERNAL_DOWNLOADS]: The skill fetches an external setup script from
joelclaw.comand includes code for a worker process that performs network requests to arbitrary URLs provided in event payloads.
Audit Metadata