inngest-local

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill suggests an automated setup method using curl -sL joelclaw.com/scripts/inngest-setup.sh | bash. Executing a remote script directly in the shell is a high-risk pattern that bypasses local review of the script's behavior.
  • [PERSISTENCE]: The instructions guide the user to create a macOS launchd agent at ~/Library/LaunchAgents/com.you.inngest-worker.plist to ensure the background worker starts automatically on system boot and remains running. While documented as a durability feature, this is a system persistence mechanism.
  • [INDIRECT_PROMPT_INJECTION]: The worker implementation pattern in src/functions/process-task.ts creates a surface for indirect injection.
  • Ingestion points: The worker processes events received via a Hono HTTP endpoint (/api/inngest) defined in src/serve.ts.
  • Boundary markers: The code example lacks delimiters or explicit instructions to treat fetched content as untrusted data.
  • Capability inventory: The function uses fetch for network requests and Bun.write / Bun.file().text() for file system operations.
  • Sanitization: There is no evidence of sanitization or validation of the content fetched from external URLs before processing.
  • [COMMAND_EXECUTION]: The skill requires the execution of multiple shell commands, including docker run for container management, kubectl apply for Kubernetes deployments, and openssl for cryptographic key generation.
  • [EXTERNAL_DOWNLOADS]: The skill fetches an external setup script from joelclaw.com and includes code for a worker process that performs network requests to arbitrary URLs provided in event payloads.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — inngest-local