inngest-local

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose and most capabilities are coherent for self-hosting Inngest, using official Docker images and npm packages. However, the optional automation path relies on an unverified third-party pipe-to-shell installer from a personal domain, which creates a high supply-chain risk inconsistent with safer official installation patterns. No confirmed credential theft or malicious exfiltration is visible, but the install trust issue is substantial enough to classify the skill as suspicious rather than benign.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Sep 23, 2026, 05:05 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Finngest-local%2F@28eb42da50c368150224668a57efff397aa6d4f9a6430baa8b1dcfc26cd35506
Security Audit — socket — inngest-local