inngest-local
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's stated purpose and most capabilities are coherent for self-hosting Inngest, using official Docker images and npm packages. However, the optional automation path relies on an unverified third-party pipe-to-shell installer from a personal domain, which creates a high supply-chain risk inconsistent with safer official installation patterns. No confirmed credential theft or malicious exfiltration is visible, but the install trust issue is substantial enough to classify the skill as suspicious rather than benign.
Confidence: 86%Severity: 72%
Audit Metadata