inngest-middleware
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for handling event-driven data that create an indirect prompt injection surface. Specifically, the dependency injection example shows event data being passed to an LLM provider and subsequently used in database operations.
- Ingestion points: Untrusted event data is ingested through the
eventobject in the function context andctx.eventin middleware lifecycle hooks withinSKILL.md. - Boundary markers: The provided code examples do not implement delimiters or explicit instructions to ignore potentially malicious embedded content within the event payloads.
- Capability inventory: The skill demonstrates capabilities including network requests (via OpenAI client) and database writes (via Prisma client) in
SKILL.md. - Sanitization: There is no evidence of data sanitization, schema validation, or escaping of the
event.data.contentbefore it is interpolated into the prompt or stored in the database.
Audit Metadata