inngest-middleware

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for handling event-driven data that create an indirect prompt injection surface. Specifically, the dependency injection example shows event data being passed to an LLM provider and subsequently used in database operations.
  • Ingestion points: Untrusted event data is ingested through the event object in the function context and ctx.event in middleware lifecycle hooks within SKILL.md.
  • Boundary markers: The provided code examples do not implement delimiters or explicit instructions to ignore potentially malicious embedded content within the event payloads.
  • Capability inventory: The skill demonstrates capabilities including network requests (via OpenAI client) and database writes (via Prisma client) in SKILL.md.
  • Sanitization: There is no evidence of data sanitization, schema validation, or escaping of the event.data.content before it is interpolated into the prompt or stored in the database.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — inngest-middleware