deepstream-generate-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill uses user-provided requirements to construct queries for a BM25 retrieval engine and eventually assembles them into shell commands, creating an attack surface for indirect injection.
  • Ingestion points: Ingests untrusted data through the interactive requirement gathering step in SKILL.md and references/requirement-extraction.md.
  • Boundary markers: Lacks explicit delimiters or instructions to ignore embedded commands in user queries.
  • Capability inventory: Generates gst-launch-1.0 commands and executes validation via subprocess.run in scripts/validate_pipeline.py.
  • Sanitization: The validator script implements a regex-based allowlist for element names and uses shlex.split for command tokenization to prevent shell injection.
  • [DYNAMIC_EXECUTION]: The scripts/validate_pipeline.py script executes gst-launch-1.0 and gst-inspect-1.0 via subprocess.run to verify the syntax and structural integrity of generated pipelines. This involves executing logic based on dynamically assembled content derived from the skill's dataset and user input.
  • [COMMAND_EXECUTION]: The primary output of the skill is a runnable shell command. The skill instructions in SKILL.md (Step 5) and references/output-format.md explicitly forbid dangerous shell patterns such as heredocs, variable indirection, and line continuations to minimize risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 08:39 AM
Security Audit — agent-trust-hub — deepstream-generate-pipeline