deepstream-generate-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill uses user-provided requirements to construct queries for a BM25 retrieval engine and eventually assembles them into shell commands, creating an attack surface for indirect injection.
- Ingestion points: Ingests untrusted data through the interactive requirement gathering step in
SKILL.mdandreferences/requirement-extraction.md. - Boundary markers: Lacks explicit delimiters or instructions to ignore embedded commands in user queries.
- Capability inventory: Generates
gst-launch-1.0commands and executes validation viasubprocess.runinscripts/validate_pipeline.py. - Sanitization: The validator script implements a regex-based allowlist for element names and uses
shlex.splitfor command tokenization to prevent shell injection. - [DYNAMIC_EXECUTION]: The
scripts/validate_pipeline.pyscript executesgst-launch-1.0andgst-inspect-1.0viasubprocess.runto verify the syntax and structural integrity of generated pipelines. This involves executing logic based on dynamically assembled content derived from the skill's dataset and user input. - [COMMAND_EXECUTION]: The primary output of the skill is a runnable shell command. The skill instructions in
SKILL.md(Step 5) andreferences/output-format.mdexplicitly forbid dangerous shell patterns such as heredocs, variable indirection, and line continuations to minimize risks.
Audit Metadata