deepstream-import-vision-model
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches machine learning models and configuration files from HuggingFace and NVIDIA NGC (NVIDIA GPU Cloud).
- Downloads are restricted to HTTPS/TLS v1.2.
- Model identifiers and organization names are validated against strict alphanumeric regex patterns before being interpolated into URLs.
- The skill utilizes SafeTensors for weights where possible, which is a secure alternative to the vulnerable Pickle format.
- [COMMAND_EXECUTION]: The skill executes various CLI tools including
trtexec,deepstream-app,gst-launch-1.0, andwkhtmltopdf. - These commands are run inside a specific NVIDIA DeepStream Docker container, isolating the host environment.
- The
dsrun.shandds-perf-run.shwrappers facilitate this containerized execution. - Shell scripts use
set -euo pipefailand validate arguments to prevent common script injection vulnerabilities. - [DYNAMIC_EXECUTION]: The skill performs runtime compilation and code generation.
- A C++ bounding box parser is generated and compiled using
makeat runtime to match the specific model architecture. - Python models are exported to ONNX format using
torch.onnx.export, which involves dynamic tracing of the model's graph. - These operations are performed on local/vetted model data and within the isolated container environment.
- [PRIVILEGE_ESCALATION]: The skill's reporting script (
md-to-html-pdf.py) includes logic to attemptapt-get installif required binaries are missing. - This logic is intended for environment setup within the ephemeral DeepStream container.
- The skill installer (
install.sh) includes path resolution checks to ensure any cleanup operations are strictly confined to the target project directory.
Audit Metadata