deepstream-import-vision-model

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches machine learning models and configuration files from HuggingFace and NVIDIA NGC (NVIDIA GPU Cloud).
  • Downloads are restricted to HTTPS/TLS v1.2.
  • Model identifiers and organization names are validated against strict alphanumeric regex patterns before being interpolated into URLs.
  • The skill utilizes SafeTensors for weights where possible, which is a secure alternative to the vulnerable Pickle format.
  • [COMMAND_EXECUTION]: The skill executes various CLI tools including trtexec, deepstream-app, gst-launch-1.0, and wkhtmltopdf.
  • These commands are run inside a specific NVIDIA DeepStream Docker container, isolating the host environment.
  • The dsrun.sh and ds-perf-run.sh wrappers facilitate this containerized execution.
  • Shell scripts use set -euo pipefail and validate arguments to prevent common script injection vulnerabilities.
  • [DYNAMIC_EXECUTION]: The skill performs runtime compilation and code generation.
  • A C++ bounding box parser is generated and compiled using make at runtime to match the specific model architecture.
  • Python models are exported to ONNX format using torch.onnx.export, which involves dynamic tracing of the model's graph.
  • These operations are performed on local/vetted model data and within the isolated container environment.
  • [PRIVILEGE_ESCALATION]: The skill's reporting script (md-to-html-pdf.py) includes logic to attempt apt-get install if required binaries are missing.
  • This logic is intended for environment setup within the ephemeral DeepStream container.
  • The skill installer (install.sh) includes path resolution checks to ensure any cleanup operations are strictly confined to the target project directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 08:38 AM
Security Audit — agent-trust-hub — deepstream-import-vision-model