deepstream-import-vision-model

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/dsrun.sh

This fragment is a straightforward Docker-based command runner with no direct evidence of embedded malware, secrets, obfuscation, or exfiltration. The main supply-chain/security risk is the intentional passthrough of caller-controlled command text into bash -lc and the ability to override the executed container image via DS_IMAGE. When used in CI or automation with any untrusted inputs, it can enable arbitrary in-container code execution and manipulation of the bind-mounted host working directory.

Confidence: 70%Severity: 52%
Audit Metadata
Analyzed At
Sep 8, 2026, 08:46 AM
Package URL
pkg:socket/skills-sh/nvidia%2Fdeepstream%2Fdeepstream-import-vision-model%2F@971e7bb7ebe4e7420e2cc620630025d6740c3e78e0d0d96708424454d5c7fbf9
Security Audit — socket — deepstream-import-vision-model