deepstream-sop

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The Docker build process downloads the Basler Pylon SDK from an Azure Blob Storage domain and clones specialized research repositories for event boundary detection (DDM-Net) and GStreamer plugins from GitHub. These are essential, well-known dependencies for the microservice's domain.
  • [COMMAND_EXECUTION]: The service uses Python's subprocess module to execute nvidia-smi for gathering GPU utilization metrics. It also spawns a subprocess to run an internal export script that converts PyTorch models to TensorRT engines. These are routine tasks for high-performance NVIDIA applications.
  • [DYNAMIC_EXECUTION]: The model serving logic includes an optional path to build TensorRT engines on-the-fly if a cached engine is not found. This involves executing a local script (export_ddm_to_tensorrt.py) to perform the conversion at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The microservice exposes a chat-completions endpoint that accepts user-supplied text prompts to guide video analysis. This creates a surface where external data is interpolated into the vision-language model's context, which is the intended functionality for SOP compliance classification.
  • [PRIVILEGE_ESCALATION]: The provided Docker Compose configuration adds the SYS_PTRACE capability to the service container. While this grants elevated permissions, it is a standard requirement for inter-process communication features and performance analysis tools used in NVIDIA GPU environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 08:39 AM
Security Audit — agent-trust-hub — deepstream-sop