deepstream-sop
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The Docker build process downloads the Basler Pylon SDK from an Azure Blob Storage domain and clones specialized research repositories for event boundary detection (DDM-Net) and GStreamer plugins from GitHub. These are essential, well-known dependencies for the microservice's domain.
- [COMMAND_EXECUTION]: The service uses Python's
subprocessmodule to executenvidia-smifor gathering GPU utilization metrics. It also spawns a subprocess to run an internal export script that converts PyTorch models to TensorRT engines. These are routine tasks for high-performance NVIDIA applications. - [DYNAMIC_EXECUTION]: The model serving logic includes an optional path to build TensorRT engines on-the-fly if a cached engine is not found. This involves executing a local script (
export_ddm_to_tensorrt.py) to perform the conversion at runtime. - [INDIRECT_PROMPT_INJECTION]: The microservice exposes a chat-completions endpoint that accepts user-supplied text prompts to guide video analysis. This creates a surface where external data is interpolated into the vision-language model's context, which is the intended functionality for SOP compliance classification.
- [PRIVILEGE_ESCALATION]: The provided Docker Compose configuration adds the
SYS_PTRACEcapability to the service container. While this grants elevated permissions, it is a standard requirement for inter-process communication features and performance analysis tools used in NVIDIA GPU environments.
Audit Metadata