rtvi-cv-scaffold-vss-service

Warn

Audited by Socket on Aug 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and mostly uses official NVIDIA/VSS components and documented data flows, so it does not look malicious. The main issue is the required customer-supplied parser `.so`, an opaque executable loaded into the service without provenance or verification guidance; combined with host networking and container execution, this makes the skill high security risk despite otherwise coherent behavior.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Aug 16, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/nvidia%2Fdeepstream%2Frtvi-cv-scaffold-vss-service%2F@099f05cb4af65406de9d41555aca4a6a2e8045bc4f557f77ff245e40a7675375
Security Audit — socket — rtvi-cv-scaffold-vss-service