dlstreamer-coding-agent

Warn

Audited by Socket on Sep 8, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose and most capabilities are coherent for a DL Streamer coding assistant, and its external sources are largely official. However, the explicit instruction to bypass user confirmation for installs, downloads, and execution materially conflicts with its own safety rules and makes the skill higher risk than a normal framework guide.

Confidence: 91%Severity: 69%
AnomalyLOW
assets/cpp-app-template.cpp

No clear malware, persistence, credential theft, reverse shell, cryptomining, or network exfiltration behavior is present. The main security issue is unsafe construction of a GStreamer pipeline from unescaped command-line values, especially input URIs, output paths, and device values. This can cause denial of service or potentially pipeline-element injection when arguments are attacker-controlled. RTSP credentials may also be exposed in console output. Use GStreamer API element properties or rigorously escape and allowlist all dynamic values.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Sep 8, 2026, 06:30 PM
Package URL
pkg:socket/skills-sh/open-edge-platform%2Fskills%2Fdlstreamer-coding-agent%2F@99323cacc37fdcfd97c310758a96890bbee87982f96eb79c18c619d7de732cc7
Security Audit — socket — dlstreamer-coding-agent