video-streaming-expert
Fail
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: Path Traversal vulnerability in the Node.js streaming server example.\n
- The
references/EXAMPLES.mdfile contains a Node.js implementation of a video delivery endpointapp.get('/video/:filename', ...)that processes user-supplied filenames.\n - The implementation uses
req.params.filenamedirectly in apath.joincall with a local directory without any sanitization or validation against a whitelist.\n - This construction allows a malicious user to supply directory traversal sequences (such as
../../etc/passwd) to access and read sensitive files from the server's filesystem.\n - The file contents are then streamed directly to the network response using
fs.createReadStream(videoPath).pipe(res).\n- [COMMAND_EXECUTION]: Unsafe file path construction in subprocess execution.\n - The
/transcodeendpoint in the Node.js example uses thereq.body.videoIdparameter to construct input and output file paths for theffmpegtool.\n - These unsanitized paths are passed directly as arguments to
child_process.spawn('ffmpeg', [...]).\n - This lack of validation allows for unauthorized file access by pointing the transcoder at sensitive system files or writing output to arbitrary directories on the host.\n- [INDIRECT_PROMPT_INJECTION]: Vulnerability surface due to ingestion of untrusted parameters without sanitization.\n
- The skill demonstrates workflows that ingest untrusted data from network requests and use it to control system-level operations.\n
- Ingestion points: Request parameters (
streamKey,filename) and body fields (videoId) in theserver.jsexample withinreferences/EXAMPLES.md.\n - Boundary markers: No delimiters or safety instructions are present to prevent the agent from treating untrusted data as command components.\n
- Capability inventory: The skill utilizes the
fsmodule for filesystem access (createReadStream,mkdirSync) andchild_process.spawnfor executingffmpeg(found inreferences/EXAMPLES.md).\n - Sanitization: There is a complete absence of input validation, path normalization, or sanitization before external data is used in high-privilege operations.
Recommendations
- AI detected serious security threats
Audit Metadata