video-streaming-expert

Fail

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: Path Traversal vulnerability in the Node.js streaming server example.\n
  • The references/EXAMPLES.md file contains a Node.js implementation of a video delivery endpoint app.get('/video/:filename', ...) that processes user-supplied filenames.\n
  • The implementation uses req.params.filename directly in a path.join call with a local directory without any sanitization or validation against a whitelist.\n
  • This construction allows a malicious user to supply directory traversal sequences (such as ../../etc/passwd) to access and read sensitive files from the server's filesystem.\n
  • The file contents are then streamed directly to the network response using fs.createReadStream(videoPath).pipe(res).\n- [COMMAND_EXECUTION]: Unsafe file path construction in subprocess execution.\n
  • The /transcode endpoint in the Node.js example uses the req.body.videoId parameter to construct input and output file paths for the ffmpeg tool.\n
  • These unsanitized paths are passed directly as arguments to child_process.spawn('ffmpeg', [...]).\n
  • This lack of validation allows for unauthorized file access by pointing the transcoder at sensitive system files or writing output to arbitrary directories on the host.\n- [INDIRECT_PROMPT_INJECTION]: Vulnerability surface due to ingestion of untrusted parameters without sanitization.\n
  • The skill demonstrates workflows that ingest untrusted data from network requests and use it to control system-level operations.\n
  • Ingestion points: Request parameters (streamKey, filename) and body fields (videoId) in the server.js example within references/EXAMPLES.md.\n
  • Boundary markers: No delimiters or safety instructions are present to prevent the agent from treating untrusted data as command components.\n
  • Capability inventory: The skill utilizes the fs module for filesystem access (createReadStream, mkdirSync) and child_process.spawn for executing ffmpeg (found in references/EXAMPLES.md).\n
  • Sanitization: There is a complete absence of input validation, path normalization, or sanitization before external data is used in high-privilege operations.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — video-streaming-expert