doca-bench-extension

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive guide for authoring, building, and debugging shared libraries for the NVIDIA DOCA Bench framework. All instructions follow developer best practices for the target environment.
  • [EXTERNAL_DOWNLOADS]: The skill refers to the DOCA SDK and CUDA Toolkit, which are fetched from official and trusted NVIDIA repositories and domains (e.g., docs.nvidia.com). These references are legitimate and do not involve untrusted third-party sources.
  • [PROMPT_INJECTION]: The skill's instructions to the agent do not contain any bypass markers, role-play instructions, or commands to ignore safety guidelines. It includes proper routing and refusal logic to keep the agent within the intended scope.
  • [COMMAND_EXECUTION]: The skill describes build commands (Meson, Ninja) and diagnostic commands (ldd, nm, readelf) that are standard for shared library development on Linux. No arbitrary or hidden command execution patterns were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by processing user descriptions of workload classes to determine the need for an extension. However, this is mitigated by a mandatory validation workflow that checks against built-in tool modes first and requires specific hardware preconditions. Ingestion occurs via the user prompt in SKILL.md; boundary markers include explicit decision trees in CAPABILITIES.md; capabilities are restricted to generating build and run instructions; and the workflow promotes manual verification steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 05:55 AM
Security Audit — agent-trust-hub — doca-bench-extension