skills/nvidia/skills/doca-bench/Gen Agent Trust Hub

doca-bench

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill explicitly states it is documentation-only in SKILLCARD.yaml and does not include any scripts, executables, or runtime code components.
  • [SAFE]: All external references point to official NVIDIA documentation or trusted GitHub repositories (github.com/NVIDIA-DOCA), which are verified vendor resources.
  • [SAFE]: The skill includes comprehensive safety policies in CAPABILITIES.md, warning users that the benchmarking tool is not intended for production deployments and that the companion app's communication channel may carry sensitive information.
  • [SAFE]: A "do-not-invent" guard is implemented to prevent the agent from hallucinating CLI flags, instructing the agent to rely solely on the installed binary's help output or official documentation.
  • [SAFE]: No patterns of prompt injection, data exfiltration, or malicious obfuscation were detected. The large Base64 strings found in skill.oms.sig are standard cryptographic signatures and do not contain executable commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:10 PM
Security Audit — agent-trust-hub — doca-bench