doca-collectx-deployment
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists exclusively of instructional Markdown files and metadata. No scripts, binaries, or other executable files are bundled with the skill. The structure utilizes companion files like CAPABILITIES.md and TASKS.md to organize guidance.\n- [EXTERNAL_DOWNLOADS]: The skill references official NVIDIA documentation (docs.nvidia.com) and verified public GitHub repositories (github.com/NVIDIA-DOCA). These are trusted external sources according to the author context and general security standards.\n- [PROMPT_INJECTION]: No malicious prompt injection patterns were detected. The skill incorporates several safety constraints, specifically instructing the agent to refuse to 'invent' or hallucinate symbols, provider names, or configuration paths, and to instead rely on live system data and official guides.\n- [COMMAND_EXECUTION]: Instructional content describes standard operational tasks for telemetry daemons. There are no instances of obfuscated commands, suspicious shell pipes from remote sources, or attempts at unauthorized privilege escalation.\n- [DATA_EXFILTRATION]: The skill outlines the use of legitimate telemetry export backends such as Prometheus, Fluent Bit, and NetFlow. No evidence of hidden exfiltration channels, unauthorized network requests, or hardcoded credentials was found.
Audit Metadata