skills/nvidia/skills/doca-common/Gen Agent Trust Hub

doca-common

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill references official NVIDIA documentation domains and GitHub repositories to provide users with authoritative SDK guidance and samples.
  • [SAFE]: The inclusion of a digital signature bundle (skill.oms.sig) using the sigstore/in-toto standard demonstrates a commitment to software supply chain security and provenance.
  • [SAFE]: Base64 encoded content within the signature file consists of standard X.509 certificates and signature data required for verification, which is expected behavior for this file type.
  • [SAFE]: The skill includes explicit security warnings, specifically advising developers not to log secrets through the DOCA_LOG_* macros due to a lack of automatic redaction.
  • [SAFE]: Command execution recommendations are limited to local environment discovery and build-time configuration using standard system utilities like pkg-config, ls, and grep.
  • [PROMPT_INJECTION]: The skill provides clear instructions to the agent on how to handle specific user queries and when to route to other skills, which serves as functional steering rather than a security bypass attempt.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface as it instructs the agent to inspect local files (headers, samples) and command outputs to provide answers. However, risk is minimal as the agent is guided to use this data for C/C++ development context without executing the content of those files directly. (Severity: LOW)
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 01:22 PM
Security Audit — agent-trust-hub — doca-common