doca-firefly
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely documentation-based, providing configuration patterns, architectural overviews, and debugging workflows for the DOCA Firefly service. It does not contain any executable scripts, code, or commands that interact with the host beyond standard Linux observability tools (e.g.,
tcpdump,pmc,chronyc). - [COMMAND_EXECUTION]: The commands listed in
TASKS.md(such aspmc,phc_ctl,tcpdump, andchronyc) are standard Linux utilities used for network and clock observability. They are presented as manual steps for operators and do not include any automated execution or shell-injection risks. - [EXTERNAL_DOWNLOADS]: The skill mentions pulling container images from NVIDIA NGC, which is a trusted vendor resource for this skill. It correctly instructs users to follow official documentation for image tags and registry credentials.
- [PROMPT_INJECTION]: The instructions focus on technical deployment and troubleshooting. There are no attempts to override agent behavior, bypass safety filters, or extract system prompts. The 'Safety policy' section correctly emphasizes hardware and operational safety.
- [DATA_EXFILTRATION]: No network exfiltration patterns or sensitive file access (like
.sshor.awscredentials) were detected. The skill advises users not to include secrets in prompts or logs.
Audit Metadata