skills/nvidia/skills/doca-firefly/Gen Agent Trust Hub

doca-firefly

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely documentation-based, providing configuration patterns, architectural overviews, and debugging workflows for the DOCA Firefly service. It does not contain any executable scripts, code, or commands that interact with the host beyond standard Linux observability tools (e.g., tcpdump, pmc, chronyc).
  • [COMMAND_EXECUTION]: The commands listed in TASKS.md (such as pmc, phc_ctl, tcpdump, and chronyc) are standard Linux utilities used for network and clock observability. They are presented as manual steps for operators and do not include any automated execution or shell-injection risks.
  • [EXTERNAL_DOWNLOADS]: The skill mentions pulling container images from NVIDIA NGC, which is a trusted vendor resource for this skill. It correctly instructs users to follow official documentation for image tags and registry credentials.
  • [PROMPT_INJECTION]: The instructions focus on technical deployment and troubleshooting. There are no attempts to override agent behavior, bypass safety filters, or extract system prompts. The 'Safety policy' section correctly emphasizes hardware and operational safety.
  • [DATA_EXFILTRATION]: No network exfiltration patterns or sensitive file access (like .ssh or .aws credentials) were detected. The skill advises users not to include secrets in prompts or logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 05:55 AM
Security Audit — agent-trust-hub — doca-firefly