skills/nvidia/skills/doca-flow/Gen Agent Trust Hub

doca-flow

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill provides legitimate developer guidance for NVIDIA DOCA Flow and incorporates safety-first instructions for interacting with networking hardware.\n- [COMMAND_EXECUTION]: The skill utilizes common development and system tools such as pkg-config, grep, ldd, meson, ninja, and devlink. These tools are used appropriately to inspect the environment, build software, and verify port configurations.\n- [PRIVILEGE_ESCALATION]: The skill includes instructions to use sudo for configuring system hugepages (mount, tee). This is a documented requirement for DOCA/DPDK applications and is presented transparently within the configuration workflow.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it translates user networking requirements into code.\n
  • Ingestion points: User-provided networking requirements, project manifests, and source files.\n
  • Boundary markers: Includes non-negotiable rules for library selection, ground rules for symbol verification, and explicit refusal criteria for hardware-incompatible requests.\n
  • Capability inventory: Access to build toolchains, system diagnostic tools, and administrative access for hugepage setup.\n
  • Sanitization: The skill enforces strict adherence to official NVIDIA samples and requires the agent to cross-reference all symbols with local installed headers, ensuring accuracy and safety against untrusted inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 05:55 AM
Security Audit — agent-trust-hub — doca-flow