doca-hardware-safety

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional and safety-oriented, aimed at preventing operational risks like hardware bricking or network disconnection during firmware and configuration changes. No malicious intent or suspicious behavior was identified.- [PROMPT_INJECTION]: The skill processes system tool outputs (e.g., mlxconfig, lspci, dmesg) to verify hardware state. While this represents a potential surface for indirect prompt injection, it is mitigated by the requirement for human-in-the-loop comparison against a manually captured pre-flight baseline and the absence of automated execution based on tool output.- [COMMAND_EXECUTION]: Shell commands recommended (e.g., flint, mlxconfig, devlink) are standard, documented utilities for managing NVIDIA hardware. The skill provides clear guidance on script hygiene, such as checking for shared device readers and ensuring correct log ownership.- [DATA_EXFILTRATION]: No network exfiltration or unauthorized data access patterns were found. Network references are limited to trusted NVIDIA developer forums and official documentation.- [EXTERNAL_DOWNLOADS]: The skill does not perform or recommend automated downloads of external scripts or binaries. Dependencies are limited to official NVIDIA tools and libraries expected in a DOCA environment.- [PRIVILEGE_ESCALATION]: Administrative privilege usage (via sudo) is discussed in the context of system diagnostics and file permissions, following best practices for infrastructure management rather than attempting unauthorized escalation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:10 PM
Security Audit — agent-trust-hub — doca-hardware-safety