skills/nvidia/skills/doca-spcx-cc/Gen Agent Trust Hub

doca-spcx-cc

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of prompt injection attempts or safety filter bypass instructions were found. The language used is purely instructional and context-specific.
  • [DATA_EXFILTRATION]: No sensitive file access or unauthorized network operations were detected. All external references target official NVIDIA documentation or GitHub repositories, which are recognized as trusted vendor sources.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain patterns for downloading or executing remote code. It provides instructions for using the locally pre-installed doca_spcx_cc tool.
  • [OBFUSCATION]: No malicious obfuscation, hidden characters, or deceptive encoding was found. The signature file (skill.oms.sig) contains standard cryptographic metadata (Base64-encoded certificates and manifest) used for artifact verification, which is a benign security best practice.
  • [COMMAND_EXECUTION]: The skill documents the usage of the legitimate doca_spcx_cc CLI tool. It emphasizes using --help to confirm the documented flag surface and includes significant safety warnings regarding hardware-touching changes.
  • [PERSISTENCE_MECHANISMS]: No attempts to establish persistence on the host system were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 05:55 AM
Security Audit — agent-trust-hub — doca-spcx-cc