skills/nvidia/skills/doca-version/Gen Agent Trust Hub

doca-version

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for the agent to help users identify installed DOCA versions by reading specific configuration files (e.g., /opt/mellanox/doca/applications/VERSION) and running standard diagnostic utilities like pkg-config, doca_caps, and bfver.
  • [EXTERNAL_DOWNLOADS]: The skill references official NVIDIA and Mellanox resources for documentation and package repositories (e.g., docs.nvidia.com and linux.mellanox.com). These are well-known, trusted vendor domains and do not pose a security risk.
  • [COMMAND_EXECUTION]: Workflows include standard shell commands for system interrogation (grep, cat, dpkg, rpm, flint). No suspicious remote execution patterns (such as piping curl to bash) or arbitrary command injections were detected.
  • [SAFE]: The skill.oms.sig file contains a digital signature bundle in a standard format (Sigstore/in-toto). While it contains Base64-encoded certificates and payloads, these are used for integrity verification and do not contain malicious instructions or obfuscated attack code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 05:55 AM
Security Audit — agent-trust-hub — doca-version