skills/nvidia/skills/doca-version/Gen Agent Trust Hub

doca-version

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructs the agent to use standard system tools (e.g., pkg-config, dpkg, apt-cache, ldconfig) and read specific version files (e.g., /opt/mellanox/doca/applications/VERSION) to verify installation consistency. These operations are limited to environment inspection and do not involve sensitive data access or unauthorized system modifications.
  • [SAFE]: All external URL references target official vendor domains, including docs.nvidia.com and linux.mellanox.com. These are recognized as trusted resources for the authoring organization (NVIDIA).
  • [SAFE]: The instructions emphasize anti-hallucination practices, specifically prohibiting the agent from inventing version strings or relying on training data memory for technical specifications.
  • [SAFE]: The skill.oms.sig file contains standard cryptographic signatures and metadata for file integrity verification, which is a security best practice for skill distribution.
  • [SAFE]: The skill lacks any evidence of prompt injection, data exfiltration, or persistence mechanisms. Its functionality is strictly aligned with the stated purpose of DOCA SDK version management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:09 PM
Security Audit — agent-trust-hub — doca-version