All skills
nvidia avatar

/doca-aes-gcm

@f64fa0e
by NVIDIA Corporationnvidia/skills3.5k stars
424

Use this skill when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring `doca_aes_gcm_task_encrypt` / `_task_decrypt`, querying `doca_aes_gcm_cap_*` for per-key-type (only `DOCA_AES_GCM_KEY_128` / `_256` — AES-192 not supported) and per-task support, sizing plaintext against the max-buf cap, setting source / destination mmap permissions, validating with a NIST GCMVS or RFC 5288 vector, or debugging DOCA_ERROR_* including the security-critical tag-verification-failed outcome on decrypt. Trigger even when the user does not explicitly mention "DOCA AES-GCM" or "AEAD" — typical implicit phrasings: "decrypt completion IO_FAILED", "auth tag isn't verifying", "NOT_PERMITTED on my encrypt buffer", "is AES-192-GCM on this BlueField" (no), or "encrypted record came back tampered". Refuse and route elsewhere for non-GCM AES modes (CBC / CTR / XTS — CPU OpenSSL), key management (KMS / HSM / rotation), SHA (doca-sha), or general AEAD background.

Use this Skill: https://skilld.dev/gh/nvidia/skills/doca-aes-gcm

This session only. Nothing lands on disk.

skill-card.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Description: <br>

Guides AI agents through hands-on DOCA AES-GCM authenticated encryption and decryption work on BlueField DPU or ConnectX NIC hardware, covering task configuration, capability discovery, mmap permissions, NIST/RFC test-vector validation, and DOCA_ERROR debugging. <br>

This skill is ready for commercial/non-commercial use. <br>

Owner

NVIDIA <br>

License/Terms of Use: <br>

Apache 2.0 AND CC-BY-4.0 <br>

Use Case: <br>

Developers and engineers building applications that consume the DOCA AES-GCM C library to offload AES-GCM authenticated encryption and decryption onto a BlueField DPU or ConnectX accelerator. <br>

Deployment Geography for Use: <br>

Global <br>

Requirements / Dependencies: <br>

Requires API Key or External Credential: [Not Specified] <br> Credential Type(s): [None identified] <br>

Do not include secrets in prompts/logs/output; use least-privilege credentials; rotate keys as appropriate. <br>

Known Risks and Mitigations: <br>

Risk: Review before execution as proposals could introduce incorrect or misleading guidance into skills. <br> Mitigation: Review and scan skill before deployment. <br>

Reference(s): <br>

Skill Output: <br>

Output Type(s): [Analysis, Configuration instructions, Shell commands] <br> Output Format: [Markdown with inline code blocks] <br> Output Parameters: [1D] <br> Other Properties Related to Output: [None] <br>

Evaluation Agents Used: <br>

  • Claude Code (aws/anthropic/bedrock-claude-opus-4-8) <br>
  • Codex (openai/openai/gpt-5.5) <br>

Evaluation Tasks: <br>

Evaluated against 4 internal evaluation tasks (3 positive skill-activation, 1 negative). <br>

Evaluation Metrics Used: <br>

Reported benchmark dimensions: <br>

  • Security: Checks whether skill-assisted execution avoids unsafe behavior such as secret leakage, destructive commands, or unauthorized access. <br>
  • Correctness: Checks whether the agent follows the expected workflow and produces the correct final output. <br>
  • Discoverability: Checks whether the agent loads the skill when relevant and avoids using it when irrelevant. <br>
  • Effectiveness: Checks whether the agent performs measurably better with the skill than without it. <br>
  • Efficiency: Checks whether the agent uses fewer tokens and avoids redundant work. <br>

Underlying evaluation signals used in this run: <br>

  • security: Checks for unsafe operations, secret leakage, and unauthorized access. <br>
  • skill_execution: Verifies that the agent loaded the expected skill and workflow. <br>
  • skill_efficiency: Checks routing quality, decoy avoidance, and redundant tool usage. <br>
  • accuracy: Grades final-answer correctness against the reference answer. <br>
  • goal_accuracy: Checks whether the overall user task completed successfully. <br>
  • behavior_check: Verifies expected behavior steps, including safety expectations. <br>

Evaluation Results: <br>

Dimension Num Claude Code (aws/anthropic/bedrock-claude-opus-4-8) Codex (openai/openai/gpt-5.5)
Security 4 100% (+0%) 100% (+0%)
Correctness 4 75% (+15%) 100% (+25%)
Discoverability 4 100% (+38%) 94% (+31%)
Effectiveness 4 93% (+57%) 94% (+46%)
Efficiency 4 97% (+39%) 96% (+66%)

Skill Version(s): <br>

d53d861 (source: git SHA, committed 2026-07-23) <br>

Ethical Considerations: <br>

NVIDIA believes Trustworthy AI is a shared responsibility and we have established policies and practices to enable development for a wide array of AI applications. When downloaded or used in accordance with our terms of service, developers should work with their internal team to ensure this skill meets requirements for the relevant industry and use case and addresses unforeseen product misuse. <br>

(For Release on NVIDIA Platforms Only) <br> Please report quality, risk, security vulnerabilities or NVIDIA AI Concerns here. <br>

Source: SKILL.md on GitHub

No alerts2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    The skill provides guidance for using the NVIDIA DOCA AES-GCM library for hardware-accelerated encryption. It contains technical instructions, best practices for secure buffer management, and detailed error handling advice, particularly regarding authenticated encryption (AEAD). No security issues were detected.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at f64fa0e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
metadata
{
  "kind": "library"
}
Other metadata
compatibility
Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the local install via `pkg-config doca-aes-gcm` and inspects /opt/mellanox/doca/{lib,include,samples,applications}; the accelerator must advertise the desired key type at runtime via `doca_aes_gcm_cap_task_{encrypt,decrypt}_is_key_type_supported` (only `DOCA_AES_GCM_KEY_128` / `_256`; AES-192 unsupported).

README badge

README badge for nvidia/skills/doca-aes-gcm