All skills
nvidia avatar

/doca-flow-grpc-server

@a5736e4
by NVIDIA Corporationnvidia/skills3.5k stars
424

PLAINTEXT-ONLY: the shipped `doca_flow_grpc` server uses `grpc::InsecureServerCredentials()` with NO TLS / mTLS / token-auth knob on the binary — transport security must come from external infrastructure (e.g. an mTLS proxy / sidecar) on a trusted segment. Use this skill when bringing up, configuring, hardening, or debugging `doca_flow_grpc` — the DOCA-shipped gRPC remote-control surface in front of `doca-flow` that lets non-C++ clients (Python, Go, Rust, Java) program Flow pipes and entries over RPC instead of linking `libdoca_flow.so` directly. Trigger even when the user doesn't say 'doca-flow-grpc-server' or 'gRPC' — e.g. 'program Flow rules from Python on another host', 'remotely configure pipes on the BlueField', 'client times out connecting to the Flow server', 'where is the .proto for Flow', 'UNAUTHENTICATED / FAILED_PRECONDITION on a Flow RPC'. Route elsewhere for the underlying doca-flow API, generic gRPC tooling (protoc, language bindings), or DOCA install / BFB bring-up.

Use this Skill: https://skilld.dev/gh/nvidia/skills/doca-flow-grpc-server

This session only. Nothing lands on disk.

BENCHMARK.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Evaluation Report

Evaluation of the doca-flow-grpc-server skill before publication through Skill Evaluator.

This benchmark summarizes 3-Tier Evaluation from Skill Evaluator results for the skill. The goal is to document whether the skill is safe, discoverable, effective, and useful for agents before it is published for broader workflow use.

Evaluation Summary

  • Skill: doca-flow-grpc-server
  • Evaluation date: 2026-07-26
  • Environment: k8s-sandbox
  • Dataset: 4 evaluation tasks
  • Attempts per task: 1
  • Pass threshold: 50%
  • Overall verdict: PASS

Agents Used

  • Claude Code (aws/anthropic/bedrock-claude-opus-4-8)
  • Codex (openai/openai/gpt-5.5)

Metrics Used

Reported benchmark dimensions:

  • Security: checks whether skill-assisted execution avoids unsafe behavior such as secret leakage, destructive commands, or unauthorized access.
  • Correctness: checks whether the agent follows the expected workflow and produces the correct final output.
  • Discoverability: checks whether the agent loads the skill when relevant and avoids using it when irrelevant.
  • Effectiveness: checks whether the agent performs measurably better with the skill than without it.
  • Efficiency: checks whether the agent uses fewer tokens and avoids redundant work.

Underlying evaluation signals used in this run:

  • security (Security): checks for unsafe operations, secret leakage, and unauthorized access.
  • skill_execution (Skill Execution): verifies that the agent loaded the expected skill and workflow.
  • skill_efficiency (Efficiency): checks routing quality, decoy avoidance, and redundant tool usage.
  • accuracy (Accuracy): grades final-answer correctness against the reference answer.
  • goal_accuracy (Goal Accuracy): checks whether the overall user task completed successfully.
  • behavior_check (Behavior Check): verifies expected behavior steps, including safety expectations.

Test Tasks

The benchmark dataset contained 4 evaluation tasks:

  • Positive tasks: 3 tasks where the skill was expected to activate.
  • Negative tasks: 1 tasks where no skill was expected.
  • Unlabeled tasks: 0 tasks where positive/negative intent could not be inferred.

Task composition is derived from the evaluation dataset when possible. Entries with expected_skill set are treated as positive skill-activation cases, while entries with expected_skill: null are treated as negative activation cases.

Results

Dimension Num Claude Code (aws/anthropic/bedrock-claude-opus-4-8) Codex (openai/openai/gpt-5.5)
Security 4 100% (+0%) 100% (+0%)
Correctness 4 100% (+65%) 100% (+35%)
Discoverability 4 100% (+38%) 95% (+45%)
Effectiveness 4 87% (+53%) 100% (+50%)
Efficiency 4 91% (+34%) 91% (+62%)

Score values show skill-assisted performance. Values in parentheses show uplift versus the no-skill baseline when baseline data is available.

Tier 1: Static Validation Summary

Tier 1 validation passed with observations. Skill Evaluator ran 1 checks and found 7 total findings.

Top findings:

  • MEDIUM SCHEMA/folder_hierarchy: Unexpected nesting depth for general skill (skills/tools/doca-flow-grpc-server)
  • MEDIUM SCHEMA/body_recommended_section: Missing recommended section: '## Instructions' (skills/tools/doca-flow-grpc-server/SKILL.md)
  • MEDIUM SCHEMA/body_recommended_section: Missing recommended section: '## Examples' (skills/tools/doca-flow-grpc-server/SKILL.md)
  • MEDIUM SCHEMA/author_missing: Author not specified in metadata (skills/tools/doca-flow-grpc-server/SKILL.md)
  • LOW SCHEMA/unexpected_file: Unexpected 'CAPABILITIES.md' in skill root (skills/tools/doca-flow-grpc-server/CAPABILITIES.md)

Tier 2: Deduplication Summary

This tier was not run or did not produce findings in this report.

Publication Recommendation

The skill is suitable to proceed toward Skill Evaluator publication based on this benchmark. Skill owners should keep this file with the skill and refresh it when the evaluation dataset, skill behavior, or target agents materially change.

Source: SKILL.md on GitHub

No alerts2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    This skill provides comprehensive guidance for configuring and operating the DOCA Flow gRPC server. It is purely instructional and includes significant security warnings regarding the server's default plaintext communication, advising users to implement external transport security (TLS/mTLS) and network isolation. It follows industry best practices for system administration and software development within the DOCA ecosystem.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at a5736e4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "kind": "tool"
}
Other metadata
compatibility
Requires DOCA on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC. The `doca_flow_grpc` binary is a build artifact (install: false in tools/flow_grpc_server/meson.build, gated by flag_enable_grpc_support + flag_enable_grpc_flow_library) — NOT installed under a default DOCA path; build it from the DOCA source tree with gRPC enabled. Its `.proto` lives under libs/doca_flow/grpc/. Confirm Flow via `pkg-config doca-flow`.

README badge

README badge for nvidia/skills/doca-flow-grpc-server