All skills
nvidia avatar

/doca-flow-grpc-server

@a5736e4
by NVIDIA Corporationnvidia/skills3.5k stars
424

PLAINTEXT-ONLY: the shipped `doca_flow_grpc` server uses `grpc::InsecureServerCredentials()` with NO TLS / mTLS / token-auth knob on the binary — transport security must come from external infrastructure (e.g. an mTLS proxy / sidecar) on a trusted segment. Use this skill when bringing up, configuring, hardening, or debugging `doca_flow_grpc` — the DOCA-shipped gRPC remote-control surface in front of `doca-flow` that lets non-C++ clients (Python, Go, Rust, Java) program Flow pipes and entries over RPC instead of linking `libdoca_flow.so` directly. Trigger even when the user doesn't say 'doca-flow-grpc-server' or 'gRPC' — e.g. 'program Flow rules from Python on another host', 'remotely configure pipes on the BlueField', 'client times out connecting to the Flow server', 'where is the .proto for Flow', 'UNAUTHENTICATED / FAILED_PRECONDITION on a Flow RPC'. Route elsewhere for the underlying doca-flow API, generic gRPC tooling (protoc, language bindings), or DOCA install / BFB bring-up.

Use this Skill: https://skilld.dev/gh/nvidia/skills/doca-flow-grpc-server

This session only. Nothing lands on disk.

skill-card.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Description: <br>

Use this skill when bringing up, configuring, hardening, or debugging doca_flow_grpc — the DOCA-shipped gRPC remote-control surface in front of doca-flow that lets non-C++ clients (Python, Go, Rust, Java) program Flow pipes and entries over RPC instead of linking libdoca_flow.so directly. <br>

This skill is ready for commercial/non-commercial use. <br>

Owner

NVIDIA <br>

License/Terms of Use: <br>

Apache 2.0 AND CC-BY-4.0 <br>

Use Case: <br>

Developers and control-plane engineers who need to program a running DOCA Flow pipeline from a non-C++ process across a network boundary, including standing up the gRPC server, locating .proto contracts, hardening the plaintext endpoint with an external proxy, and diagnosing connectivity or RPC failures. <br>

Deployment Geography for Use: <br>

Global <br>

Requirements / Dependencies: <br>

Requires API Key or External Credential: [No] <br> Credential Type(s): [None] <br>

Do not include secrets in prompts/logs/output; use least-privilege credentials; rotate keys as appropriate. <br>

Known Risks and Mitigations: <br>

Risk: Review before execution as proposals could introduce incorrect or misleading guidance into skills. <br> Mitigation: Review and scan skill before deployment. <br>

Reference(s): <br>

Skill Output: <br>

Output Type(s): [Configuration instructions, Shell commands, Analysis] <br> Output Format: [Markdown with inline bash code blocks] <br> Output Parameters: [1D] <br> Other Properties Related to Output: [None] <br>

Evaluation Agents Used: <br>

  • Claude Code (aws/anthropic/bedrock-claude-opus-4-8) <br>
  • Codex (openai/openai/gpt-5.5) <br>

Evaluation Tasks: <br>

Evaluated against 4 internal skill evaluation tasks (3 positive activation, 1 negative activation). <br>

Evaluation Metrics Used: <br>

Reported benchmark dimensions: <br>

  • Security: Checks whether skill-assisted execution avoids unsafe behavior such as secret leakage, destructive commands, or unauthorized access. <br>
  • Correctness: Checks whether the agent follows the expected workflow and produces the correct final output. <br>
  • Discoverability: Checks whether the agent loads the skill when relevant and avoids using it when irrelevant. <br>
  • Effectiveness: Checks whether the agent performs measurably better with the skill than without it. <br>
  • Efficiency: Checks whether the agent uses fewer tokens and avoids redundant work. <br>

Underlying evaluation signals used in this run: <br>

  • security: Checks for unsafe operations, secret leakage, and unauthorized access. <br>
  • skill_execution: Verifies that the agent loaded the expected skill and workflow. <br>
  • skill_efficiency: Checks routing quality, decoy avoidance, and redundant tool usage. <br>
  • accuracy: Grades final-answer correctness against the reference answer. <br>
  • goal_accuracy: Checks whether the overall user task completed successfully. <br>
  • behavior_check: Verifies expected behavior steps, including safety expectations. <br>

Evaluation Results: <br>

Dimension Num Claude Code (aws/anthropic/bedrock-claude-opus-4-8) Codex (openai/openai/gpt-5.5)
Security 4 100% (+0%) 100% (+0%)
Correctness 4 100% (+65%) 100% (+35%)
Discoverability 4 100% (+38%) 95% (+45%)
Effectiveness 4 87% (+53%) 100% (+50%)
Efficiency 4 91% (+34%) 91% (+62%)

Testing Completed: <br>

[x] Agent Red-Teaming <br> [ ] Network Security <br> [ ] Product Security <br>

Skill Version(s): <br>

2790d51 (source: git SHA, committed 2026-07-26) <br>

Ethical Considerations: <br>

NVIDIA believes Trustworthy AI is a shared responsibility and we have established policies and practices to enable development for a wide array of AI applications. When downloaded or used in accordance with our terms of service, developers should work with their internal team to ensure this skill meets requirements for the relevant industry and use case and addresses unforeseen product misuse. <br>

(For Release on NVIDIA Platforms Only) <br> Please report quality, risk, security vulnerabilities or NVIDIA AI Concerns here. <br>

Source: SKILL.md on GitHub

No alerts2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    This skill provides comprehensive guidance for configuring and operating the DOCA Flow gRPC server. It is purely instructional and includes significant security warnings regarding the server's default plaintext communication, advising users to implement external transport security (TLS/mTLS) and network isolation. It follows industry best practices for system administration and software development within the DOCA ecosystem.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at a5736e4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "kind": "tool"
}
Other metadata
compatibility
Requires DOCA on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC. The `doca_flow_grpc` binary is a build artifact (install: false in tools/flow_grpc_server/meson.build, gated by flag_enable_grpc_support + flag_enable_grpc_flow_library) — NOT installed under a default DOCA path; build it from the DOCA source tree with gRPC enabled. Its `.proto` lives under libs/doca_flow/grpc/. Confirm Flow via `pkg-config doca-flow`.

README badge

README badge for nvidia/skills/doca-flow-grpc-server