All skills
nvidia avatar

/doca-hardware-safety

@a5736e4
by NVIDIA Corporationnvidia/skills3.5k stars
424

Use this skill whenever the agent is about to recommend or apply a change that touches DPU / NIC hardware state on a live system — mlxconfig firmware-parameter write, NIC firmware burn, BFB reflash, NIC ↔ DPU mode flip, SR-IOV or device-emulation slot enable, kernel boot-parameter change (IOMMU, hugepages, VFIO), PCIe rebind / rescan / link-state flip, or BlueField cold reboot. Wraps the change in pre-flight inventory, OOB reachability, a maintenance window, the mlxconfig cold-power-cycle rule, replica rehearsal, and rollback. Trigger even when the user does not say "hardware safety" — implicit phrasings: "flip BlueField mode over SSH", "enable SR-IOV and reboot", "burned firmware but mlxconfig shows old value", "reflashed BFB and lost representors", "reflash during business hours", "vendor says this is one-way". Refuse for general DOCA orientation (doca-public-knowledge-map), install or env debug (doca-setup), and program-side debug (doca-debug, doca-programming-guide) — those belong to other skills.

Use this Skill: https://skilld.dev/gh/nvidia/skills/doca-hardware-safety

This session only. Nothing lands on disk.

BENCHMARK.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Evaluation Report

Evaluation of the doca-hardware-safety skill before publication through Skill Evaluator.

This benchmark summarizes 3-Tier Evaluation from Skill Evaluator results for the skill. The goal is to document whether the skill is safe, discoverable, effective, and useful for agents before it is published for broader workflow use.

Evaluation Summary

  • Skill: doca-hardware-safety
  • Evaluation date: 2026-07-25
  • Environment: k8s-sandbox
  • Dataset: 4 evaluation tasks
  • Attempts per task: 1
  • Pass threshold: 50%
  • Overall verdict: PASS

Agents Used

  • Claude Code (aws/anthropic/bedrock-claude-opus-4-8)
  • Codex (openai/openai/gpt-5.5)

Metrics Used

Reported benchmark dimensions:

  • Security: checks whether skill-assisted execution avoids unsafe behavior such as secret leakage, destructive commands, or unauthorized access.
  • Correctness: checks whether the agent follows the expected workflow and produces the correct final output.
  • Discoverability: checks whether the agent loads the skill when relevant and avoids using it when irrelevant.
  • Effectiveness: checks whether the agent performs measurably better with the skill than without it.
  • Efficiency: checks whether the agent uses fewer tokens and avoids redundant work.

Underlying evaluation signals used in this run:

  • security (Security): checks for unsafe operations, secret leakage, and unauthorized access.
  • skill_execution (Skill Execution): verifies that the agent loaded the expected skill and workflow.
  • skill_efficiency (Efficiency): checks routing quality, decoy avoidance, and redundant tool usage.
  • accuracy (Accuracy): grades final-answer correctness against the reference answer.
  • goal_accuracy (Goal Accuracy): checks whether the overall user task completed successfully.
  • behavior_check (Behavior Check): verifies expected behavior steps, including safety expectations.

Test Tasks

The benchmark dataset contained 4 evaluation tasks:

  • Positive tasks: 3 tasks where the skill was expected to activate.
  • Negative tasks: 1 tasks where no skill was expected.
  • Unlabeled tasks: 0 tasks where positive/negative intent could not be inferred.

Task composition is derived from the evaluation dataset when possible. Entries with expected_skill set are treated as positive skill-activation cases, while entries with expected_skill: null are treated as negative activation cases.

Results

Dimension Num Claude Code (aws/anthropic/bedrock-claude-opus-4-8) Codex (openai/openai/gpt-5.5)
Security 4 100% (+0%) 100% (+0%)
Correctness 4 75% (+50%) 100% (+20%)
Discoverability 4 100% (+50%) 94% (+44%)
Effectiveness 4 86% (+46%) 99% (+48%)
Efficiency 4 91% (+41%) 93% (+68%)

Score values show skill-assisted performance. Values in parentheses show uplift versus the no-skill baseline when baseline data is available.

Tier 1: Static Validation Summary

Tier 1 validation passed with observations. Skill Evaluator ran 1 checks and found 5 total findings.

Top findings:

  • MEDIUM SCHEMA/body_recommended_section: Missing recommended section: '## Instructions' (skills/doca-hardware-safety/SKILL.md)
  • MEDIUM SCHEMA/body_recommended_section: Missing recommended section: '## Examples' (skills/doca-hardware-safety/SKILL.md)
  • MEDIUM SCHEMA/author_missing: Author not specified in metadata (skills/doca-hardware-safety/SKILL.md)
  • LOW SCHEMA/unexpected_file: Unexpected 'CAPABILITIES.md' in skill root (skills/doca-hardware-safety/CAPABILITIES.md)
  • LOW SCHEMA/unexpected_file: Unexpected 'TASKS.md' in skill root (skills/doca-hardware-safety/TASKS.md)

Tier 2: Deduplication Summary

This tier was not run or did not produce findings in this report.

Publication Recommendation

The skill is suitable to proceed toward Skill Evaluator publication based on this benchmark. Skill owners should keep this file with the skill and refresh it when the evaluation dataset, skill behavior, or target agents materially change.

Source: SKILL.md on GitHub

No alerts2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    The skill 'doca-hardware-safety' is a security-focused framework designed to guide operators through high-risk hardware configuration tasks on NVIDIA DPU and NIC devices. It enforces strict safety protocols, including mandatory pre-flight inventory, out-of-band access verification, and maintenance window planning. No malicious patterns, unauthorized data access, or obfuscation techniques were detected. The skill's design emphasizes human-in-the-loop verification and best practices for administrative tasks.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at a5736e4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "kind": "library"
}
Other metadata
compatibility
No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within DO require a live DOCA install at /opt/mellanox/doca with a BlueField DPU or ConnectX NIC, plus out-of-band console reachability (BMC, RShim, or operator-managed console) for any link-breaking change.

README badge

README badge for nvidia/skills/doca-hardware-safety