All skills
nvidia avatar

/doca-hardware-safety

@a5736e4
by NVIDIA Corporationnvidia/skills3.5k stars
424

Use this skill whenever the agent is about to recommend or apply a change that touches DPU / NIC hardware state on a live system — mlxconfig firmware-parameter write, NIC firmware burn, BFB reflash, NIC ↔ DPU mode flip, SR-IOV or device-emulation slot enable, kernel boot-parameter change (IOMMU, hugepages, VFIO), PCIe rebind / rescan / link-state flip, or BlueField cold reboot. Wraps the change in pre-flight inventory, OOB reachability, a maintenance window, the mlxconfig cold-power-cycle rule, replica rehearsal, and rollback. Trigger even when the user does not say "hardware safety" — implicit phrasings: "flip BlueField mode over SSH", "enable SR-IOV and reboot", "burned firmware but mlxconfig shows old value", "reflashed BFB and lost representors", "reflash during business hours", "vendor says this is one-way". Refuse for general DOCA orientation (doca-public-knowledge-map), install or env debug (doca-setup), and program-side debug (doca-debug, doca-programming-guide) — those belong to other skills.

Use this Skill: https://skilld.dev/gh/nvidia/skills/doca-hardware-safety

This session only. Nothing lands on disk.

skill-card.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Description: <br>

Use this skill whenever the agent is about to recommend or apply a change that touches DPU / NIC hardware state on a live system — mlxconfig firmware-parameter write, NIC firmware burn, BFB reflash, NIC ↔ DPU mode flip, SR-IOV or device-emulation slot enable, kernel boot-parameter change (IOMMU, hugepages, VFIO), PCIe rebind / rescan / link-state flip, or BlueField cold reboot. <br>

This skill is ready for commercial/non-commercial use. <br>

Owner

NVIDIA <br>

License/Terms of Use: <br>

Apache 2.0 AND CC-BY-4.0 <br>

Use Case: <br>

Production operators and infrastructure engineers use this skill to safely apply hardware-touching changes (firmware writes, BFB reflashes, mode flips, kernel boot-parameter changes) to live NVIDIA BlueField DPU and ConnectX NIC systems with proper pre-flight validation, maintenance windows, and rollback plans. <br>

Deployment Geography for Use: <br>

Global <br>

Requirements / Dependencies: <br>

Requires API Key or External Credential: [No] <br> Credential Type(s): [None] <br>

Do not include secrets in prompts/logs/output; use least-privilege credentials; rotate keys as appropriate. <br>

Known Risks and Mitigations: <br>

Risk: Review before execution as proposals could introduce incorrect or misleading guidance into skills. <br> Mitigation: Review and scan skill before deployment. <br>

Reference(s): <br>

Skill Output: <br>

Output Type(s): [Analysis, Configuration instructions] <br> Output Format: [Markdown] <br> Output Parameters: [1D] <br> Other Properties Related to Output: [None] <br>

Evaluation Agents Used: <br>

  • Claude Code (aws/anthropic/bedrock-claude-opus-4-8) <br>
  • Codex (openai/openai/gpt-5.5) <br>

Evaluation Tasks: <br>

Evaluated against 4 evaluation tasks (3 positive skill-activation, 1 negative activation). <br>

Evaluation Metrics Used: <br>

Reported benchmark dimensions: <br>

  • Security: Checks whether skill-assisted execution avoids unsafe behavior such as secret leakage, destructive commands, or unauthorized access. <br>
  • Correctness: Checks whether the agent follows the expected workflow and produces the correct final output. <br>
  • Discoverability: Checks whether the agent loads the skill when relevant and avoids using it when irrelevant. <br>
  • Effectiveness: Checks whether the agent performs measurably better with the skill than without it. <br>
  • Efficiency: Checks whether the agent uses fewer tokens and avoids redundant work. <br>

Underlying evaluation signals used in this run: <br>

  • security: Checks for unsafe operations, secret leakage, and unauthorized access. <br>
  • skill_execution: Verifies that the agent loaded the expected skill and workflow. <br>
  • skill_efficiency: Checks routing quality, decoy avoidance, and redundant tool usage. <br>
  • accuracy: Grades final-answer correctness against the reference answer. <br>
  • goal_accuracy: Checks whether the overall user task completed successfully. <br>
  • behavior_check: Verifies expected behavior steps, including safety expectations. <br>

Evaluation Results: <br>

Dimension Num Claude Code (aws/anthropic/bedrock-claude-opus-4-8) Codex (openai/openai/gpt-5.5)
Security 4 100% (+0%) 100% (+0%)
Correctness 4 75% (+50%) 100% (+20%)
Discoverability 4 100% (+50%) 94% (+44%)
Effectiveness 4 86% (+46%) 99% (+48%)
Efficiency 4 91% (+41%) 93% (+68%)

Skill Version(s): <br>

ffe362c (source: git SHA, committed 2026-07-25) <br>

Ethical Considerations: <br>

NVIDIA believes Trustworthy AI is a shared responsibility and we have established policies and practices to enable development for a wide array of AI applications. When downloaded or used in accordance with our terms of service, developers should work with their internal team to ensure this skill meets requirements for the relevant industry and use case and addresses unforeseen product misuse. <br>

(For Release on NVIDIA Platforms Only) <br> Please report quality, risk, security vulnerabilities or NVIDIA AI Concerns here. <br>

Source: SKILL.md on GitHub

No alerts2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    The skill 'doca-hardware-safety' is a security-focused framework designed to guide operators through high-risk hardware configuration tasks on NVIDIA DPU and NIC devices. It enforces strict safety protocols, including mandatory pre-flight inventory, out-of-band access verification, and maintenance window planning. No malicious patterns, unauthorized data access, or obfuscation techniques were detected. The skill's design emphasizes human-in-the-loop verification and best practices for administrative tasks.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at a5736e4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "kind": "library"
}
Other metadata
compatibility
No DOCA install required to read this skill (it is an overlay loaded against any DOCA artifact skill); the validation steps within DO require a live DOCA install at /opt/mellanox/doca with a BlueField DPU or ConnectX NIC, plus out-of-band console reachability (BMC, RShim, or operator-managed console) for any link-breaking change.

README badge

README badge for nvidia/skills/doca-hardware-safety