All skills
nvidia avatar

/doca-sha-offload-engine

@a5736e4
by NVIDIA Corporationnvidia/skills3.5k stars
424

Use this skill when wiring the DOCA SHA Offload Engine (an OpenSSL ENGINE) into an existing OpenSSL pipeline to offload one-shot SHA-1, SHA-256, or SHA-512 (EVP_Digest) onto DOCA SHA hardware without rewriting against doca-sha. Covers engine load mechanics (`openssl engine dynamic`, `set_pci_addr` ctrl, `-engine_impl`), the SHA-224 negative test that proves offload engaged, the message-size window where offload beats CPU SHA, and engine-vs-library selection. Trigger even when the user does not say "DOCA SHA Offload Engine" or "OpenSSL ENGINE" — typical implicit phrasings: "speed up openssl SHA on BlueField", "offload SHA without code changes", "is openssl using the accelerator or falling back to software", "prove DOCA SHA actually ran", "openssl dgst hashed but I'm not sure it was offloaded". Refuse and route elsewhere for new SHA pipelines (use doca-sha), MD5 / SHA-3 / SHA-224 / HMAC-SHA offload, incremental hashing via chained `EVP_DigestUpdate`, or OpenSSL PROVIDER authoring.

Use this Skill: https://skilld.dev/gh/nvidia/skills/doca-sha-offload-engine

This session only. Nothing lands on disk.

BENCHMARK.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Evaluation Report

Evaluation of the doca-sha-offload-engine skill before publication through Skill Evaluator.

This benchmark summarizes 3-Tier Evaluation from Skill Evaluator results for the skill. The goal is to document whether the skill is safe, discoverable, effective, and useful for agents before it is published for broader workflow use.

Evaluation Summary

  • Skill: doca-sha-offload-engine
  • Evaluation date: 2026-07-26
  • Environment: k8s-sandbox
  • Dataset: 4 evaluation tasks
  • Attempts per task: 1
  • Pass threshold: 50%
  • Overall verdict: PASS

Agents Used

  • Claude Code (aws/anthropic/bedrock-claude-opus-4-8)
  • Codex (openai/openai/gpt-5.5)

Metrics Used

Reported benchmark dimensions:

  • Security: checks whether skill-assisted execution avoids unsafe behavior such as secret leakage, destructive commands, or unauthorized access.
  • Correctness: checks whether the agent follows the expected workflow and produces the correct final output.
  • Discoverability: checks whether the agent loads the skill when relevant and avoids using it when irrelevant.
  • Effectiveness: checks whether the agent performs measurably better with the skill than without it.
  • Efficiency: checks whether the agent uses fewer tokens and avoids redundant work.

Underlying evaluation signals used in this run:

  • security (Security): checks for unsafe operations, secret leakage, and unauthorized access.
  • skill_execution (Skill Execution): verifies that the agent loaded the expected skill and workflow.
  • skill_efficiency (Efficiency): checks routing quality, decoy avoidance, and redundant tool usage.
  • accuracy (Accuracy): grades final-answer correctness against the reference answer.
  • goal_accuracy (Goal Accuracy): checks whether the overall user task completed successfully.
  • behavior_check (Behavior Check): verifies expected behavior steps, including safety expectations.

Test Tasks

The benchmark dataset contained 4 evaluation tasks:

  • Positive tasks: 3 tasks where the skill was expected to activate.
  • Negative tasks: 1 tasks where no skill was expected.
  • Unlabeled tasks: 0 tasks where positive/negative intent could not be inferred.

Task composition is derived from the evaluation dataset when possible. Entries with expected_skill set are treated as positive skill-activation cases, while entries with expected_skill: null are treated as negative activation cases.

Results

Dimension Num Claude Code (aws/anthropic/bedrock-claude-opus-4-8) Codex (openai/openai/gpt-5.5)
Security 4 100% (+0%) 100% (+0%)
Correctness 4 100% (+35%) 100% (+25%)
Discoverability 4 100% (+25%) 95% (+34%)
Effectiveness 4 98% (+69%) 100% (+59%)
Efficiency 4 97% (+36%) 94% (+59%)

Score values show skill-assisted performance. Values in parentheses show uplift versus the no-skill baseline when baseline data is available.

Tier 1: Static Validation Summary

Tier 1 validation passed with observations. Skill Evaluator ran 1 checks and found 7 total findings.

Top findings:

  • MEDIUM SCHEMA/folder_hierarchy: Unexpected nesting depth for general skill (skills/tools/doca-sha-offload-engine)
  • MEDIUM SCHEMA/body_recommended_section: Missing recommended section: '## Instructions' (skills/tools/doca-sha-offload-engine/SKILL.md)
  • MEDIUM SCHEMA/body_recommended_section: Missing recommended section: '## Examples' (skills/tools/doca-sha-offload-engine/SKILL.md)
  • MEDIUM SCHEMA/author_missing: Author not specified in metadata (skills/tools/doca-sha-offload-engine/SKILL.md)
  • LOW SCHEMA/unexpected_file: Unexpected 'CAPABILITIES.md' in skill root (skills/tools/doca-sha-offload-engine/CAPABILITIES.md)

Tier 2: Deduplication Summary

This tier was not run or did not produce findings in this report.

Publication Recommendation

The skill is suitable to proceed toward Skill Evaluator publication based on this benchmark. Skill owners should keep this file with the skill and refresh it when the evaluation dataset, skill behavior, or target agents materially change.

Source: SKILL.md on GitHub

No alerts2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    The doca-sha-offload-engine skill is a documentation-only resource providing verified instructions for using the NVIDIA DOCA SHA Offload Engine with OpenSSL. It guides users through installation, configuration, building, and performance testing of the engine. All referenced tools and URLs belong to trusted or well-known sources (NVIDIA, OpenSSL), and no malicious patterns such as prompt injection, obfuscation, or unauthorized data exfiltration were detected.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at a5736e4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "kind": "tool"
}
Other metadata
compatibility
Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached, plus OpenSSL ≥ 1.1.1 and libssl-dev (or distro equivalent) on the build host. The engine ships under /opt/mellanox/doca/tools/doca_sha_offload_engine/ as libdoca_sha_offload_engine.so; reads the user's local install via `pkg-config doca-sha` and inspects /opt/mellanox/doca/{lib,include,samples,applications}.

README badge

README badge for nvidia/skills/doca-sha-offload-engine