Automation & Ops ✓ NVIDIA · Official runtime-securitybluefielddoca-arguscontainer-deploymentsiem-forwardinghost-monitoring

DOCA Argus Runtime Security Operations

Deploy Argus on BlueField to detect runtime threats and forward findings to an existing SIEM.

FollowSkills review · FSRS-2.0
Not recommended
50/ 100 5-point scale 2.5 / 5
Trust15 / 25 · 3.0/5

The skill clearly scopes BlueField, Argus, and SIEM use, forbids silent detector disabling, and requires calibration. However, least privilege, user confirmation, credential handling, data-flow detail, and rollback are not concretely specified; reliance on external SIEM and host observation warrants deductions.

Reliability8 / 20 · 2.0/5

It provides a layered failure model, version checks, and failure-oriented workflows. Yet image names, configuration keys, commands, and log formats are delegated to an external public guide, with no executable test suite supplied; static evidence does not justify a higher score.

Adaptability10 / 15 · 3.3/5

Audience, trigger phrases, supported scenarios, and exclusions are relatively clear. Chinese-language support is absent, and deployment depends on NGC, public documentation, and an external SIEM whose mainland-China reachability is not addressed, so points are deducted.

Convention8 / 15 · 2.7/5

The material is well layered and includes loading order, tasks, limitations, version guidance, and related skills. However, license metadata is inconsistent, author/version/signature fields are missing or TBD, recommended sections are absent, paths conflict with the benchmark report, and maintenance ownership is unclear.

Effectiveness6 / 15 · 2.0/5

It supplies configuration decisions, deployment sequencing, and diagnostic structure, but intentionally omits image tags, configuration examples, SIEM configurations, and complete commands. Users must consult external guidance and fill substantial gaps, limiting static effectiveness.

Verifiability3 / 10 · 1.5/5

The files cite a public guide and include a benchmark report, but the evaluation dataset is unavailable and there is no reproducible test suite, CI coverage, or independent corroboration. Only limited auditability is supported.

Evidence confidence:Low Reviewed Jul 20, 2026 Reviewed revision 55f18499943e
The upstream repository has new commits since this review. The score still applies to the reviewed revision shown and may not cover the latest changes.
Before you use it
  • Do not treat the benchmark PASS or NVIDIA provenance as a substitute for evidence of this skill's actual reliability or safety; the report says the evaluation dataset was unavailable.
  • Before deployment, verify the matching DOCA/container version, public guide, configuration schema, image source, credential scope, and SIEM reachability; these critical facts are not fully contained in the skill files.
  • The skill provides no Chinese-language operational material and does not establish availability of NGC, public documentation, or SIEM services from mainland-China networks.
Review evidence [1][2][3][4][5][6][7][8][9]
See the full review method →

What does this skill do, and when should you use it?

This skill supports security operators and platform teams running the DOCA Argus Service container on BlueField Arm. It guides decisions across detection policy, forwarding, sampling, and host coverage, then helps validate the full path from finding emission to SIEM review. Argus observes the BlueField and attached host for suspicious activity, integrity violations, and operational anomalies. It assumes DOCA is already installed and does not cover DOCA installation or custom security-tool development against a lower-level library.

Guides operators in obtaining and starting the Argus container from NVIDIA NGC on BlueField Arm; selecting detection policy, local or SIEM forwarding, sampling sensitivity, and host coverage; inspecting container logs and the documented finding feed; validating delivery through a forwarder into Splunk, ELK, Sentinel, or syslog; and diagnosing missing findings, excessive findings, forwarding failures, and performance impact.

  1. A security operations team needs runtime security for production BlueField-3 hosts.
  2. A platform team has a healthy Argus container but no findings have reached its SIEM for 24 hours.
  3. Security analysts are receiving a noisy stream of findings and need to tune policy or sampling.
  4. An enterprise needs to connect Argus findings to an existing Splunk, ELK, Sentinel, or syslog workflow.
  5. An operator needs to complete smoke testing and a calibration period before trusting the channel for production decisions.

What are this skill's strengths and limitations?

Pros
  • Covers the four central configuration axes: detection, forwarding, sampling, and host coverage.
  • Addresses end-to-end validation from the Argus container to the security operations surface.
  • Clearly separates the Argus service from the lower-level App Shield library.
  • Includes guidance for missing findings, noisy findings, forwarding problems, and performance impact.
  • Promotes calibration and explicitly avoids silently disabling findings.
Limitations
  • Provides guidance rather than copy-ready production configs, image tags, detection-rule packs, or SIEM ingest definitions.
  • Requires BlueField Arm, an installed DOCA environment, NGC access, and the BlueField OS container runtime.
  • Does not install DOCA and is not intended for metrics observability or custom security-program development.
  • The supplied material does not establish support or testing for particular hardware models, DOCA versions, or deployments.

How do you install this skill?

Install the skill with the NVIDIA skills CLI: npx skills add nvidia/skills --skill doca-argus --yes. This installs the guidance only; the Argus container still must be deployed on a properly prepared BlueField Arm environment from NVIDIA NGC.

How do you use this skill?

After installation, use a task-specific prompt such as: “The Argus container on BlueField is healthy, but no findings are arriving in Splunk. Help me troubleshoot it layer by layer.” Use this skill for Argus configuration, operation, testing, and debugging after DOCA is installed. DOCA installation, detailed SIEM-side ingest configuration, and custom App Shield tool development are out of scope.

How does this skill compare with similar options?

Compared with the older DOCA App Shield library, Argus is a packaged service container for production runtime-security operations; App Shield is a lower-level library for building custom DPU-side security tooling and is outside this bundle. Compared with DOCA Telemetry, Argus focuses on runtime-security findings, while Telemetry addresses metrics observability.

FAQ

Does this skill install DOCA or the Argus container?
It provides installation and operating guidance, and the skill itself can be installed with the skills CLI. DOCA preparation and Argus container deployment must still be performed on BlueField Arm according to the relevant public guides.
Why can a healthy container produce no findings?
The skill directs operators to check detection policy, sampling, host coverage, the finding feed, and the forwarding path rather than treating container health alone as proof of a working pipeline.
Does it include ready-made detection rules or SIEM configurations?
No. It deliberately excludes pre-baked detection policies, production configs, image tags, and Splunk, Logstash, or Sentinel ingest definitions.
Is it suitable for writing a custom security application?
No. Argus is a service container. Custom DPU-side security tooling should use the public documentation for the DOCA App Shield library instead.

More skills from this repository

All from NVIDIA/skills

Dev & Engineering ✓ NVIDIA · Official

DOCA Environment Setup

Verify, prepare, and troubleshoot the DOCA environment while routing workloads to the right deployment path.

Automation & Ops ✓ NVIDIA · Official

DOCA Container Deployment

Deploy, validate, and troubleshoot DOCA service containers on NVIDIA BlueField.

Automation & Ops ✓ NVIDIA · Official

DOCA UROM Service Operations

Deploy and troubleshoot the DOCA UROM service container on BlueField Arm.

Automation & Ops ✓ NVIDIA · Official

DOCA BlueField Bare-Metal Deployment

Run, supervise, and troubleshoot DOCA binaries directly on BlueField hardware.

Automation & Ops ✓ NVIDIA · Official

DOCA Firefly Time-Synchronization Operations

Operate, configure, and troubleshoot DOCA Firefly PTP time synchronization on BlueField.

Dev & Engineering ✓ NVIDIA · Official

DOCA Version Consistency Assistant

Verifies DOCA version sources and host–BlueField consistency while diagnosing build-versus-runtime drift.

Dev & Engineering ✓ NVIDIA · Official

DOCA Flow gRPC Remote Control

Deploy, secure, smoke-test, and troubleshoot DOCA Flow’s gRPC control plane for non-C++ clients.

Dev & Engineering ✓ NVIDIA · Official

DOCA Hardware Telemetry Counter Reader

Guides developers in reading per-domain hardware counters from BlueField and ConnectX devices.

Dev & Engineering ✓ NVIDIA · Official

DOCA Flow DPA Performance

Guides defensible measurement of DOCA Flow rule-update and disable rates on DPA-capable NVIDIA hardware.

Automation & Ops ✓ NVIDIA · Official

DOCA Capabilities Inspector

Inspect what DOCA can see on a host through a read-only device and capability CLI.

Automation & Ops ✓ NVIDIA · Official

DOCA PCC Diagnostic Counters

Read fixed firmware and hardware PCC congestion diagnostics on ConnectX and BlueField devices.

Automation & Ops ✓ NVIDIA · Official

DOCA Telemetry Utils

Discover telemetry counters, translate Data IDs, and verify BlueField support before committing exporter configuration.

Dev & Engineering ✓ NVIDIA · Official

DOCA Verbs Raw RDMA Control

Guides DOCA developers who genuinely need low-level verbs control, porting, and diagnosis.

Automation & Ops ✓ NVIDIA · Official

DOCA Management Service Operations

Operate and troubleshoot NVIDIA DMS for centralized BlueField and ConnectX management.

Dev & Engineering ✓ NVIDIA · Official

DOCA GPUNetIO Development Skill

Helps developers connect CUDA kernels on NVIDIA GPUs to DOCA network queues for GPU-side packet I/O and debugging.

Dev & Engineering ✓ NVIDIA · Official

DOCA STA Storage Target Acceleration

Build and debug RDMA NVMe-oF storage targets accelerated by DOCA STA on BlueField.

Automation & Ops ✓ NVIDIA · Official

DOCA Structured Tools Contract

A governed fallback contract for consolidating DOCA environment, device, capability, validation, and host-DPU state data.

Dev & Engineering ✓ NVIDIA · Official

DOCA Telemetry Exporter Development

Guides DOCA applications in defining, emitting, and debugging structured telemetry for external consumers.

Automation & Ops ✓ NVIDIA · Official

DOCA Upgrade Control

Safely gate DOCA upgrades and rollbacks with explicit confirmation.

Automation & Ops ✓ NVIDIA · Official

DOCA Bench Benchmarking Skill

Measure DOCA library throughput, latency, and bandwidth reproducibly on real NVIDIA networking hardware.

Related skills