Automation & Ops ✓ NVIDIA · Official dpu-hardwarenic-firmwarebluefieldmlxconfigsriovpcierollback

DOCA Hardware Safety

A rollback-oriented operating discipline for live DPU and NIC hardware changes.

FollowSkills review · FSRS-2.0
Not recommended
57/ 100 5-point scale 2.9 / 5
Trust21 / 25 · 4.2/5

SKILL.md, CAPABILITIES.md, and TASKS.md define scoped hardware classes, pre-flight inventory, out-of-band access, maintenance windows, operator-confirmed prerequisites, cold-power-cycle rules, replica rehearsal, rollback, and refusal without rollback. skill-card.md also states that credentials are not required and secrets must not be included. Points are deducted because the skill governs real high-impact operations while authorization, approvals, data-flow details, and recovery endpoints remain operator-supplied, and companion-skill dependencies are not independently verified here.

Reliability8 / 20 · 2.0/5

The workflow order, failure taxonomy, refusal behavior, and rollback ladder are substantially consistent, and the companion files are present in the supplied evidence. Static review cannot establish runnable key paths; there is no reproducible command-level test or real CI coverage, several concrete actions are delegated to other skills, and the benchmark's claimed dataset is unavailable.

Adaptability11 / 15 · 3.7/5

SKILL.md clearly defines hardware change classes, implicit trigger phrases, and out-of-scope scenarios across BlueField, ConnectX, firmware, kernel, PCIe, and reboot operations. Points are deducted because this is primarily a cross-skill safety overlay rather than a standalone operational guide, and Chinese-language support, localized operations, and mainland-China network reachability are not documented.

Convention9 / 15 · 3.0/5

The loader, CAPABILITIES.md, TASKS.md, evaluation files, and skill card provide useful progressive structure, dependencies, version anchors, limitations, ownership, and update guidance. Points are deducted because frontmatter declares Apache-2.0 while skill-card.md declares Apache 2.0 AND CC-BY-4.0; author information, changelog, explicit version-maintenance responsibility, and concrete troubleshooting entry points are incomplete. The benchmark also reports missing Instructions/Examples sections.

Effectiveness5 / 15 · 1.7/5

The skill provides a coherent safety discipline for high-risk hardware changes: inventory, OOB access, maintenance window, application, verification, replica rehearsal, and rollback, with explicit refusal conditions. Points are deducted because it is a thin loader: exact commands, parameters, device versions, and artifact health checks require other skills or operator runbooks. Static evidence does not show directly usable execution output, and the benchmark effectiveness claims are not independently reproducible.

Verifiability3 / 10 · 1.5/5

The supplied files contain structured workflow rules, class tables, failure modes, and rollback requirements that support auditability. However, there is no committed test suite, CI coverage, or independently reproducible experiment; BENCHMARK.md provides only aggregate figures and states that the source evaluation dataset was unavailable. Verifiability is therefore limited.

Evidence confidence:Low Reviewed Jul 20, 2026 Reviewed revision 55f18499943e
The upstream repository has new commits since this review. The score still applies to the reviewed revision shown and may not cover the latest changes.
Before you use it
  • This is a static review; no commands were executed and hardware actions, rollback paths, or benchmark results were not independently verified.
  • Before execution, supply the exact device context, authorization, maintenance window, OOB endpoint, baseline snapshot, version anchors, and a rehearsed rollback procedure.
  • Resolve the Apache-2.0 versus Apache 2.0 AND CC-BY-4.0 metadata inconsistency, and add author, version, changelog, and reproducible test evidence.
  • Chinese output and mainland-China environment support are undocumented; do not treat the benchmark summary figures as independent proof.
Review evidence [1][2][3][4][5][6][7][8]
See the full review method →

What does this skill do, and when should you use it?

This skill covers live-system changes to DPU and NIC hardware state, including mlxconfig writes, firmware burns, BFB reflashes, mode changes, SR-IOV, PCIe state, and BlueField reboots. It requires pre-flight inventory, out-of-band reachability, a time-boxed maintenance window, representative replica rehearsal, and rollback preparation. Production work is routed through configure, test, modify, run verification, and debug/rollback stages. It is a cross-cutting safety layer and does not contain artifact-specific firmware-slot, kernel-parameter, or container-tag instructions.

Determines whether a request activates the hardware-safety overlay; directs the agent to SKILL.md, CAPABILITIES.md, and TASKS.md; structures inventory capture, out-of-band confirmation, maintenance-window planning, replica testing, rollback rehearsal, production application, and post-change verification; and applies the stated cold-power-cycle discipline to mlxconfig-class changes.

  1. An operator is about to switch a BlueField between NIC and DPU mode over SSH and needs to protect the management path.
  2. A network engineer plans to enable SR-IOV, device-emulation slots, or PCIe changes and needs a controlled change plan.
  3. A firmware engineer is preparing a NIC firmware burn or BlueField BFB reflash during a production maintenance window.
  4. A platform engineer is changing IOMMU, VFIO, or hugepage boot state before a host reboot.
  5. A production request lacks rollback, out-of-band access, a maintenance window, or representative replica validation and must be refused or escalated.

What are this skill's strengths and limitations?

Pros
  • Covers mlxconfig, firmware/BFB operations, kernel state, PCIe, SR-IOV, and BlueField reboot risks.
  • Makes maintenance windows, out-of-band access, representative replicas, verification, and documented rollback explicit gates.
  • Provides a reusable cross-cutting policy that overlays artifact-specific DOCA safety guidance.
  • The repository README describes signed publication, evaluation artifacts, and daily synchronization.
Limitations
  • The substantive workflow is delegated to CAPABILITIES.md and TASKS.md, which are not included in the supplied material.
  • Validation requires a live DOCA installation, BlueField or ConnectX hardware, and out-of-band console reachability.
  • It does not specify artifact-level firmware slots, exact kernel parameters, or container tags.
  • The supplied material provides no evidence of support for particular hardware models, firmware combinations, or comprehensive test coverage.

How do you install this skill?

Install the individual skill with the CLI command documented by the repository README:

npx skills add nvidia/skills --skill doca-hardware-safety --yes

The README does not specify a fixed destination; the CLI prompts for the installation location.

How do you use this skill?

After installation in an Agent Skills-compatible client, invoke it for requests involving live DPU/NIC hardware state, for example: “Plan a safe BlueField mode switch over SSH with SR-IOV enabled.” The skill should state the activation explicitly and route the answer through configure → test → modify → run → debug.

FAQ

Is this for general DOCA orientation or application debugging?
No. The source explicitly routes general DOCA orientation, installation/environment debugging, and purely program-side debugging to other skills.
When must it refuse a production recommendation?
When rollback is undocumented, a link-breaking change lacks out-of-band access, no explicit time-boxed maintenance window exists, or the change and rollback have not passed on a representative non-production replica.
Does using it require network access?
The documented npx installation command retrieves the repository, and the source does not describe an offline installation method. Runtime validation requirements explicitly include local DOCA, the relevant hardware, and an out-of-band console.
What is its license?
The SKILL.md frontmatter declares Apache-2.0. The repository README describes the overall project as dual-licensed under Apache License 2.0 and CC BY 4.0.

More skills from this repository

All from NVIDIA/skills

Automation & Ops ✓ NVIDIA · Official

DOCA Capabilities Inspector

Inspect what DOCA can see on a host through a read-only device and capability CLI.

Automation & Ops ✓ NVIDIA · Official

DOCA Upgrade Control

Safely gate DOCA upgrades and rollbacks with explicit confirmation.

Automation & Ops ✓ NVIDIA · Official

DOCA BlueField-3 Bring-Up

Guides operators through BF3 day-one bring-up, recovery, RShim/BFB provisioning, and installation validation.

Dev & Engineering ✓ NVIDIA · Official

DOCA Comch Host–DPU Messaging

Guides developers through configuring, building, and debugging Comch messaging between a host and a BlueField DPU.

Dev & Engineering ✓ NVIDIA · Official

DOCA Device Emulation Development

Guides developers in building custom PCIe devices on BlueField whose backend runs on the DPU and is visible to the host.

Dev & Engineering ✓ NVIDIA · Official

DOCA Hardware Telemetry Counter Reader

Guides developers in reading per-domain hardware counters from BlueField and ConnectX devices.

Dev & Engineering ✓ NVIDIA · Official

DOCA Environment Setup

Verify, prepare, and troubleshoot the DOCA environment while routing workloads to the right deployment path.

Automation & Ops ✓ NVIDIA · Official

DOCA Structured Tools Contract

A governed fallback contract for consolidating DOCA environment, device, capability, validation, and host-DPU state data.

Automation & Ops ✓ NVIDIA · Official

DOCA BlueField Bare-Metal Deployment

Run, supervise, and troubleshoot DOCA binaries directly on BlueField hardware.

Dev & Engineering ✓ NVIDIA · Official

DOCA Device Management Development Skill

Programmatically manage BlueField and ConnectX state through the DOCA C API.

Dev & Engineering ✓ NVIDIA · Official

DOCA SHA OpenSSL Offload Engine

Adds DOCA SHA hardware acceleration to existing OpenSSL pipelines without rewriting the application around the doca-sha C API.

Dev & Engineering ✓ NVIDIA · Official

NeMo Relay Plugin Builder

Guides reusable NeMo Relay runtime behavior into configurable plugins.

Dev & Engineering ✓ NVIDIA · Official

DOCA Flow DPA Performance

Guides defensible measurement of DOCA Flow rule-update and disable rates on DPA-capable NVIDIA hardware.

Dev & Engineering ✓ NVIDIA · Official

Jetson PCIe Controller Customizer

Configure per-controller PCIe state, lane width, and link speed on custom Jetson Thor or Orin carriers.

Automation & Ops ✓ NVIDIA · Official

DOCA PCC Diagnostic Counters

Read fixed firmware and hardware PCC congestion diagnostics on ConnectX and BlueField devices.

Automation & Ops ✓ NVIDIA · Official

DOCA Telemetry Utils

Discover telemetry counters, translate Data IDs, and verify BlueField support before committing exporter configuration.

Dev & Engineering ✓ NVIDIA · Official

DOCA Verbs Raw RDMA Control

Guides DOCA developers who genuinely need low-level verbs control, porting, and diagnosis.

Automation & Ops ✓ NVIDIA · Official

DOCA Management Service Operations

Operate and troubleshoot NVIDIA DMS for centralized BlueField and ConnectX management.

Dev & Engineering ✓ NVIDIA · Official

DOCA GPUNetIO Development Skill

Helps developers connect CUDA kernels on NVIDIA GPUs to DOCA network queues for GPU-side packet I/O and debugging.

Dev & Engineering ✓ NVIDIA · Official

DOCA STA Storage Target Acceleration

Build and debug RDMA NVMe-oF storage targets accelerated by DOCA STA on BlueField.

Related skills