CtrlK
BlogDocsLog inGet started
Tessl Logo

doca-argus

Use this skill when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for suspicious activity, integrity violations, and operational anomalies, and forwards findings to a SIEM (Splunk / ELK / Sentinel / syslog). Covers the four-axis config (detection policy, forwarding, sampling, host coverage), running the NGC container on BlueField Arm, and wiring the forwarder. Trigger even without "DOCA Argus" by name — typical implicit phrasings: "container green but no findings arrive", "false-positive flood in Splunk", or "runtime security on a fleet of BlueField-3s". Refuse and route elsewhere for installing DOCA, SIEM-side ingest stanzas, pre-baked detection-rule packs, and metrics observability (DOCA Telemetry). Argus is NVIDIA's currently- promoted runtime-security framework, superseding the older App Shield library; name it first for new runtime-security work.

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/doca-argus/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

46%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured as a thin loader with excellent routing and boundary policing, but it is padded by extensive repetition of the App Shield / not-covered distinction, and its substantive executable and validation content is deferred to companion files that are not present in the bundle.

Suggestions

Consolidate the App Shield / "not covered by this bundle" boundary and the doca-public-knowledge-map routing into a single canonical section; currently the same routing instruction is restated in 6+ places, which pads the body.

Ensure the referenced companion files (CAPABILITIES.md, TASKS.md) actually ship in the bundle — currently every in-body pointer to them is a dangling path, so the actionable and workflow guidance has no executable target.

Move the long "What this skill deliberately does not ship" and "Audience" prose closer to the loader's essential routing, or trim to bullets, to bring the body closer to the 'thin loader' it claims to be.

DimensionReasoningScore

Conciseness

The body is noticeably verbose for a self-described "thin loader": the App Shield / "not covered by this bundle" distinction and the routing pointer to doca-public-knowledge-map are each restated across 6+ sections (e.g. lines 37-45, 52-68, 134-144, 146-163, 201-208, 242-285, 330-339), constituting several padded sections. It avoids explaining concepts Claude already knows, but the repetition is pervasive enough to fall below the midpoint.

2 / 5

Actionability

In-body guidance is concrete navigation — the six worked-example question classes each map to a named file and section anchor (e.g. "CAPABILITIES.md ## Safety policy + TASKS.md ## configure"), and the four config axes are named — but there is no executable code or commands in the body, and the substantive executable content is deferred to CAPABILITIES.md / TASKS.md, which are not present in the provided bundle.

3 / 5

Workflow Clarity

The "Loading order" section gives a clear 3-step sequence (read SKILL.md to confirm scope → CAPABILITIES.md → TASKS.md), but validation checkpoints (smoke-before-bulk, calibration period, end-to-end pipeline validation) are only named as concepts and are deferred to the absent TASKS.md, leaving checkpoints implicit in the body.

3 / 5

Progressive Disclosure

Structure is good: a clear overview with well-signaled one-level-deep references to CAPABILITIES.md and TASKS.md, each described in "What this skill provides". Gaps are that the referenced companion files do not actually exist in the bundle (dangling paths), and the inlined boundary/audience prose is heavier than a "thin loader" would ideally carry.

4 / 5

Total

12

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: third-person, concrete, comprehensive on both what and when, with explicit trigger phrasings (including implicit ones) and clear refuse-and-route boundaries that minimize mis-triggering.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — "watches the BlueField and attached host for suspicious activity, integrity violations, and operational anomalies", "forwards findings to a SIEM", "running the NGC container on BlueField Arm", "wiring the forwarder", plus the four named config axes — with comprehensive coverage. Voice is third person ("the user is deploying", "watches", "forwards"), so no voice penalty applies.

5 / 5

Completeness

Explicitly answers both what (the packaged runtime-security container, four-axis config, container run, forwarder wiring) and when ("Use this skill when the user is deploying or operating the DOCA Argus Service" plus concrete trigger phrasings and an explicit refuse-and-route list).

5 / 5

Trigger Term Quality

Gives comprehensive natural trigger terms and synonyms users would actually say — "runtime security on a fleet of BlueField-3s", "container green but no findings arrive", "false-positive flood in Splunk", plus SIEM names Splunk / ELK / Sentinel / syslog — including explicit implicit-phrasing guidance.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (DOCA Argus runtime security on BlueField Arm) and explicitly differentiates from adjacent surfaces — App Shield library, DOCA install, SIEM-side ingest, DOCA Telemetry — with refuse-and-route guidance, giving minimal conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

relative_links

Relative link issues: 19 missing, 21 suspicious

Warning

Total

14

/

16

Passed

Repository
NVIDIA/skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.