Official agent skill

Doca Aes Gcm

by NVIDIA in NVIDIA/skills

A skill your agent uses when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt, querying docaaesgcmcap for…

OfficialApache-2.0Auto-check passedDevelopment

Install Doca Aes Gcm

skills CLI
$ npx skills add NVIDIA/skills --skill doca-aes-gcm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/skills doca-aes-gcm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/doca-aes-gcm .claude/skills/doca-aes-gcm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
doca-aes-gcm
GitHub stars
3.5k
Token cost
~4.2k tokens
SKILL.md length
1,834 words
Files
8
Skills in repo
380
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt, querying docaaesgcmcap for…

  • Works in 3 steps: Read this SKILL.md first to confirm the… → **For the AES-GCM capability matrix,… → **For step-by-step workflows —…
  • The user is doing hands-on DOCA AES-GCM work on a BlueField DPU
  • SKILL.md covers Example questions this skill…, Audience, When to load this skill and What this skill provides, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Doca Aes Gcm is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Use this skill when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt, querying docaaesgcmcap for per-key-type (only DOCAAESGCMKEY128 / 256 — AES-192 not supported) and per-task support, sizing plaintext against the max-buf cap, setting source / destination mmap permissions, validating with a NIST GCMVS or RFC 5288 vector, or debugging DOCAERROR including the security-critical tag-verification-failed outcome on decrypt. Trigger even…

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `BENCHMARK.md`, `CAPABILITIES.md` and `SKILLCARD.yaml`). Compatibility notes: Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the local…

It sits in Development, covering Cryptography. The repository describes itself as: Agent Skills for NVIDIA products — install into Claude Code, Codex, and other coding agents to run Physical AI, robotics, simulation, CUDA, and RAG workflows end to end. The licence is Apache-2.0.

When your agent uses it

  • The user is doing hands-on DOCA AES-GCM work on a BlueField DPU
  • ConnectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt
  • Querying docaaesgcmcap for per-key-type (only DOCAAESGCMKEY128 / 256 — AES-192 not supported) and per-task support
  • Sizing plaintext against the max-buf cap

Example prompts

  • “DOCA AES-GCM”
  • “— typical implicit phrasings:”
  • “auth tag isn”
  • “/doca-aes-gcm”

Requirements

  • Compatibility (from SKILL.md): Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the local install via `pkg-config doca-aes-gcm` and inspects /opt/mellanox/doca/{lib,include,samples,applications}; the accelerator must advertise the desired key type at runtime via `doca_aes_gcm_cap_task_{encrypt,decrypt}_is_key_type_supported` (only `DOCA_AES_GCM_KEY_128` / `_256`; AES-192 unsupported).

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read this SKILL.md first to confirm the user's question is in
  2. **For the AES-GCM capability matrix, task types, key-size
  3. **For step-by-step workflows — configure, build, modify, run,

What it can do on your machine

Read from SKILL.md and the folder at commit 67a13c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the local install via `pkg-config doca-aes-gcm` and inspects /opt/mellanox/doca/{lib,include,samples,applications}; the accelerator must advertise the desired key type at runtime via `doca_aes_gcm_cap_task_{encrypt,decrypt}_is_key_type_supported` (only `DOCA_AES_GCM_KEY_128` / `_256`; AES-192 unsupported).

    From compatibility in the SKILL.md frontmatter.

Context cost

Doca Aes Gcm loads about 4.2k tokens when it runs. Until then it costs about 250 tokens; SKILL.md has 1,834 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~250
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/skills at commit 67a13c0, republished under its Apache-2.0 licence (© NVIDIA). 1,834 words, ~4,164 tokens.

Download SKILL.mdSave it as .claude/skills/doca-aes-gcm/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
doca-aes-gcm
description
Use this skill when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring `doca_aes_gcm_task_encrypt` / `_task_decrypt`, querying `doca_aes_gcm_cap_*` for per-key-type (only `DOCA_AES_GCM_KEY_128` / `_256` — AES-192 not supported) and per-task support, sizing plaintext against the max-buf cap, setting source / destination mmap permissions, validating with a NIST GCMVS or RFC 5288 vector, or debugging DOCA_ERROR_* including the security-critical tag-verification-failed outcome on decrypt. Trigger even when the user does not explicitly mention "DOCA AES-GCM" or "AEAD" — typical implicit phrasings: "decrypt completion IO_FAILED", "auth tag isn't verifying", "NOT_PERMITTED on my encrypt buffer", "is AES-192-GCM on this BlueField" (no), or "encrypted record came back tampered". Refuse and route elsewhere for non-GCM AES modes (CBC / CTR / XTS — CPU OpenSSL), key management (KMS / HSM / rotation), SHA (doca-sha), or general AEAD background.
compatibility
Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the local install via `pkg-config doca-aes-gcm` and inspects /opt/mellanox/doca/{lib,include,samples,applications}; the accelerator must advertise the desired key type at runtime via `doca_aes_gcm_cap_task_{encrypt,decrypt}_is_key_type_supported` (only `DOCA_AES_GCM_KEY_128` / `_256`; AES-192 unsupported).
license
Apache-2.0
metadata.kind
library

DOCA AES-GCM

Where to start: This skill assumes DOCA is already installed and the user is doing hands-on AES-GCM-acceleration work on a BlueField / ConnectX / host with DOCA. Open TASKS.md if the user wants to do something (configure / build / modify / run / test / debug); open CAPABILITIES.md when the question is what can DOCA AES-GCM express on this version. If the user has not installed DOCA yet, route to doca-setup first. If the user is asking "should I even use the accelerator for this encryption?", the path-selection rule in CAPABILITIES.md ## Capabilities and modes is the first stop. If the user is treating AES-GCM as a confidentiality-only primitive (raw AES-CTR / AES-CBC style), stop and read the AEAD note in CAPABILITIES.md ## Safety policy first — AES-GCM is authenticated encryption, and confusing the two is the most expensive failure mode this skill exists to prevent.

Example questions this skill answers well

The CLASSES of DOCA AES-GCM questions this skill is built to answer, each with one worked example. The agent should treat the class as the load-bearing piece — the worked example is a single instance.

  • "Should I offload this AES-GCM encryption to DOCA AES-GCM, or just do it on the CPU with OpenSSL?" — worked example: "I am encrypting 4 KiB TLS records at line rate; is doca-aes-gcm worth the setup vs OpenSSL EVP_aes_256_gcm on the CPU?". Answered by the path-selection table in CAPABILITIES.md ## Capabilities and modes
  • "Does my device support the AES-GCM key size I want?" — worked example: "is AES-256-GCM in the accelerator on this BlueField? And while we're here, is AES-192-GCM available?" (Answer: the library exposes only DOCA_AES_GCM_KEY_128 / DOCA_AES_GCM_KEY_256; AES-192 is not in the enum and is not supported. For the two real key types, gate on doca_aes_gcm_cap_task_encrypt_is_key_type_supported(devinfo, key_type) and the matching _decrypt_is_key_type_supported. AES-192 is not available — route to a CPU library.) Answered by the per-key-type capability queries and the per-task doca_aes_gcm_cap_task_*_is_supported queries in CAPABILITIES.md ## Capabilities and modes
  • "How do I correctly decrypt an AES-GCM message and verify the auth tag?" — worked example: "my doca_aes_gcm_task_decrypt completion reports an error — is the plaintext output safe to use?". Answered by the auth-tag verification rule in CAPABILITIES.md ## Safety policy (do not use the plaintext if the auth tag did not verify) + the decrypt completion-handling workflow in TASKS.md ## test and TASKS.md ## debug.
  • "What permissions does the source / destination mmap need?" — worked example: "my doca_aes_gcm_task_encrypt returns DOCA_ERROR_NOT_PERMITTED". Answered by the permission matrix in CAPABILITIES.md ## Safety policy
  • "Is this DOCA AES-GCM API available on my installed DOCA version?" — worked example: "is AES-192-GCM in the DOCA I have installed, on this device?". Answered by the version-compatibility overlay in CAPABILITIES.md ## Version compatibility, which cross-links the canonical detection chain in doca-version and adds the AES-GCM-specific "discover key sizes via cap query" bullets.
  • "What does this DOCA_ERROR_* from an AES-GCM call mean and which layer caused it?" — worked example: "DOCA_ERROR_IO_FAILED on the decrypt completion — is this a hardware bug or a tag mismatch?". Answered by the AES-GCM overlay on the cross-library taxonomy in CAPABILITIES.md ## Error taxonomy

Audience

This skill serves external developers building applications that consume the DOCA AES-GCM library — i.e., users whose code calls doca_aes_gcm_* (directly in C/C++, or through FFI/bindings from another language) to offload AES-GCM authenticated encryption / decryption onto a BlueField DPU or ConnectX accelerator. It is not for NVIDIA developers contributing to DOCA AES-GCM itself.

Language scope. DOCA AES-GCM ships as a C library with pkg-config module name doca-aes-gcm. The shipped samples are written in C. C and C++ consumers are the canonical case and the worked examples in TASKS.md assume that path. Other-language consumers (Rust, Go, Python, …) consume the same *.so through FFI or language-specific bindings; the skill's contribution in that case is to keep the lifecycle, capability-discovery, permission, error-taxonomy, AEAD-semantics, and encrypt-vs-decrypt guidance language-neutral, and to route the agent to the public C ABI as the authoritative surface that any wrapper will eventually call.

Key handling is out of scope. This skill teaches the agent how to use the DOCA AES-GCM library; it does not teach the user how to generate, store, rotate, or distribute AES-GCM keys. Key-management is the user's responsibility (a KMS, an HSM, a sealed file, an env var the user trusts). The skill's only key-handling rule is the operational one in CAPABILITIES.md ## Safety policy: do not log keys, do not commit them to source, and treat any key buffer the program holds as sensitive memory.

When to load this skill

Load this skill when the user is doing hands-on DOCA AES-GCM work, in any language. Concretely:

  • Initializing a doca_aes_gcm context on a doca_dev and configuring at least one task type (doca_aes_gcm_task_encrypt and/or doca_aes_gcm_task_decrypt) before doca_ctx_start().
  • Choosing between encrypt (doca_aes_gcm_task_encrypt — takes key + IV + AAD + plaintext, produces ciphertext + auth tag) and decrypt (doca_aes_gcm_task_decrypt — takes key + IV + AAD + ciphertext + expected auth tag, produces plaintext and verifies the tag) for the user's data shape.
  • Setting permissions on doca_mmap correctly for the source buffer (DOCA_ACCESS_FLAG_LOCAL_READ_ONLY at minimum — the plaintext on encrypt or the ciphertext on decrypt) and the destination buffer (DOCA_ACCESS_FLAG_LOCAL_READ_WRITE).
  • Checking which AES-GCM key types (DOCA_AES_GCM_KEY_128 / DOCA_AES_GCM_KEY_256 — AES-192 is not in the library) the active device's accelerator advertises via doca_aes_gcm_cap_task_encrypt_is_key_type_supported / doca_aes_gcm_cap_task_decrypt_is_key_type_supported, and which task types via doca_aes_gcm_cap_task_encrypt_is_supported / _task_decrypt_is_supported.
  • Sizing the per-submission plaintext against doca_aes_gcm_cap_task_encrypt_get_max_buf_size(devinfo).
  • Validating an encrypt + decrypt round-trip against a published AES-GCM test vector (NIST GCMVS, or RFC 5288 examples) before pushing any user data through the accelerator.
  • Handling the auth-tag verification result on decrypt completions as a security-critical signal — a tag-mismatch completion means the ciphertext was tampered with or corrupted, and the plaintext output of that task is poisoned and must not be consumed.
  • Debugging a DOCA_ERROR_* returned from an AES-GCM call (lifecycle vs. unsupported key size vs. permission vs. tag verification failure on decrypt) and the task-completion event on the progress engine.
  • Designing or extending non-C bindings (Rust, Go, Python, …) that wrap the AES-GCM C ABI — for the lifecycle, permission, capability, AEAD-semantics, and encrypt-vs-decrypt rules the wrapper must honor.

Do not load this skill for general DOCA orientation, install of DOCA itself, AES modes that are not GCM (CBC / CTR / XTS — those are not in this library and CPU + OpenSSL is the right answer), SHA hashing on the same accelerator family (use doca-sha), or other DOCA libraries. For those, use doca-public-knowledge-map.

Show full SKILL.md (777 more words)Show less

What this skill provides

This is a thin loader. The body keeps only the orientation needed to pick the right next file. The substantive AES-GCM-specific material lives in two companion files:

  • CAPABILITIES.md — what DOCA AES-GCM can express on this version: the two task types (encrypt and decrypt), the AEAD output shape (ciphertext + auth tag on encrypt; verified plaintext on decrypt), the AES-GCM key-type surface (only 128-bit and 256-bit — AES-192 is not in the enum, both cap-queried), the capability-query surface (doca_aes_gcm_cap_* for task presence, key-type support, and buffer sizing), the AES-GCM error taxonomy (mapped onto the cross-library DOCA_ERROR_* set, with explicit treatment of the tag-verification-failure outcome as security-critical), the observability surface (per-task completion events on the progress engine), the safety policy that gates source / destination mmap permission decisions and key-handling cautions, and the path-selection rule (when to use doca-aes-gcm versus CPU OpenSSL or a different DOCA crypto library).
  • TASKS.md — step-by-step workflows for the six in-scope AES-GCM verbs: configure, build, modify, run, test, debug. Plus a Deferred task verbs block that points out-of-scope questions at the right next skill.

The skill assumes a host or BlueField where DOCA is already installed at the standard location and the user has the privileges their public install profile expects. It does not cover installing DOCA — that path goes through doca-setup.

What this skill deliberately does not ship

This skill is agent guidance, not a samples or templates bundle. To keep the boundary clean, it deliberately does not contain — and pull requests should not add:

  • Pre-written DOCA AES-GCM application source code, in any language. The verified AES-GCM source code is the shipped C samples at /opt/mellanox/doca/samples/doca_aes_gcm/. The agent's job is to route the user to those files and prescribe a minimum-diff modification on them via the universal modify-a-sample workflow in doca-programming-guide, layered with the AES-GCM-specific overrides in TASKS.md ## modify.
  • Pre-computed AES-GCM test vectors. The skill tells the agent to use a published test vector (e.g. NIST GCMVS, RFC 5288 AES-GCM examples) as the known-vector smoke; it does not ship a vector bank of its own. The agent must cite the vector source so the user can audit it.
  • Pre-baked AES-GCM keys, IVs, or AAD strings. A key in this repo is a key in every customer's repo — by construction, it must not be there. The skill teaches the shape of the inputs; the user supplies the actual bytes from their own key-management system.
  • Standalone build manifests (meson.build, CMakeLists.txt, Cargo.toml, …) parked inside the skill. The agent constructs the build manifest in the user's project directory against the user's installed DOCA, where pkg-config --modversion doca-aes-gcm is the source of truth.
  • A samples/, bindings/, or reference/ subtree of any kind. A mock or incomplete artifact in this skill's tree, even one labeled "reference", is misleading: users will read it as buildable.

Loading order

  1. Read this SKILL.md first to confirm the user's question is in scope.
  2. For the AES-GCM capability matrix, task types, key-size surface, capability-query rules, permission matrix, AEAD semantics, error taxonomy, observability, and safety / path-selection policy, see CAPABILITIES.md.
  3. For step-by-step workflows — configure, build, modify, run, test, debug — see TASKS.md.

Both companion files cross-link to each other, doca-version for the canonical version-handling rules, and doca-public-knowledge-map whenever the right answer is "look it up in the public docs or the installed package layout" rather than "AES-GCM-specific guidance".

  • doca-public-knowledge-map — the routing table for every public DOCA documentation source and the on-disk layout of an installed DOCA package. The DOCA AES-GCM page lives at docs.nvidia.com/doca/sdk/DOCA-AES-GCM/; it is a member of the DOCA Crypto Acceleration family alongside doca-sha.
  • doca-setup — env preparation, install verification, and the I have no install yet path with the public NGC DOCA container. This skill assumes its preconditions are satisfied.
  • doca-version — canonical DOCA version-handling rules. This skill's ## Version compatibility cross-links the four-way match rule and adds only the AES-GCM-specific "discover key sizes + task presence via cap query" overlay.
  • doca-structured-tools-contract — the bundle's structured-tools precedence rule (detect / prefer / fall back / report). The Command appendix in TASKS.md honors this contract.
  • doca-programming-guide — general DOCA programming patterns shared by every library: the canonical pkg-config + meson build pattern, the universal modify-a-shipped-sample first-app workflow, the universal lifecycle, the cross-library DOCA_ERROR_* taxonomy, and the program-side debug order. This skill layers AES-GCM specifics on top.
  • doca-sha — the sibling library in the DOCA Crypto Acceleration family for hardware-accelerated SHA hashing. Load alongside this skill when the user's flow is authenticated-encryption with a separate keyed hash (rare — AES-GCM already provides authentication via its tag) or when the user is comparing offload paths between the two.
  • doca-debug — the cross-cutting debug ladder (install / version / build / link / runtime / program / driver). AES-GCM-specific debug (key-size-not-supported, oversized input, tag-verification failure on decrypt) overlays on top of that ladder.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files in skills/doca-aes-gcm of NVIDIA/skills.

  • SKILL.md
  • BENCHMARK.md
  • CAPABILITIES.md
  • SKILLCARD.yaml
  • TASKS.md
  • evals/evals.json
  • skill-card.md
  • skill.oms.sig

Open the folder on GitHubat commit 67a13c0

Compare with similar skills

Doca Aes Gcm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Doca Aes Gcm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Doca Aes Gcm this skillNVIDIA/skills3.5k—~4.2kAutomated safety check: PassApache-2.0
Code Review SecurityOWASP/secure-agent-playbook187—~549Automated safety check: PassCC-BY-4.0
Sharp Edges Analysistrailofbits/skills7.4k3 repos~3kAutomated safety check: PassCC-BY-SA-4.0
Crypto Protocol Diagramstrailofbits/skills7.4k—~4.6kAutomated safety check: PassCC-BY-SA-4.0
Mermaid to ProVerif Modeltrailofbits/skills7.4k—~4.5kAutomated safety check: PassCC-BY-SA-4.0
Audit Embedded Firmware Securitycyberful/cyberful135—~644Automated safety check: PassAGPL-3.0

Similar skills

  • Code Review Security

    OWASP/secure-agent-playbook

    Security-focused code review mapped to OWASP Top 10 and ASVS.

    187 GitHub stars~549 tokensUpdated 13 days ago
    DevelopmentAuto-check passed
  • Sharp Edges Analysis

    trailofbits/skills

    Official

    Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis.

    7.4k GitHub starsUsed in 3 repos~3k tokens
    SecurityAuto-check passed
  • Crypto Protocol Diagrams

    trailofbits/skills

    Official

    Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check passed
  • Mermaid to ProVerif Model

    trailofbits/skills

    Official

    Converts a Mermaid sequence diagram of a cryptographic protocol into a ProVerif model file ready for checking secrecy, authentication and forward secrecy.

    7.4k GitHub stars~4.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Audit extracted embedded firmware for boot and update trust, credential and secret handling, service exposure, privilege boundaries, parsers, persistence, cryptography, hardening, recovery, and…

    135 GitHub stars~644 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • A skill your agent uses when targeting IACR Conference on Cryptographic Hardware and Embedded Systems (CHES) or deciding whether a computer-science manuscript fits this venue.

    223 GitHub starsUsed in 1 repo~1.9k tokens
    SecurityAuto-check passed

More from NVIDIA/skills

All 380 skills in this repo
  • Official

    A skill your agent uses when the user wants to deploy, run, debug, tear down, or call the REST API of the RTVI-CV 2D detection / tracking microservice.

    3.5k GitHub starsUsed in 1 repo~4.5k tokens
    Auto-check passed
  • Official

    Generates, validates, compares and explains HOLOLINK_def.svh macro files for the HSB IP, using bundled Python scripts and asking before it writes anything.

    3.5k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Official

    Runs and validates an end-to-end Mission Control demo in a locally installed Isaac Sim, with a Nova Carter robot driven through a Python server.

    3.5k GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Orchestrates defect image generation for PCBA, metal surface and glass inspection with NVIDIA Cosmos AnomalyGen on OSMO, from cold-start Day 0 to real-photo Day 1 labeling.

    3.5k GitHub stars~5k tokensUpdated yesterday
    Auto-check: notes
  • Orchestrates video data augmentation and auto-labeling workflows on OSMO, from flow selection and preflight checks to submission, monitoring and output download.

    3.5k GitHub stars~4.7k tokensUpdated yesterday
    Auto-check: notes
  • Official

    Runs NVIDIA TAO Data Services KPI analysis on object detection results, comparing predictions to ground truth and writing per-class precision, recall and AP to a CSV.

    3.5k GitHub stars~2.7k tokensUpdated yesterday
    Auto-check: notes

Questions about Doca Aes Gcm

What does Doca Aes Gcm do?

A skill your agent uses when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt, querying docaaesgcmcap for…. Doca Aes Gcm is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Use this skill when the user is doing hands-on DOCA AES-GCM work on a BlueField DPU or ConnectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt, querying docaaesgcmcap for per-key-type (only DOCAAESGCMKEY128 / 256 — AES-192 not supported) and per-task support, sizing plaintext against the max-buf cap, setting source / destination mmap permissions, validating with a NIST GCMVS or RFC 5288 vector, or debugging DOCAERROR including the security-critical tag-verification-failed outcome on decrypt.

When should I use Doca Aes Gcm?

Doca Aes Gcm fits situations like: the user is doing hands-on DOCA AES-GCM work on a BlueField DPU; connectX NIC — configuring docaaesgcmtaskencrypt / taskdecrypt; querying docaaesgcmcap for per-key-type (only DOCAAESGCMKEY128 / 256 — AES-192 not supported) and per-task support; sizing plaintext against the max-buf cap.

How do I install Doca Aes Gcm in Claude Code?

Run `npx skills add NVIDIA/skills --skill doca-aes-gcm -a claude-code`. Or copy the skill folder (skills/doca-aes-gcm in NVIDIA/skills) into .claude/skills/doca-aes-gcm in your project. Claude Code loads it when a task matches its description.

How do I install Doca Aes Gcm in Codex?

Run `npx skills add NVIDIA/skills --skill doca-aes-gcm -a codex`. Or copy the skill folder (skills/doca-aes-gcm in NVIDIA/skills) into .agents/skills/doca-aes-gcm in your project. Codex loads it when a task matches its description.

Can I use Doca Aes Gcm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/skills --skill doca-aes-gcm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/doca-aes-gcm, .gemini/skills/doca-aes-gcm, .github/skills/doca-aes-gcm and .opencode/skills/doca-aes-gcm in your project.

What does Doca Aes Gcm need to run?

SKILL.md names no scripts, command-line tools or credentials: Doca Aes Gcm is instructions for the agent only. Compatibility (from SKILL.md): Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the local install via `pkg-config doca-aes-gcm` and inspects /opt/mellanox/doca/{lib,include,samples,applications}; the accelerator must advertise the desired key type at runtime via `doca_aes_gcm_cap_task_{encrypt,decrypt}_is_key_type_supported` (only `DOCA_AES_GCM_KEY_128` / `_256`; AES-192 unsupported). .

Does Doca Aes Gcm access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Doca Aes Gcm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Doca Aes Gcm use?

Doca Aes Gcm is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Doca Aes Gcm use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Doca Aes Gcm?

Skills that share tags, products or a category with Doca Aes Gcm: Code Review Security (OWASP/secure-agent-playbook, 187 stars), Sharp Edges Analysis (trailofbits/skills, 7.4k stars), Crypto Protocol Diagrams (trailofbits/skills, 7.4k stars) and Mermaid to ProVerif Model (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Doca Aes Gcm?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/skills, which has 3,539 GitHub stars. The repository holds 380 skills in this directory. The repository was last updated on October 7, 2026.

Source: NVIDIA/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.