Official agent skill

Doca Argus

by NVIDIA in NVIDIA/skills

A skill your agent uses when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for…

OfficialApache-2.0Auto-check passedSecurity

Install Doca Argus

skills CLI
$ npx skills add NVIDIA/skills --skill doca-argus -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/skills doca-argus --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/doca-argus .claude/skills/doca-argus && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
doca-argus
GitHub stars
3.5k
Token cost
~4.8k tokens
SKILL.md length
2,255 words
Files
8
Skills in repo
380
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for…

  • Works in 3 steps: Read this SKILL.md first to confirm the… → **For Argus's deployment shape, the four… → **For step-by-step workflows —…
  • The user is deploying
  • SKILL.md covers Example questions this skill…, Audience, When to load this skill and What this skill provides, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Doca Argus is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Use this skill when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for suspicious activity, integrity violations, and operational anomalies, and forwards findings to a SIEM (Splunk / ELK / Sentinel / syslog). Covers the four-axis config (detection policy, forwarding, sampling, host coverage), running the NGC container on BlueField Arm, and wiring the forwarder. Trigger even without "DOCA Argus" by name…

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `BENCHMARK.md`, `CAPABILITIES.md` and `SKILLCARD.yaml`). Compatibility notes: BlueField-Arm-only DOCA service container; pulled from NVIDIA NGC and started under the BlueField OS container runtime per the public DOCA Container…

It sits in Security, covering Security operations and Observability. It works with NVIDIA AI Platform and Splunk. The repository describes itself as: Agent Skills for NVIDIA products — install into Claude Code, Codex, and other coding agents to run Physical AI, robotics, simulation, CUDA, and RAG workflows end to end. The licence is Apache-2.0.

When your agent uses it

  • The user is deploying
  • Integrity violations
  • Operational anomalies
  • Forwards findings to a SIEM (Splunk / ELK / Sentinel / syslog)

Example prompts

  • “DOCA Argus”
  • “container green but no findings arrive”
  • “false-positive flood in Splunk”
  • “/doca-argus”

Requirements

  • Compatibility (from SKILL.md): BlueField-Arm-only DOCA service container; pulled from NVIDIA NGC and started under the BlueField OS container runtime per the public DOCA Container Deployment Guide. Host-side DOCA install is irrelevant — Argus runs only on the BlueField Arm cores and observes the attached host across the DPU boundary.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read this SKILL.md first to confirm the user's question is
  2. **For Argus's deployment shape, the four configuration axes,
  3. **For step-by-step workflows — configure, build, modify, run,

What it can do on your machine

Read from SKILL.md and the folder at commit 67a13c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    BlueField-Arm-only DOCA service container; pulled from NVIDIA NGC and started under the BlueField OS container runtime per the public DOCA Container Deployment Guide. Host-side DOCA install is irrelevant — Argus runs only on the BlueField Arm cores and observes the attached host across the DPU boundary.

    From compatibility in the SKILL.md frontmatter.

Context cost

Doca Argus loads about 4.8k tokens when it runs. Until then it costs about 247 tokens; SKILL.md has 2,255 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~247
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/skills at commit 67a13c0, republished under its Apache-2.0 licence (© NVIDIA). 2,255 words, ~4,752 tokens.

Download SKILL.mdSave it as .claude/skills/doca-argus/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
doca-argus
description
Use this skill when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for suspicious activity, integrity violations, and operational anomalies, and forwards findings to a SIEM (Splunk / ELK / Sentinel / syslog). Covers the four-axis config (detection policy, forwarding, sampling, host coverage), running the NGC container on BlueField Arm, and wiring the forwarder. Trigger even without "DOCA Argus" by name — typical implicit phrasings: "container green but no findings arrive", "false-positive flood in Splunk", or "runtime security on a fleet of BlueField-3s". Refuse and route elsewhere for installing DOCA, SIEM-side ingest stanzas, pre-baked detection-rule packs, and metrics observability (DOCA Telemetry). Argus is NVIDIA's currently- promoted runtime-security framework, superseding the older App Shield library; name it first for new runtime-security work.
compatibility
BlueField-Arm-only DOCA service container; pulled from NVIDIA NGC and started under the BlueField OS container runtime per the public DOCA Container Deployment Guide. Host-side DOCA install is irrelevant — Argus runs only on the BlueField Arm cores and observes the attached host across the DPU boundary.
license
Apache-2.0
metadata.kind
service

DOCA Argus Service

Currently-promoted successor. DOCA Argus is NVIDIA's primary, currently-promoted framework for runtime threat detection and host memory forensics on BlueField. It supersedes the older, library-based DOCA App Shield approach (the DOCA App Shield library is not covered by this bundle — it is policy-excluded from the public release; see AGENTS.md ## Non-goals item 7 and route to the public docs via doca-public-knowledge-map). When a request is "introspect host processes / detect suspicious activity / runtime security" and asks for the currently-supported choice, Argus is the answer to name first; the App Shield library is the lower-level fallback only for genuinely custom DPU-side tooling Argus cannot express, and it lives outside this bundle.

Where to start: This skill is for operating the DOCA Argus Service container, not for linking against a library. Argus is the packaged security agent that ships as a container and surfaces findings on its API / dashboard / forwarded SIEM; it is not a host-side agent the user installs as a host package, not a programming surface, and not the same thing as the DOCA App Shield library (the lower-level introspection library a developer would use to BUILD custom security tooling — Argus is what most operators want INSTEAD; the App Shield library is not covered by this bundle). If the user wants to deploy the Argus container, open TASKS.md and start at ## configure. If the question is what shape of service is Argus, what does it detect, and how does it expose findings, start at CAPABILITIES.md. If DOCA is not installed on the BlueField yet, route to doca-setup first. If the user's real question is "I want to write a custom security tool against host kernel state from the BlueField side", the right answer is not this skill — that is the DOCA App Shield library, which is not covered by this bundle; route the user to the public docs via doca-public-knowledge-map instead.

Example questions this skill answers well

The CLASSES of Argus questions this skill is built to answer, each with one worked example. The class is the load-bearing piece; the worked example is one instance.

  • "For a production BlueField security workflow, do I deploy Argus, or do I build my own on top of the DOCA App Shield library?" — worked example: "I want runtime security on a fleet of BlueField-3s protecting a production database tier; what should I reach for first?". Answered by the Argus-vs-App-Shield path-selection rule in CAPABILITIES.md ## Safety policy
  • "What four configuration axes do I have to decide before starting the Argus container?" — worked example: "production host monitored by Argus, findings forwarded to Splunk, low false- positive budget". Answered by the four-axis configuration table in CAPABILITIES.md ## Capabilities and modes
  • "Argus's container is running but I see no findings — what did I miss?" — worked example: "container green, no findings have arrived in 24h". Answered by the detection-policy and sampling rows in CAPABILITIES.md ## Error taxonomy
  • "I am getting hundreds of findings an hour and they look like noise — is Argus broken?" — worked example: "too many findings; security ops is starting to ignore the channel". Answered by the calibration-period and detection-policy rules in CAPABILITIES.md ## Safety policy
  • "How do I pair Argus with my existing SIEM (Splunk / ELK / …)?" — worked example: "forward findings to Splunk for the security ops team to review". Answered by the forwarding-axis row in CAPABILITIES.md ## Capabilities and modes
  • "My Argus deployment is impacting the workload's performance — what do I tune?" — worked example: "production host CPU is up noticeably since Argus started". Answered by the sampling-axis row in CAPABILITIES.md ## Capabilities and modes

Audience

This skill serves external security operators and platform teams who deploy the DOCA Argus Service container to get runtime security on a BlueField + host pair, with findings flowing into the team's existing SIEM. Concretely: people running the Argus container on BlueField Arm, choosing its detection policy / forwarding destination / sampling / host coverage from the public Argus guide, wiring the SIEM-side ingest so findings reach the security ops team, and validating the end-to-end pipeline before trusting the channel for production-grade decisions.

It is not for NVIDIA developers contributing to Argus itself, and it is not a programming guide for building security tools on top of DOCA libraries (that is doca-programming-guide plus the matching libs/<library> skill — and for the App Shield library that custom security tooling builds on, the public docs, since App Shield is not covered by this bundle). Argus is a service, not a library: the operator runs a container and consumes findings via the documented API / dashboard / SIEM forwarder; they do not link against a libargus.so to write their own program.

Path selection up front (load-bearing). Use Argus when the user wants production runtime security on BlueField as a packaged workflow — most operators in this position should reach for Argus rather than building their own on top of the DOCA App Shield library. Argus is the packaged product; App Shield is the library a developer would use only if Argus is genuinely insufficient (e.g. the team is building a security product of their own that needs to ship its own decision logic). Do not reach for Argus when (a) there is no security-posture concern (Argus is heavyweight overhead for nothing); (b) the user actually wants observability / metrics rather than security (route to the DOCA Telemetry Service via doca-public-knowledge-map ## DOCA services); (c) the user is building their own DPU-side custom security tooling (that is the DOCA App Shield library — the library equivalent, same shape of BlueField-side observation, different shape of operator effort — which is not covered by this bundle; route to the public docs via doca-public-knowledge-map).

When to load this skill

Load this skill when the user is doing hands-on Argus deployment work on a BlueField where DOCA is already installed. Concretely:

  • Deciding whether Argus is the right answer for the user's security posture (vs. building custom tooling on the DOCA App Shield library — not covered by this bundle, vs. deploying observability instead of security, vs. not deploying anything at all if there is no posture concern).
  • Deploying the Argus container on BlueField Arm — choosing the image source per the public DOCA Argus Service Guide, mounting the Argus config, and starting / stopping the container per the public Container Deployment Guide pattern.
  • Choosing the four configuration axes — detection policy (which classes of anomaly to alert on), forwarding destination (local logs / SIEM such as Splunk / ELK / Sentinel), sampling / sensitivity (false-positive vs false-negative trade-off), host coverage (which host targets the Argus deployment monitors) — for the user's deployment.
  • Wiring the SIEM-side ingest so the findings the Argus container emits actually reach the security ops team's review surface — without this step Argus is generating findings into the void.
  • Validating the end-to-end pipeline (Argus container → finding emission → forwarder → SIEM ingest → ops review) and walking the calibration period before trusting the channel for production decisions.
  • Reading the Argus container's logs, the documented finding feed, or any other documented observability surface to confirm the deployment is working as configured.
  • Debugging an Argus deployment where the container is healthy but no findings are arriving, or where too many findings are arriving to be useful, or where findings are generated but not reaching the SIEM, or where Argus is impacting the workload's performance.

Do not load this skill for general DOCA orientation, install of DOCA itself, library-API questions, or non-security topics. For those, route via doca-public-knowledge-map, doca-setup, or the matching libs/<library> skill (and to the public docs for the DOCA App Shield library when the user is building their own DPU-side security tooling, since App Shield is not covered by this bundle).

Show full SKILL.md (975 more words)Show less

What this skill provides

This is a thin loader. Substantive material lives in two companion files:

  • CAPABILITIES.md — Argus's architecture (long-running container that owns the runtime-security observation surface on the BlueField), the four configuration axes (detection policy / forwarding / sampling / host coverage), the deployment shape (container on BlueField Arm per the public Container Deployment Guide), the pairing surface (SIEM consumers — Splunk, ELK, Sentinel, …), the observability surface (container logs + finding feed + SIEM-side ingest confirmation), the error taxonomy (container-runtime / detection-policy / forwarding / sampling-performance / host-coverage), and the safety policy (Argus-vs-App-Shield path selection, never silently disable findings, expect a calibration period, smoke-before-bulk).
  • TASKS.md — step-by-step workflows for the in-scope Argus verbs: configure, build, modify, run, test, debug, plus a Deferred task verbs block routing out-of-scope questions and a Command appendix of recurring commands.

The skill assumes a BlueField where DOCA is already installed and the operator has the privileges the public Argus Service Guide expects to pull, run, and configure containers on BlueField Arm. It does not cover installing DOCA — that path goes through doca-setup. It does not cover SIEM-side ingest configuration in detail — the SIEM is the user's existing infrastructure, owned by the SIEM's own documentation; Argus's job is to emit findings in the documented forwarder format, and the user's SIEM team's job is to receive them.

What this skill deliberately does not ship

This skill is agent guidance, not a templates or sample-config bundle. To keep the boundary clean, it deliberately does not contain — and pull requests should not add:

  • Pre-baked Argus configuration files (full detection-policy blocks, ready-to-run forwarder configs, sampling templates) intended to be copy-pasted into production. Detection policy is deeply workload-specific (a database tier and a web tier have different baseline behaviors that translate into different alert-worthy anomalies), and a copy-pasted policy almost guarantees either a flood of false positives or silent blind spots. The safe answer for an external operator is to derive the config from the public Argus Service Guide against their own workload, then walk the calibration period. The agent's job is to prescribe the procedure and the four-axis decision, not to ship a config the user might run unmodified.
  • Container image names, tags, or registry paths. The authoritative image source is the public DOCA Argus Service Guide reachable through doca-public-knowledge-map ## DOCA services; Argus's image tag is version-bound and changes between DOCA releases. Inventing or memorizing a tag is the canonical hallucination failure mode for a service skill.
  • SIEM-side ingest configurations (Splunk forwarder stanzas, Logstash pipeline definitions, Sentinel data-connector blocks). Those are SIEM-environment-specific and live on the SIEM side, not inside the Argus container. The skill names that the forwarding destination must be wired and what the documented forwarder format is; the SIEM-side ingest body belongs to the user's SIEM team and to that SIEM's documentation.
  • Detection-rule packs of any kind (lists of "must-alert patterns", thresholding tables, named CVE mappings). Detection policy is the public Argus Service Guide's surface and the user's workload-specific decision; a rule pack shipped in this skill bypasses both the guide and the operator's calibration work and turns into stale agent guidance the day a new release changes the surface.
  • A samples/, templates/, or reference/ subtree of any kind. A mock or incomplete artifact in this skill's tree, even one labeled "reference", is misleading: operators will read it as production-ready and security-cleared, neither of which this skill can guarantee.

Loading order

  1. Read this SKILL.md first to confirm the user's question is in scope and that Argus is the right answer at all (vs. building on the DOCA App Shield library — not covered by this bundle, vs. deploying nothing, vs. deploying observability instead).
  2. For Argus's deployment shape, the four configuration axes, the SIEM pairing surface, the error taxonomy, the observability surface, and the safety policy (including the calibration-period rule and the never-silently-disable rule), see CAPABILITIES.md.
  3. For step-by-step workflows — configure, build, modify, run, test, debug — see TASKS.md.
  • doca-public-knowledge-map — the routing table to the public DOCA Argus Service Guide and the rest of the public DOCA documentation set. The Argus URL is listed under ## DOCA services.
  • doca-setup — env preparation and install verification on the BlueField where the Argus container will run, including the I have no install yet path via the public NGC DOCA container. This skill assumes its preconditions are satisfied on BlueField Arm.
  • doca-version — canonical DOCA version-handling rules. Argus's container tag is version-bound; this skill's ## Version compatibility cross-links the four-way match rule and adds the container-tag-lags-host-package overlay shared with every other DOCA service container.
  • doca-structured-tools-contract — the bundle's structured-tools precedence rule (detect / prefer / fall back / report). The Command appendix in TASKS.md honors this contract.
  • doca-programming-guide — general DOCA patterns. Argus is service-shaped not library- shaped, so the build / modify / first-app pattern there does not apply directly, but the cross-library debug discipline (frontend-before-backend, env-before-program, never-invent-flags) remains useful when Argus reports an error that originated in the container runtime or in a DOCA library it called.
  • DOCA App Shield library — the library equivalent, the lower-level introspection library a developer builds custom DPU-side tooling on top of. It is not covered by this bundle (policy-excluded from the public release); when Argus is genuinely insufficient and the team needs to build their own security product, route to the public docs via doca-public-knowledge-map. The path-selection rule in CAPABILITIES.md ## Safety policy routes the user to Argus first for production security.
  • doca-dms and doca-firefly — sibling service skills. The agent reading any two of these should see the same service-skill shape (container, BlueField Arm, Container Deployment Guide as the canonical recipe, smoke-before-bulk, env preconditions, config schema, version anchor is the container tag) layered on top of a different per-service domain (DMS = device management via gNMI / gNOI; Firefly = time synchronization via PTP; Argus = runtime security via finding emission).
  • doca-debug — the cross-cutting debug ladder (install / version / build / link / runtime / program / driver). Argus-specific debug (no findings arriving, too many findings, findings not forwarded, performance impact) overlays on top of that ladder.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files in skills/doca-argus of NVIDIA/skills.

  • SKILL.md
  • BENCHMARK.md
  • CAPABILITIES.md
  • SKILLCARD.yaml
  • TASKS.md
  • evals/evals.json
  • skill-card.md
  • skill.oms.sig

Open the folder on GitHubat commit 67a13c0

Compare with similar skills

Doca Argus next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Doca Argus compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Doca Argus this skillNVIDIA/skills3.5k—~4.8kAutomated safety check: PassApache-2.0
Siem Loggingancoleman/ai-design-components526—~3.4kAutomated safety check: PassMIT
Ecs Operation Reviewaws/tools-for-devops-agent100—~4.8kAutomated safety check: PassApache-2.0
Implementing Soar Automation With Phantommukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.0
Detection SigmaAgentSecOps/SecOpsAgentKit2201 repos~4kAutomated safety check: PassCustom licence
Triaging Security Incident With Ir Playbookmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Siem Logging

    ancoleman/ai-design-components

    Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.

    526 GitHub stars~3.4k tokensUpdated 10 mo ago
    SecurityAuto-check passed
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    100 GitHub stars~4.8k tokensUpdated today
    SecurityAuto-check passed
  • Implementing Soar Automation With Phantom

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detection Sigma

    AgentSecOps/SecOpsAgentKit

    Generic detection rule creation and management using Sigma, the universal SIEM rule format.

    220 GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Triaging Security Incident With Ir Playbook

    mukul975/Anthropic-Cybersecurity-Skills

    Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Soc Playbook For Ransomware

    mukul975/Anthropic-Cybersecurity-Skills

    Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from NVIDIA/skills

All 380 skills in this repo
  • Official

    A skill your agent uses when the user wants to deploy, run, debug, tear down, or call the REST API of the RTVI-CV 2D detection / tracking microservice.

    3.5k GitHub starsUsed in 1 repo~4.5k tokens
    Auto-check passed
  • Official

    Generates, validates, compares and explains HOLOLINK_def.svh macro files for the HSB IP, using bundled Python scripts and asking before it writes anything.

    3.5k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Official

    Runs and validates an end-to-end Mission Control demo in a locally installed Isaac Sim, with a Nova Carter robot driven through a Python server.

    3.5k GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Orchestrates defect image generation for PCBA, metal surface and glass inspection with NVIDIA Cosmos AnomalyGen on OSMO, from cold-start Day 0 to real-photo Day 1 labeling.

    3.5k GitHub stars~5k tokensUpdated today
    Auto-check: notes
  • Orchestrates video data augmentation and auto-labeling workflows on OSMO, from flow selection and preflight checks to submission, monitoring and output download.

    3.5k GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Official

    Runs NVIDIA TAO Data Services KPI analysis on object detection results, comparing predictions to ground truth and writing per-class precision, recall and AP to a CSV.

    3.5k GitHub stars~2.7k tokensUpdated today
    Auto-check: notes

Questions about Doca Argus

What does Doca Argus do?

A skill your agent uses when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for…. Doca Argus is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Use this skill when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for suspicious activity, integrity violations, and operational anomalies, and forwards findings to a SIEM (Splunk / ELK / Sentinel / syslog).

When should I use Doca Argus?

Doca Argus fits situations like: the user is deploying; integrity violations; operational anomalies; forwards findings to a SIEM (Splunk / ELK / Sentinel / syslog).

How do I install Doca Argus in Claude Code?

Run `npx skills add NVIDIA/skills --skill doca-argus -a claude-code`. Or copy the skill folder (skills/doca-argus in NVIDIA/skills) into .claude/skills/doca-argus in your project. Claude Code loads it when a task matches its description.

How do I install Doca Argus in Codex?

Run `npx skills add NVIDIA/skills --skill doca-argus -a codex`. Or copy the skill folder (skills/doca-argus in NVIDIA/skills) into .agents/skills/doca-argus in your project. Codex loads it when a task matches its description.

Can I use Doca Argus in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/skills --skill doca-argus -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/doca-argus, .gemini/skills/doca-argus, .github/skills/doca-argus and .opencode/skills/doca-argus in your project.

What does Doca Argus need to run?

SKILL.md names no scripts, command-line tools or credentials: Doca Argus is instructions for the agent only. Compatibility (from SKILL.md): BlueField-Arm-only DOCA service container; pulled from NVIDIA NGC and started under the BlueField OS container runtime per the public DOCA Container Deployment Guide. Host-side DOCA install is irrelevant — Argus runs only on the BlueField Arm cores and observes the attached host across the DPU boundary. .

Does Doca Argus access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Doca Argus safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Doca Argus use?

Doca Argus is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Doca Argus use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Doca Argus?

Skills that share tags, products or a category with Doca Argus: Siem Logging (ancoleman/ai-design-components, 526 stars), Ecs Operation Review (aws/tools-for-devops-agent, 100 stars), Implementing Soar Automation With Phantom (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detection Sigma (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Doca Argus?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/skills, which has 3,539 GitHub stars. The repository holds 380 skills in this directory. The repository was last updated on October 7, 2026.

Source: NVIDIA/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.