Official agent skill

Doca Dms

by NVIDIA in NVIDIA/skills

Operate NVIDIA DOCA Management Service (dmsd + dmspe) on a BlueField, Arm/x86 host, or Kubernetes pod: choose deployment and authentication, configure -allowedusers and dmsgroup, use gNMI…

OfficialApache-2.0Auto-check passedBackend & APIs

Install Doca Dms

skills CLI
$ npx skills add NVIDIA/skills --skill doca-dms -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/skills doca-dms --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/doca-dms .claude/skills/doca-dms && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
doca-dms
GitHub stars
3.5k
Token cost
~2.8k tokens
SKILL.md length
1,293 words
Files
8
Skills in repo
380
Repo updated
First seen
Licence
Apache-2.0

At a glance

Operate NVIDIA DOCA Management Service (dmsd + dmspe) on a BlueField, Arm/x86 host, or Kubernetes pod: choose deployment and authentication, configure -allowedusers and dmsgroup, use gNMI…

  • Works in 4 steps: Read this SKILL.md first to confirm the… → **For the DMS architecture, deployment… → **For step-by-step workflows —… → …
  • Even without DMS for manage a remote BlueField over gRPC
  • SKILL.md covers Example questions this skill…, Audience, When to load this skill and What this skill provides, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Doca Dms is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Operate NVIDIA DOCA Management Service (dmsd + dmspe) on a BlueField, Arm/x86 host, or Kubernetes pod: choose deployment and authentication, configure -allowedusers and dmsgroup, use gNMI Get/Set/Subscribe, run supported gNOI workflows, and debug frontend/backend failures. Trigger even without "DMS" for "manage a remote BlueField over gRPC", "gNOI reboot from orchestrator", or fleet-management requests. SAFETY: reboot, OS install, factory-reset, and managed-file deletion are destructive and require target-bound…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `BENCHMARK.md`, `CAPABILITIES.md` and `SKILLCARD.yaml`). Compatibility notes: DOCA service shipped with the DOCA install at /opt/mellanox/doca on the management endpoint (x86 host (non-DPU), BlueField Arm, or Kubernetes pod) on Linux…

It sits in Backend & APIs, covering Messaging and chat bots and gRPC and Protobuf. It works with NVIDIA AI Platform, gRPC and Kubernetes. The repository describes itself as: Agent Skills for NVIDIA products — install into Claude Code, Codex, and other coding agents to run Physical AI, robotics, simulation, CUDA, and RAG workflows end to end. The licence is Apache-2.0.

When your agent uses it

  • Even without DMS for manage a remote BlueField over gRPC
  • GNOI reboot from orchestrator
  • Fleet-management requests

Example prompts

  • “manage a remote BlueField over gRPC”
  • “gNOI reboot from orchestrator”
  • “/doca-dms”

Requirements

  • Compatibility (from SKILL.md): DOCA service shipped with the DOCA install at /opt/mellanox/doca on the management endpoint (x86 host (non-DPU), BlueField Arm, or Kubernetes pod) on Linux (Ubuntu 22.04/24.04 or RHEL/SLES); `dmsd` + `dmspe` run there, and DMS is also pulled as an NGC container image. Verify the public DMS guide version matches the installed DOCA release before quoting flags or YANG paths.

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read this SKILL.md first to confirm the user's question is in scope.
  2. **For the DMS architecture, deployment shapes, auth modes,
  3. **For step-by-step workflows — configure, build, modify, run, test,
  4. Apply the destructive-operation gate in every phase. Before any

What it can do on your machine

Read from SKILL.md and the folder at commit 0e0d506. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    DOCA service shipped with the DOCA install at /opt/mellanox/doca on the management endpoint (x86 host (non-DPU), BlueField Arm, or Kubernetes pod) on Linux (Ubuntu 22.04/24.04 or RHEL/SLES); `dmsd` + `dmspe` run there, and DMS is also pulled as an NGC container image. Verify the public DMS guide version matches the installed DOCA release before quoting flags or YANG paths.

    From compatibility in the SKILL.md frontmatter.

Context cost

Doca Dms loads about 2.8k tokens when it runs. Until then it costs about 184 tokens; SKILL.md has 1,293 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~184
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/skills at commit 0e0d506, republished under its Apache-2.0 licence (© NVIDIA). 1,293 words, ~2,833 tokens.

Download SKILL.mdSave it as .claude/skills/doca-dms/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
doca-dms
description
Operate NVIDIA DOCA Management Service (`dmsd` + `dmspe`) on a BlueField, Arm/x86 host, or Kubernetes pod: choose deployment and authentication, configure `-allowed_users` and `dmsgroup`, use gNMI Get/Set/Subscribe, run supported gNOI workflows, and debug frontend/backend failures. Trigger even without "DMS" for "manage a remote BlueField over gRPC", "gNOI reboot from orchestrator", or fleet-management requests. SAFETY: reboot, OS install, factory-reset, and managed-file deletion are destructive and require target-bound explicit confirmation; never invoke them speculatively. Route installation and library/API build questions elsewhere, and route turnkey aggregation to the externally-productized DOCA Telemetry Service.
compatibility
DOCA service shipped with the DOCA install at /opt/mellanox/doca on the management endpoint (x86 host (non-DPU), BlueField Arm, or Kubernetes pod) on Linux (Ubuntu 22.04/24.04 or RHEL/SLES); `dmsd` + `dmspe` run there, and DMS is also pulled as an NGC container image. Verify the public DMS guide version matches the installed DOCA release before quoting flags or YANG paths.
license
Apache-2.0
metadata.kind
service

DOCA Management Service (DMS)

⚠️ Destructive operations. The gNOI reboot, OS install, factory-reset, and managed-file deletion operations are irreversible and service-impacting — they can take a production BlueField or ConnectX offline or wipe its configuration. Before issuing any of them the agent MUST: (1) verify the target device identity, and (2) obtain explicit confirmation bound to that target and action. In an interactive session this is an explicit user reply naming/accepting both; in unattended execution it must be an approved-system authorization artifact bound to both. Otherwise stop with confirmation_required. Never invoke them speculatively or as a side effect of another task. See the public DMS guide's safety guidance for these operations.

Where to start: This skill is for operating DMS, not for linking against a library. If the user wants to deploy or run the daemon, open TASKS.md and start at ## configure. If the question is what shape of service is DMS and what protocols does it speak, start at CAPABILITIES.md. If DOCA is not installed on the management endpoint yet, route to doca-setup first.

Example questions this skill answers well

The CLASSES of DMS questions this skill is built to answer, each with one worked example. The class is the load-bearing piece; the worked example is one instance.

Audience

This skill serves external operators and platform teams who deploy and operate DMS to manage NVIDIA® BlueField® networking platforms or NVIDIA® ConnectX® SmartNICs from a centralized control plane. Concretely: people running dmsd, integrating gNMI/gNOI clients against it, choosing an authentication mode, or wiring DMS into a Kubernetes deployment.

It is not for NVIDIA developers contributing to DMS itself, and it is not a programming guide for building applications on top of DOCA libraries (that is doca-programming-guide plus the matching library skill under libs/). DMS is a service, not a library: the user invokes it as a daemon and talks to it over gRPC; they do not link against libdms.so to write their own program.

Status note. Per the public DMS guide, DMS is currently in beta, with General Availability scoped to SPC-X use cases. The skill reflects the public guide's posture: prescribe the documented launch / auth / deployment paths, follow the documented security best practices, and defer roadmap and GA-scope questions to the live public guide rather than guessing.

When to load this skill

Load this skill when the user is doing hands-on DMS operation work against a BlueField or ConnectX target where DOCA is already installed on the management endpoint (host, DPU, or pod). Concretely:

  • Deciding where DMS should run (host non-DPU / BlueField Arm / Kubernetes pod) for a given target topology.
  • Bringing up the dmsd daemon — choosing SystemD vs manual launch, selecting an authentication mode, wiring -allowed_users (the gRPC client authorization boundary) and, if needed, dmsgroup (the dmspe backend-helper Unix group).
  • Issuing gNMI Get / Set requests against modeled paths (e.g. /interfaces/interface/config/mtu).
  • Issuing gNOI operations: OS install, reboot, file transfer, factory-reset, mlxconfig, containerz.
  • Choosing an authentication mode (localhost / PAM / credentials / mTLS) and understanding the security trade-offs the public guide calls out.
  • Reading or rotating DMS logs, configuring config persistency, or recovering from a crashed daemon.
  • Debugging a DMS request that returned an error — separating "frontend rejected before reaching backend" from "backend executed and the underlying tool (e.g. mlxconfig) failed".

Do not load this skill for general DOCA orientation, install of DOCA itself, or library-API questions. For those, route via doca-public-knowledge-map, doca-setup, or the matching libs/<library> skill.

Show full SKILL.md (510 more words)Show less

What this skill provides

This is a thin loader. Substantive material lives in two companion files:

  • CAPABILITIES.md — DMS architecture (frontend dmsd / privileged backend dmspe), management protocols (gNMI, gNOI), the YANG-based unified configuration dictionary, deployment shapes, authentication modes with their security trade-offs, the configuration-persistency model, the logging surface, and DMS's documented security posture.
  • TASKS.md — step-by-step workflows for the in-scope DMS verbs: configure, build, modify, run, test, debug, plus a Deferred task verbs block routing out-of-scope questions.

The skill assumes a host where DOCA is already installed and the operator has root / sudo access where the public guide says it is required. It does not cover installing DOCA — that path goes through doca-setup.

What this skill deliberately does not ship

This skill is agent guidance, not a templates or sample-config bundle. To keep the boundary clean, it deliberately does not contain — and pull requests should not add:

  • Pre-baked DMS configuration files (YANG instance documents, full-stack example configs, ready-to-run dmsd flag bundles) intended to be copy-pasted into production. Configs are deployment- specific and the safe answer for an external operator is to derive them from the public guide against their own target. The agent's job is to prescribe the procedure and quote the documented flags and paths, not to ship a config the user might run unmodified.
  • Pre-written gNMI / gNOI client programs in any language. The client surface is standard gNMI / gNOI (publicly documented); the skill describes which paths and operations DMS supports, not how to build a gRPC client in language X.
  • TLS material, credentials, or PAM stanzas. These are user-environment artifacts; the skill points at the documented configuration knobs and the documented security best practices and stops there.
  • A samples/, templates/, or reference/ subtree of any kind. A mock or incomplete artifact in this skill's tree, even one labeled "reference", is misleading: operators will read it as production-ready.

Loading order

  1. Read this SKILL.md first to confirm the user's question is in scope.
  2. For the DMS architecture, deployment shapes, auth modes, protocol/path inventory, persistency, logging, and security posture, see CAPABILITIES.md.
  3. For step-by-step workflows — configure, build, modify, run, test, debug — see TASKS.md.
  4. Apply the destructive-operation gate in every phase. Before any gNOI OS install, reboot, factory reset, or managed-file deletion — including a test or debug action — verify the exact target and obtain explicit confirmation for that specific operation using the interactive or approved-system mechanism defined in the warning above. No earlier confirmation or workflow phase carries authorization forward.
  • doca-public-knowledge-map — the routing table to the public DMS guide and the rest of the public DOCA documentation set.
  • doca-setup — env preparation and install verification on the host where dmsd will run, including the I have no install yet path via the public NGC DOCA container. This skill assumes its preconditions are satisfied at the management endpoint.
  • doca-programming-guide — general DOCA patterns. DMS is service-shaped not library-shaped, so the build / modify / first-app pattern there does not apply directly, but the cross-library DOCA_ERROR_* taxonomy and the layered-debug order remain useful when DMS reports errors that originated in a DOCA library it called.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files in skills/doca-dms of NVIDIA/skills.

  • SKILL.md
  • BENCHMARK.md
  • CAPABILITIES.md
  • SKILLCARD.yaml
  • TASKS.md
  • evals/evals.json
  • skill-card.md
  • skill.oms.sig

Open the folder on GitHubat commit 0e0d506

Compare with similar skills

Doca Dms next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Doca Dms compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Doca Dms this skillNVIDIA/skills3.5k—~2.8kAutomated safety check: PassApache-2.0
Kratos Developmentaide-family/moon253—~1.5kAutomated safety check: PassNone
Nestjs Features Performanceaiskillstore/marketplace430—~3.8kAutomated safety check: PassMIT
Intrinsic Core API Overviewintrinsic-ai/intrinsic-core552—~3.4kAutomated safety check: PassApache-2.0
Intrinsic Core Debuggingintrinsic-ai/intrinsic-core552—~3.8kAutomated safety check: NotesApache-2.0
Intrinsic Core Service Authoringintrinsic-ai/intrinsic-core552—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Kratos Development

    aide-family/moon

    Develops Go microservices with Kratos v2 following official design philosophy, DDD/Clean Architecture layout, Protobuf API, error/config/middleware patterns, and observability.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Nestjs Features Performance

    aiskillstore/marketplace

    Selects and implements NestJS runtime features, error and API contracts, security, testing, DevOps, performance, and safe scale.

    430 GitHub stars~3.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Intrinsic Core API Overview

    intrinsic-ai/intrinsic-core

    Intrinsic Core gRPC service selection, Envoy x-resource-instance-name routing, and progressive disclosure hub across ObjectWorldService, MotionPlannerService, ICON, cameras, KVStore, and platform…

    552 GitHub stars~3.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Intrinsic Core Debugging

    intrinsic-ai/intrinsic-core

    Meta-level debugging workflows, architectural layer isolation, and progressive disclosure routing across Envoy ingress, Kubernetes pods, Behavior Trees, ObjectWorld synchronization, ICON real-time…

    552 GitHub stars~3.8k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Intrinsic Core Service Authoring

    intrinsic-ai/intrinsic-core

    Intrinsic Core microservice authoring, ServiceManifest definitions (realspec vs simspec), RuntimeContext port bindings (gRPC port 1 vs HTTP port 7), SIGTERM lifecycle handling, and .binpb sideloading.

    552 GitHub stars~2.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Performing Cloud Native Forensics With Falco

    mukul975/Anthropic-Cybersecurity-Skills

    Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation.

    34k GitHub stars~635 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from NVIDIA/skills

All 380 skills in this repo
  • Official

    A skill your agent uses when the user wants to deploy, run, debug, tear down, or call the REST API of the RTVI-CV 2D detection / tracking microservice.

    3.5k GitHub starsUsed in 1 repo~4.5k tokens
    Auto-check passed
  • Official

    Generates, validates, compares and explains HOLOLINK_def.svh macro files for the HSB IP, using bundled Python scripts and asking before it writes anything.

    3.5k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Official

    Runs and validates an end-to-end Mission Control demo in a locally installed Isaac Sim, with a Nova Carter robot driven through a Python server.

    3.5k GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Orchestrates defect image generation for PCBA, metal surface and glass inspection with NVIDIA Cosmos AnomalyGen on OSMO, from cold-start Day 0 to real-photo Day 1 labeling.

    3.5k GitHub stars~5k tokensUpdated yesterday
    Auto-check: notes
  • Orchestrates video data augmentation and auto-labeling workflows on OSMO, from flow selection and preflight checks to submission, monitoring and output download.

    3.5k GitHub stars~4.7k tokensUpdated yesterday
    Auto-check: notes
  • Official

    Runs NVIDIA TAO Data Services KPI analysis on object detection results, comparing predictions to ground truth and writing per-class precision, recall and AP to a CSV.

    3.5k GitHub stars~2.7k tokensUpdated yesterday
    Auto-check: notes

Questions about Doca Dms

What does Doca Dms do?

Operate NVIDIA DOCA Management Service (dmsd + dmspe) on a BlueField, Arm/x86 host, or Kubernetes pod: choose deployment and authentication, configure -allowedusers and dmsgroup, use gNMI…. Doca Dms is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Operate NVIDIA DOCA Management Service (dmsd + dmspe) on a BlueField, Arm/x86 host, or Kubernetes pod: choose deployment and authentication, configure -allowedusers and dmsgroup, use gNMI Get/Set/Subscribe, run supported gNOI workflows, and debug frontend/backend failures.

When should I use Doca Dms?

Doca Dms fits situations like: even without DMS for manage a remote BlueField over gRPC; GNOI reboot from orchestrator; fleet-management requests.

How do I install Doca Dms in Claude Code?

Run `npx skills add NVIDIA/skills --skill doca-dms -a claude-code`. Or copy the skill folder (skills/doca-dms in NVIDIA/skills) into .claude/skills/doca-dms in your project. Claude Code loads it when a task matches its description.

How do I install Doca Dms in Codex?

Run `npx skills add NVIDIA/skills --skill doca-dms -a codex`. Or copy the skill folder (skills/doca-dms in NVIDIA/skills) into .agents/skills/doca-dms in your project. Codex loads it when a task matches its description.

Can I use Doca Dms in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/skills --skill doca-dms -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/doca-dms, .gemini/skills/doca-dms, .github/skills/doca-dms and .opencode/skills/doca-dms in your project.

What does Doca Dms need to run?

SKILL.md names no scripts, command-line tools or credentials: Doca Dms is instructions for the agent only. Compatibility (from SKILL.md): DOCA service shipped with the DOCA install at /opt/mellanox/doca on the management endpoint (x86 host (non-DPU), BlueField Arm, or Kubernetes pod) on Linux (Ubuntu 22.04/24.04 or RHEL/SLES); `dmsd` + `dmspe` run there, and DMS is also pulled as an NGC container image. Verify the public DMS guide version matches the installed DOCA release before quoting flags or YANG paths. .

Does Doca Dms access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Doca Dms safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Doca Dms use?

Doca Dms is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Doca Dms use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Doca Dms?

Skills that share tags, products or a category with Doca Dms: Kratos Development (aide-family/moon, 253 stars), Nestjs Features Performance (aiskillstore/marketplace, 430 stars), Intrinsic Core API Overview (intrinsic-ai/intrinsic-core, 552 stars) and Intrinsic Core Debugging (intrinsic-ai/intrinsic-core, 552 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Doca Dms?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/skills, which has 3,534 GitHub stars. The repository holds 380 skills in this directory. The repository was last updated on October 7, 2026.

Source: NVIDIA/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.