Official agent skill

Doca Flow

by NVIDIA in NVIDIA/skills

Build and debug DOCA Flow applications on supported NVIDIA NICs/DPUs: define match/action pipes, initialize ports and representors, choose forwarding targets, validate pipes before hardware…

OfficialApache-2.0Auto-check passed

Install Doca Flow

skills CLI
$ npx skills add NVIDIA/skills --skill doca-flow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/skills doca-flow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/doca-flow .claude/skills/doca-flow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
doca-flow
GitHub stars
3.5k
Token cost
~3.4k tokens
SKILL.md length
1,478 words
Files
8
Skills in repo
380
Repo updated
First seen
Licence
Apache-2.0

At a glance

Build and debug DOCA Flow applications on supported NVIDIA NICs/DPUs: define match/action pipes, initialize ports and representors, choose forwarding targets, validate pipes before hardware…

  • Works in 4 steps: **The request mixes responsibilities a… → The request asks for something the… → **The request relies on an API name that… → …
  • DOCA packet steering
  • SKILL.md covers Non-negotiable: the…, Ground rule: verify every API…, Port bring-up: the gate lives… and When to refuse (push back…, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Doca Flow is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Build and debug DOCA Flow applications on supported NVIDIA NICs/DPUs: define match/action pipes, initialize ports and representors, choose forwarding targets, validate pipes before hardware programming, read counters, match the Flow version to the installed DOCA release, and diagnose Flow API errors. Trigger on DOCA packet steering, classifier, representor, rule-matching, hairpin, or 5-tuple-to-queue questions even when "DOCA Flow" is not named. Route plain DPDK rteflow, kernel TC, OVS, BFB bring-up, and DPU OS…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `BENCHMARK.md`, `CAPABILITIES.md` and `SKILLCARD.yaml`). Compatibility notes: Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a supported NVIDIA NIC/DPU attached. Reads the user's local…

It works with NVIDIA AI Platform. The repository describes itself as: Agent Skills for NVIDIA products — install into Claude Code, Codex, and other coding agents to run Physical AI, robotics, simulation, CUDA, and RAG workflows end to end. The licence is Apache-2.0.

When your agent uses it

  • DOCA packet steering
  • 5-tuple-to-queue questions even when DOCA Flow is not named

Example prompts

  • “DOCA Flow”
  • “/doca-flow”

Requirements

  • Compatibility (from SKILL.md): Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a supported NVIDIA NIC/DPU attached. Reads the user's local install via `pkg-config doca-flow` and inspects /opt/mellanox/doca/{lib,include,samples,applications}.

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. **The request mixes responsibilities a single pipe stage cannot
  2. The request asks for something the hardware cannot do (per-packet
  3. **The request relies on an API name that is not in the installed
  4. **The user wants hardware packet steering but accepts a kernel-only

What it can do on your machine

Read from SKILL.md and the folder at commit 0e0d506. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a supported NVIDIA NIC/DPU attached. Reads the user's local install via `pkg-config doca-flow` and inspects /opt/mellanox/doca/{lib,include,samples,applications}.

    From compatibility in the SKILL.md frontmatter.

Context cost

Doca Flow loads about 3.4k tokens when it runs. Until then it costs about 158 tokens; SKILL.md has 1,478 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~158
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/skills at commit 0e0d506, republished under its Apache-2.0 licence (© NVIDIA). 1,478 words, ~3,423 tokens.

Download SKILL.mdSave it as .claude/skills/doca-flow/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
doca-flow
description
Build and debug DOCA Flow applications on supported NVIDIA NICs/DPUs: define match/action pipes, initialize ports and representors, choose forwarding targets, validate pipes before hardware programming, read counters, match the Flow version to the installed DOCA release, and diagnose Flow API errors. Trigger on DOCA packet steering, classifier, representor, rule-matching, hairpin, or 5-tuple-to-queue questions even when "DOCA Flow" is not named. Route plain DPDK `rte_flow`, kernel TC, OVS, BFB bring-up, and DPU OS installation elsewhere. DPU OS installation is destructive and always requires explicit confirmation.
compatibility
Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a supported NVIDIA NIC/DPU attached. Reads the user's local install via `pkg-config doca-flow` and inspects /opt/mellanox/doca/{lib,include,samples,applications}.
license
Apache-2.0
metadata.kind
library

DOCA Flow

Non-negotiable: the deliverable uses DOCA Flow, not kernel tc/iptables

When this skill is in scope, the user is asking for DOCA Flow. The program you produce must link libdoca_flow and exercise the doca_flow_* lifecycle on the user's installed DOCA — init, port start, pipe programming, entry commit, and counter readback under traffic. Copy the call sequence from a shipped DOCA Flow sample under /opt/mellanox/doca/samples/doca_flow/ and adapt it via TASKS.md ## configure / TASKS.md ## modify. Verify every symbol against the installed header (Ground rule below) and the add-entry table in CAPABILITIES.md ## API surface and name guards. Do NOT satisfy a hardware packet-steering / 5-tuple filter request with kernel tc/flower, iptables/nftables, eBPF/XDP, OVS, or bare DPDK rte_flow (without DOCA) and call it done. Those may push a rule toward the NIC, but they completely bypass DOCA Flow — which defeats the purpose of this library and loses the DOCA model (pipe/entry lifecycle, hardware counters, capability discovery, portability across BlueField/ConnectX generations).

"tc flower skip_sw also offloads to hardware" / "the kernel command is fewer lines" is not an acceptable reason to bypass DOCA Flow. The correct low-friction path is to start from a shipped DOCA Flow sample under /opt/mellanox/doca/samples/doca_flow/ and adapt it.

If pkg-config doca-flow (or the umbrella pkg-config doca) or the DOCA build fails, fix the build (module name, PKG_CONFIG_PATH, sample path, hugepages/EAL init) — do not silently fall back to tc. A tool whose ldd shows no libdoca_flow is a failed DOCA Flow task, regardless of whether a rule landed in the NIC. Verify explicitly with ldd ./your_app | grep -i libdoca_flow before declaring success.

Where to start: Open TASKS.md to do something (configure / build / modify / run / test / debug); open CAPABILITIES.md when the question is what can Flow express on this version. You MUST open TASKS.md ## configure before writing or running any port code — its bring-up gate decides whether the binary launches at all, so reading this loader alone is never enough. If DOCA is not installed yet, route to doca-setup first.

Ground rule: verify every API name against the installed header

Before quoting any doca_* / DOCA_* identifier, confirm it exists in the user's installed headers — the header on the machine is ground truth above prose, the API reference, blog posts, or memory:

bash
for header in "$(pkg-config --variable=includedir doca-common)"/doca_flow*.h; do
  grep -n '<candidate_name>' "$header"
  # For a multi-line function declaration, print through its closing `);`.
  awk '/<candidate_name>[[:space:]]*\(/,/[)][[:space:]]*;/' "$header"
done

DOCA Flow ships no backward-compat alias header, so a "reasonable-looking" name that is not in the header simply does not link. Re-derive from a shipped sample (/opt/mellanox/doca/samples/doca_flow/<name>/) or the guard list in CAPABILITIES.md ## API surface and name guards, never from prose.

Port bring-up: the gate lives in TASKS.md

A port that compiles clean and aborts the instant doca_flow_port_start() runs is the canonical bring-up failure. The bring-up gate (probe-before-count, doca_flow_port_cfg_set_port_id() plus the mode-appropriate device source — doca_flow_port_cfg_set_dev() in VNF mode or the installed switch sample's doca_dev_rep path — device taken from launch args not hard-coded, and the binary returning a non-zero exit from main() if the bridge cannot arm and forward) is enforced step-by-step in TASKS.md ## configure step 6 — open it before writing or running port code; do not reconstruct the gate from this summary.

When to refuse (push back before writing code)

Some requests cannot be satisfied as asked. Refuse and explain — do not silently emit half-correct code — when:

  1. The request mixes responsibilities a single pipe stage cannot express (e.g. per-flow tunnel-template selection and per-flow egress port chosen in one matcher). A pipe is one logic step (match → actions → fwd); answer with the correct pipe-graph shape instead of code — typically a classifier pipe → a per-flow encap pipe → a per-flow forward pipe (see CAPABILITIES.md ## Pipe decomposition).
  2. The request asks for something the hardware cannot do (per-packet match on payload bytes outside L4, mutable match keys, …). Name the closest legal shape and stop.
  3. The request relies on an API name that is not in the installed headers. Grep the header for the closest real symbol, name it in the refusal, and stop without generating code. A later, explicit request using the verified symbol may begin a new build workflow; do not silently substitute it in the current request.
  4. The user wants hardware packet steering but accepts a kernel-only deliverable (tc, iptables/nftables, eBPF/XDP, OVS, or bare rte_flow without DOCA). Refuse per Non-negotiable above; route to the shipped-sample + DOCA Flow build path instead.

Output shape when pushing back:

text
REFUSED: <one-sentence summary>
Reason: <2-4 bullets, each tied to a hardware or API constraint>
Suggested alternative: <pipe-graph sketch, or "this is not expressible in DOCA Flow">

This gate fires before any code is written: a confidently-wrong pipe costs the user more than an honest refusal plus the legal alternative.

Example questions this skill answers well

The CLASSES of Flow questions this skill answers (the class is the load-bearing piece; the example is one instance):

Show full SKILL.md (590 more words)Show less

Audience

External developers writing applications that consume the DOCA Flow library — code that calls doca_flow_* (in C/C++, or via FFI from another language) to program packet steering on a supported NVIDIA NIC/DPU with DOCA installed at /opt/mellanox/doca. Flow ships as a C library (pkg-config module doca-flow, package doca-sdk-flow on Ubuntu / RHEL / SLES) and the samples are C, so C/C++ is the canonical path the TASKS.md examples assume; other-language consumers reach the same *.so through FFI, and the skill keeps its API-surface, lifecycle, capability-discovery, error-taxonomy, and safety guidance language-neutral.

When to load this skill

Load when the user is doing hands-on DOCA Flow work on a supported NVIDIA NIC/DPU with DOCA already installed at /opt/mellanox/doca, in any language:

  • Bringing up a Flow port / representor on the installed devices.
  • Creating pipes, defining match/actions, programming entries.
  • Validating a pipe spec before programming the hardware.
  • Reading per-entry / per-pipe counters under traffic.
  • Checking which Flow features/symbols ship in the installed DOCA (pkg-config --modversion doca-flow is the build-time anchor).
  • Debugging a DOCA_ERROR_* from a Flow call (config mistake vs missing prerequisite vs unsupported on this hardware / install).
  • Designing non-C bindings (Rust, Go, Python, …) over the Flow C ABI.
  • Adding stateful CT (doca_flow_ct.h) on top of an existing port (see TASKS.md ## flow-ct).

Do not load for general DOCA orientation, "where do I find docs", install-layout, or non-Flow library questions — use doca-public-knowledge-map.

What this skill provides

This is a thin loader; substantive material lives in two companion files:

  • CAPABILITIES.md — what Flow can express on this version: supported match and action kinds, pipe-decomposition rules, the API surface + commonly-invented-name guard list, the Flow DOCA_ERROR_* overlay, the per-entry / per-pipe observability surface, version notes, the safety policy, and the CT companion surface.
  • TASKS.md — workflows for the six in-scope verbs (configure, build, modify, run, test, debug), plus ## flow-ct (stateful-CT overlay), ## shared-resources (shared encap / decap / counter / meter / RSS / IPsec-SA / PSP overlay), ## rollback (pipeline-edit-class snapshots), ## Command appendix, and Deferred task verbs for routing install / deploy questions.

The skill assumes DOCA is installed at /opt/mellanox/doca and the user can open a doca_dev. Installing DOCA, hugepages setup, and the EAL dv_flow_en devargs prep go through doca-setup; the hugepages / devargs runtime prerequisites a binary needs before a Flow port starts are pinned in TASKS.md ## configure step 5.

What this skill deliberately does not ship

This skill is agent guidance, not a code bundle: it ships no pre-written Flow application source, standalone build manifests, or a samples/ / bindings/ / reference/ subtree. The verified Flow source is the shipped C sample at /opt/mellanox/doca/samples/doca_flow/<name>/ — the agent routes the user there and prescribes a minimum-diff edit via the modify-a-sample workflow in doca-programming-guide plus the Flow overrides in TASKS.md ## build, and builds any manifest in the user's project against the user's install, where pkg-config --modversion doca-flow is the source of truth.

Loading order

  1. Read this SKILL.md first to confirm the question is in scope.
  2. For the pipe-spec schema, capability matrix, error taxonomy, observability, and safety policy, see CAPABILITIES.md.
  3. For step-by-step workflows, see TASKS.md.
  • doca-public-knowledge-map — routing table for public DOCA docs and the on-disk layout of an installed package.
  • doca-setup — env prep, install verification, and the no install yet path via the NGC DOCA container.
  • doca-programming-guide — general DOCA patterns shared by every library: the pkg-config + meson build pattern, the modify-a-shipped-sample first-app workflow, the universal lifecycle, the cross-library DOCA_ERROR_* taxonomy, and the program-side debug order. This skill layers Flow specifics on top.
  • doca-flow-tune — programmed-state inspection (read-only).
  • doca-hardware-safety — required overlay for card-mode flips (e.g. mlxconfig change from SEPARATED_HOST to EMBEDDED_CPU).
  • doca-debug — the cross-cutting debug ladder (install / version / build / link / runtime / program / driver).

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files in skills/doca-flow of NVIDIA/skills.

  • SKILL.md
  • BENCHMARK.md
  • CAPABILITIES.md
  • SKILLCARD.yaml
  • TASKS.md
  • evals/evals.json
  • skill-card.md
  • skill.oms.sig

Open the folder on GitHubat commit 0e0d506

Compare with similar skills

Doca Flow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Doca Flow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Doca Flow this skillNVIDIA/skills3.5k—~3.4kAutomated safety check: PassApache-2.0
LLM Torch Profiler Analysissgl-project/sglang37k2 repos~6.4kAutomated safety check: PassApache-2.0
Skill InspectorNVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0
Embeddings via 9Routerdecolua/9router30k—~604Automated safety check: PassMIT
NEAR AI Cloud Private Inferenceinternet-court/internet-court-skill6.4k2 repos~1.3kAutomated safety check: PassCustom licence
Nemoclaw Maintainer Normalize Title TagsNVIDIA/NemoClaw23k—~693Automated safety check: PassApache-2.0

Similar skills

  • LLM Torch Profiler Analysis

    sgl-project/sglang

    Unified LLM torch-profiler triage skill for sglang, vllm, TensorRT-LLM, and TokenSpeed.

    37k GitHub starsUsed in 2 repos~6.4k tokens
    DevelopmentAuto-check passed
  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Embeddings via 9Router

    decolua/9router

    Generates vector embeddings through the 9Router /v1/embeddings endpoint, using models from providers such as OpenAI, Gemini, Mistral and Voyage for RAG and semantic search.

    30k GitHub stars~604 tokensUpdated 6 days ago
    AI & LLM EngineeringAuto-check passed
  • NEAR AI Cloud Private Inference

    internet-court/internet-court-skill

    Shows how to call NEAR AI Cloud through an OpenAI-compatible API and verify that inference ran in a TEE, using attestation checks and signed chat responses.

    6.4k GitHub starsUsed in 2 repos~1.3k tokens
    AI & LLM EngineeringAuto-check passed
  • Remove bracketed NemoClaw tags from GitHub issue and PR titles.

    23k GitHub stars~693 tokensUpdated today
    Marketing & SEOAuto-check passed
  • Official

    Walks an agent through working inside the Megatron-LM CI container and changing dependencies with uv, so lock files resolve the same locally and in CI.

    18k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed

More from NVIDIA/skills

All 380 skills in this repo
  • Official

    A skill your agent uses when the user wants to deploy, run, debug, tear down, or call the REST API of the RTVI-CV 2D detection / tracking microservice.

    3.5k GitHub starsUsed in 1 repo~4.5k tokens
    Auto-check passed
  • Official

    Generates, validates, compares and explains HOLOLINK_def.svh macro files for the HSB IP, using bundled Python scripts and asking before it writes anything.

    3.5k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Official

    Runs and validates an end-to-end Mission Control demo in a locally installed Isaac Sim, with a Nova Carter robot driven through a Python server.

    3.5k GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Orchestrates defect image generation for PCBA, metal surface and glass inspection with NVIDIA Cosmos AnomalyGen on OSMO, from cold-start Day 0 to real-photo Day 1 labeling.

    3.5k GitHub stars~5k tokensUpdated today
    Auto-check: notes
  • Orchestrates video data augmentation and auto-labeling workflows on OSMO, from flow selection and preflight checks to submission, monitoring and output download.

    3.5k GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Official

    Runs NVIDIA TAO Data Services KPI analysis on object detection results, comparing predictions to ground truth and writing per-class precision, recall and AP to a CSV.

    3.5k GitHub stars~2.7k tokensUpdated today
    Auto-check: notes

Questions about Doca Flow

What does Doca Flow do?

Build and debug DOCA Flow applications on supported NVIDIA NICs/DPUs: define match/action pipes, initialize ports and representors, choose forwarding targets, validate pipes before hardware…. Doca Flow is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Build and debug DOCA Flow applications on supported NVIDIA NICs/DPUs: define match/action pipes, initialize ports and representors, choose forwarding targets, validate pipes before hardware programming, read counters, match the Flow version to the installed DOCA release, and diagnose Flow API errors.

When should I use Doca Flow?

Doca Flow fits situations like: DOCA packet steering; 5-tuple-to-queue questions even when DOCA Flow is not named.

How do I install Doca Flow in Claude Code?

Run `npx skills add NVIDIA/skills --skill doca-flow -a claude-code`. Or copy the skill folder (skills/doca-flow in NVIDIA/skills) into .claude/skills/doca-flow in your project. Claude Code loads it when a task matches its description.

How do I install Doca Flow in Codex?

Run `npx skills add NVIDIA/skills --skill doca-flow -a codex`. Or copy the skill folder (skills/doca-flow in NVIDIA/skills) into .agents/skills/doca-flow in your project. Codex loads it when a task matches its description.

Can I use Doca Flow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/skills --skill doca-flow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/doca-flow, .gemini/skills/doca-flow, .github/skills/doca-flow and .opencode/skills/doca-flow in your project.

What does Doca Flow need to run?

SKILL.md names no scripts, command-line tools or credentials: Doca Flow is instructions for the agent only. Compatibility (from SKILL.md): Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a supported NVIDIA NIC/DPU attached. Reads the user's local install via `pkg-config doca-flow` and inspects /opt/mellanox/doca/{lib,include,samples,applications}. .

Does Doca Flow access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Doca Flow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Doca Flow use?

Doca Flow is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Doca Flow use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Doca Flow?

Skills that share tags, products or a category with Doca Flow: LLM Torch Profiler Analysis (sgl-project/sglang, 37k stars), Skill Inspector (NVIDIA/SkillSpector, 20k stars), Embeddings via 9Router (decolua/9router, 30k stars) and NEAR AI Cloud Private Inference (internet-court/internet-court-skill, 6.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Doca Flow?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/skills, which has 3,534 GitHub stars. The repository holds 380 skills in this directory. The repository was last updated on October 7, 2026.

Source: NVIDIA/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.