Official agent skill

Doca Sha

by NVIDIA in NVIDIA/skills

A skill your agent uses when the user is doing hands-on DOCA SHA programming — offloading SHA-1, SHA-256, or SHA-512 hashing onto a BlueField DPU or ConnectX accelerator, picking between one-shot…

OfficialApache-2.0Auto-check passedSecurity

Install Doca Sha

skills CLI
$ npx skills add NVIDIA/skills --skill doca-sha -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/skills doca-sha --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/doca-sha .claude/skills/doca-sha && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
doca-sha
GitHub stars
3.5k
Token cost
~3.4k tokens
SKILL.md length
1,441 words
Files
8
Skills in repo
380
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user is doing hands-on DOCA SHA programming — offloading SHA-1, SHA-256, or SHA-512 hashing onto a BlueField DPU or ConnectX accelerator, picking between one-shot…

  • Works in 3 steps: Read this SKILL.md first to confirm the… → **For the SHA capability matrix,… → **For step-by-step workflows —…
  • The user is doing hands-on DOCA SHA programming — offloading SHA-1
  • SKILL.md covers Example questions this skill…, Audience, When to load this skill and What this skill provides, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Doca Sha is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Use this skill when the user is doing hands-on DOCA SHA programming — offloading SHA-1, SHA-256, or SHA-512 hashing onto a BlueField DPU or ConnectX accelerator, picking between one-shot docashataskhash and incremental docashataskpartialhash, querying docashacap for algorithm support and min destination / max source buffer sizes, setting source / destination docammap permissions, or decoding DOCAERROR returns from the SHA API. Trigger even when the user does not explicitly mention "DOCA SHA" or "docashatask" —…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `BENCHMARK.md`, `CAPABILITIES.md` and `SKILLCARD.yaml`). Compatibility notes: Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the user's…

It sits in Security, covering Cryptography. The repository describes itself as: Agent Skills for NVIDIA products — install into Claude Code, Codex, and other coding agents to run Physical AI, robotics, simulation, CUDA, and RAG workflows end to end. The licence is Apache-2.0.

When your agent uses it

  • The user is doing hands-on DOCA SHA programming — offloading SHA-1
  • SHA-512 hashing onto a BlueField DPU
  • ConnectX accelerator
  • Picking between one-shot docashataskhash and incremental docashataskpartialhash

Example prompts

  • “DOCA SHA”
  • “docashatask”
  • “hash a multi-GiB file on the DPU”
  • “/doca-sha”

Requirements

  • Compatibility (from SKILL.md): Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the user's local install via `pkg-config doca-sha` and inspects /opt/mellanox/doca/{lib,include,samples,applications}.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read this SKILL.md first to confirm the user's question is in
  2. **For the SHA capability matrix, algorithm enums, one-shot vs
  3. **For step-by-step workflows — configure, build, modify, run,

What it can do on your machine

Read from SKILL.md and the folder at commit 67a13c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the user's local install via `pkg-config doca-sha` and inspects /opt/mellanox/doca/{lib,include,samples,applications}.

    From compatibility in the SKILL.md frontmatter.

Context cost

Doca Sha loads about 3.4k tokens when it runs. Until then it costs about 257 tokens; SKILL.md has 1,441 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~257
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/skills at commit 67a13c0, republished under its Apache-2.0 licence (© NVIDIA). 1,441 words, ~3,411 tokens.

Download SKILL.mdSave it as .claude/skills/doca-sha/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
doca-sha
description
Use this skill when the user is doing hands-on DOCA SHA programming — offloading SHA-1, SHA-256, or SHA-512 hashing onto a BlueField DPU or ConnectX accelerator, picking between one-shot `doca_sha_task_hash` and incremental `doca_sha_task_partial_hash`, querying `doca_sha_cap_*` for algorithm support and min destination / max source buffer sizes, setting source / destination `doca_mmap` permissions, or decoding DOCA_ERROR_* returns from the SHA API. Trigger even when the user does not explicitly mention "DOCA SHA" or "doca_sha_task" — typical implicit phrasings include "hash a multi-GiB file on the DPU", "offload SHA-256 to the BlueField", "streaming hash over chunks", "partial hash returns BAD_STATE", "destination buffer too small for digest", or "is SHA-512 available on this card". Refuse and route elsewhere for general cryptographic-hash theory (collision resistance, SHA-3 selection), other DOCA crypto libraries (AES-GCM, Compress, DMA), or DOCA install / BFB bring-up — those belong to other skills.
compatibility
Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the user's local install via `pkg-config doca-sha` and inspects /opt/mellanox/doca/{lib,include,samples,applications}.
license
Apache-2.0
metadata.kind
library

DOCA SHA

Where to start: This skill assumes DOCA is already installed and the user is doing hands-on SHA-acceleration work on a BlueField / ConnectX / host with DOCA. Open TASKS.md if the user wants to do something (configure / build / modify / run / test / debug); open CAPABILITIES.md when the question is what can DOCA SHA express on this version. If the user has not installed DOCA yet, route to doca-setup first. If the user is asking "should I even use the accelerator for this hash?", the path-selection rule in CAPABILITIES.md ## Capabilities and modes is the first stop.

Example questions this skill answers well

The CLASSES of DOCA SHA questions this skill is built to answer, each with one worked example. The agent should treat the class as the load-bearing piece — the worked example is a single instance.

  • "Should I offload this hash to DOCA SHA, or just compute it on the CPU?" — worked example: "I am verifying file integrity on a 4 GiB image; is doca-sha worth the setup vs OpenSSL on the CPU?". Answered by the path-selection table in CAPABILITIES.md ## Capabilities and modes
  • "Does my device support the SHA algorithm I want?" — worked example: "is SHA-256 in the accelerator on this BlueField, and what is the minimum destination buffer size for it?". Answered by the algorithm + buffer-sizing capability-query rule (doca_sha_cap_task_hash_get_supported(devinfo, algorithm) for the one-shot path; _task_partial_hash_get_supported(devinfo, algorithm) for the partial-hash path; doca_sha_cap_get_min_dst_buf_size, doca_sha_cap_get_max_src_buf_size) in CAPABILITIES.md ## Capabilities and modes
  • "How do I pick between the one-shot and the partial / incremental hash task?" — worked example: "my input is 1 GiB and the device cap says max source buffer is 64 MiB". Answered by the one-shot-vs-partial table in CAPABILITIES.md ## Capabilities and modes
  • "What permissions does the source / destination mmap need?" — worked example: "my doca_sha_task_hash returns DOCA_ERROR_NOT_PERMITTED". Answered by the permission matrix in CAPABILITIES.md ## Safety policy
  • "Is this DOCA SHA API available on my installed DOCA version?" — worked example: "is doca_sha_task_partial_hash in the DOCA I have installed?". Answered by the version-compatibility overlay in CAPABILITIES.md ## Version compatibility, which cross-links the canonical detection chain in doca-version and adds the SHA-specific "discover, do not assume" bullets.
  • "What does this DOCA_ERROR_* from a SHA call mean and which layer caused it?" — worked example: "DOCA_ERROR_INVALID_VALUE on doca_sha_task_hash_alloc_init". Answered by the SHA overlay on the cross-library taxonomy in CAPABILITIES.md ## Error taxonomy

Audience

This skill serves external developers building applications that consume the DOCA SHA library — i.e., users whose code calls doca_sha_* (directly in C/C++, or through FFI/bindings from another language) to offload SHA hashing onto a BlueField DPU or ConnectX accelerator. It is not for NVIDIA developers contributing to DOCA SHA itself.

Language scope. DOCA SHA ships as a C library with pkg-config module name doca-sha. The shipped samples are written in C. C and C++ consumers are the canonical case and the worked examples in TASKS.md assume that path. Other-language consumers (Rust, Go, Python, …) consume the same *.so through FFI or language-specific bindings; the skill's contribution in that case is to keep the lifecycle, capability-discovery, permission, error-taxonomy, and one-shot-vs-partial guidance language-neutral, and to route the agent to the public C ABI as the authoritative surface that any wrapper will eventually call.

When to load this skill

Load this skill when the user is doing hands-on DOCA SHA work, in any language. Concretely:

  • Initializing a doca_sha context on a doca_dev and configuring at least one task type (doca_sha_task_hash and/or doca_sha_task_partial_hash) before doca_ctx_start().
  • Choosing between the one-shot task (doca_sha_task_hash — input fits in a single source buffer, output digest lands in a single destination buffer) and the partial / incremental task (doca_sha_task_partial_hash — input streamed in chunks, finalized separately) for the user's data shape.
  • Setting permissions on doca_mmap correctly for the source buffer (DOCA_ACCESS_FLAG_LOCAL_READ_ONLY at minimum) and the destination buffer (DOCA_ACCESS_FLAG_LOCAL_READ_WRITE).
  • Sizing the destination buffer against doca_sha_cap_get_min_dst_buf_size(devinfo, algorithm) and the source buffer against doca_sha_cap_get_max_src_buf_size(devinfo).
  • Checking which SHA algorithm enums (DOCA_SHA_ALGORITHM_SHA1, DOCA_SHA_ALGORITHM_SHA256, DOCA_SHA_ALGORITHM_SHA512) the active device's accelerator advertises, via doca_sha_cap_task_hash_get_supported(devinfo, algorithm) and doca_sha_cap_task_partial_hash_get_supported(devinfo, algorithm) — both fold task-support and algorithm-support into one call.
  • Validating a digest against a published test vector before pushing bulk input through the accelerator.
  • Debugging a DOCA_ERROR_* returned from a SHA call (lifecycle vs. buffer-sizing vs. permission vs. unsupported-algorithm) and the task-completion event on the progress engine.
  • Designing or extending non-C bindings (Rust, Go, Python, …) that wrap the SHA C ABI — for the lifecycle, permission, capability, and one-shot-vs-partial rules the wrapper must honor.

Do not load this skill for general DOCA orientation, install of DOCA itself, non-SHA hashing libraries on CPU (use OpenSSL or similar), or other DOCA libraries. For those, use doca-public-knowledge-map.

Show full SKILL.md (653 more words)Show less

What this skill provides

This is a thin loader. The body keeps only the orientation needed to pick the right next file. The substantive SHA-specific material lives in two companion files:

  • CAPABILITIES.md — what DOCA SHA can express on this version: the two task types (one-shot hash and partial / incremental hash), the three algorithm enums, the capability-query surface (doca_sha_cap_* for algorithm support and buffer sizing), the SHA error taxonomy (mapped onto the cross-library DOCA_ERROR_* set), the observability surface (per-task completion events on the progress engine), the safety policy that gates source / destination mmap permission decisions, and the path-selection rule (when to use doca-sha versus a CPU hash or a different DOCA crypto library).
  • TASKS.md — step-by-step workflows for the six in-scope SHA verbs: configure, build, modify, run, test, debug. Plus a Deferred task verbs block that points out-of-scope questions at the right next skill.

The skill assumes a host or BlueField where DOCA is already installed at the standard location and the user has the privileges their public install profile expects. It does not cover installing DOCA — that path goes through doca-setup.

What this skill deliberately does not ship

This skill is agent guidance, not a samples or templates bundle. To keep the boundary clean, it deliberately does not contain — and pull requests should not add:

  • Pre-written DOCA SHA application source code, in any language. The verified SHA source code is the shipped C samples at /opt/mellanox/doca/samples/doca_sha/, plus the File Integrity reference application linked from the public DOCA SHA guide. The agent's job is to route the user to those files and prescribe a minimum-diff modification on them via the universal modify-a-sample workflow in doca-programming-guide, layered with the SHA-specific overrides in TASKS.md ## modify.
  • Pre-computed digest tables for arbitrary inputs. The skill tells the agent to use a published test vector (e.g. the NIST SHA test vectors for the empty string, "abc", and the million-a input) as the known-vector smoke; it does not ship a vector bank of its own.
  • Standalone build manifests (meson.build, CMakeLists.txt, Cargo.toml, …) parked inside the skill. The agent constructs the build manifest in the user's project directory against the user's installed DOCA, where pkg-config --modversion doca-sha is the source of truth.
  • A samples/, bindings/, or reference/ subtree of any kind. A mock or incomplete artifact in this skill's tree, even one labeled "reference", is misleading: users will read it as buildable.

Loading order

  1. Read this SKILL.md first to confirm the user's question is in scope.
  2. For the SHA capability matrix, algorithm enums, one-shot vs partial task split, capability-query rules, permission matrix, error taxonomy, observability, and safety / path-selection policy, see CAPABILITIES.md.
  3. For step-by-step workflows — configure, build, modify, run, test, debug — see TASKS.md.

Both companion files cross-link to each other, doca-version for the canonical version-handling rules, and doca-public-knowledge-map whenever the right answer is "look it up in the public docs or the installed package layout" rather than "SHA-specific guidance".

  • doca-public-knowledge-map — the routing table for every public DOCA documentation source and the on-disk layout of an installed DOCA package. The DOCA SHA page lives at docs.nvidia.com/doca/sdk/DOCA-SHA/; the File Integrity reference application is the canonical worked example.
  • doca-setup — env preparation, install verification, and the I have no install yet path with the public NGC DOCA container. This skill assumes its preconditions are satisfied.
  • doca-version — canonical DOCA version-handling rules. This skill's ## Version compatibility cross-links the four-way match rule and adds only the SHA-specific "discover algorithms + buffer sizes via cap query" overlay.
  • doca-structured-tools-contract — the bundle's structured-tools precedence rule (detect / prefer / fall back / report). The Command appendix in TASKS.md honors this contract.
  • doca-programming-guide — general DOCA programming patterns shared by every library: the canonical pkg-config + meson build pattern, the universal modify-a-shipped-sample first-app workflow, the universal lifecycle, the cross-library DOCA_ERROR_* taxonomy, and the program-side debug order. This skill layers SHA specifics on top.
  • doca-debug — the cross-cutting debug ladder (install / version / build / link / runtime / program / driver). SHA-specific debug (algorithm-not-supported, destination-buffer-too-small, partial-hash-out-of-order) overlays on top of that ladder.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files in skills/doca-sha of NVIDIA/skills.

  • SKILL.md
  • BENCHMARK.md
  • CAPABILITIES.md
  • SKILLCARD.yaml
  • TASKS.md
  • evals/evals.json
  • skill-card.md
  • skill.oms.sig

Open the folder on GitHubat commit 67a13c0

Compare with similar skills

Doca Sha next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Doca Sha compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Doca Sha this skillNVIDIA/skills3.5k—~3.4kAutomated safety check: PassApache-2.0
Bom Explorecdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0
Webcrypt MCPputervision/state-memory-mcp111—~847Automated safety check: PassMIT
Security Reviewvalory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.0
Hashcat Password Recovery WorkflowAgentSecOps/SecOpsAgentKit2201 repos~3.3kAutomated safety check: NotesCustom licence
Altllm Portal Authinternet-court/internet-court-skill6.4k1 repos~632Automated safety check: PassISC

Similar skills

  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    111 GitHub stars~847 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Security Review

    valory-xyz/open-autonomy

    Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

    129 GitHub stars~11k tokensUpdated 23 days ago
    SecurityAuto-check: notes
  • Hashcat Password Recovery Workflow

    AgentSecOps/SecOpsAgentKit

    Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.

    220 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check: notes
  • Altllm Portal Auth

    internet-court/internet-court-skill

    A skill your agent uses when the user asks to log in or out with a wallet session, fetch a wallet sign-in challenge, verify an externally signed challenge, or troubleshoot AltLLM Portal wallet login…

    6.4k GitHub starsUsed in 1 repo~632 tokens
    SecurityAuto-check passed
  • Crypto Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

    386 GitHub stars~2.2k tokensUpdated 10 days ago
    SecurityAuto-check passed

More from NVIDIA/skills

All 380 skills in this repo
  • Official

    A skill your agent uses when the user wants to deploy, run, debug, tear down, or call the REST API of the RTVI-CV 2D detection / tracking microservice.

    3.5k GitHub starsUsed in 1 repo~4.5k tokens
    Auto-check passed
  • Official

    Generates, validates, compares and explains HOLOLINK_def.svh macro files for the HSB IP, using bundled Python scripts and asking before it writes anything.

    3.5k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Official

    Runs and validates an end-to-end Mission Control demo in a locally installed Isaac Sim, with a Nova Carter robot driven through a Python server.

    3.5k GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Orchestrates defect image generation for PCBA, metal surface and glass inspection with NVIDIA Cosmos AnomalyGen on OSMO, from cold-start Day 0 to real-photo Day 1 labeling.

    3.5k GitHub stars~5k tokensUpdated today
    Auto-check: notes
  • Orchestrates video data augmentation and auto-labeling workflows on OSMO, from flow selection and preflight checks to submission, monitoring and output download.

    3.5k GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Official

    Runs NVIDIA TAO Data Services KPI analysis on object detection results, comparing predictions to ground truth and writing per-class precision, recall and AP to a CSV.

    3.5k GitHub stars~2.7k tokensUpdated today
    Auto-check: notes

Categories

Questions about Doca Sha

What does Doca Sha do?

A skill your agent uses when the user is doing hands-on DOCA SHA programming — offloading SHA-1, SHA-256, or SHA-512 hashing onto a BlueField DPU or ConnectX accelerator, picking between one-shot…. Doca Sha is an agent skill from NVIDIA/skills, published by the product's own GitHub organization. Use this skill when the user is doing hands-on DOCA SHA programming — offloading SHA-1, SHA-256, or SHA-512 hashing onto a BlueField DPU or ConnectX accelerator, picking between one-shot docashataskhash and incremental docashataskpartialhash, querying docashacap for algorithm support and min destination / max source buffer sizes, setting source / destination docammap permissions, or decoding DOCAERROR returns from the SHA API.

When should I use Doca Sha?

Doca Sha fits situations like: the user is doing hands-on DOCA SHA programming — offloading SHA-1; SHA-512 hashing onto a BlueField DPU; connectX accelerator; picking between one-shot docashataskhash and incremental docashataskpartialhash.

How do I install Doca Sha in Claude Code?

Run `npx skills add NVIDIA/skills --skill doca-sha -a claude-code`. Or copy the skill folder (skills/doca-sha in NVIDIA/skills) into .claude/skills/doca-sha in your project. Claude Code loads it when a task matches its description.

How do I install Doca Sha in Codex?

Run `npx skills add NVIDIA/skills --skill doca-sha -a codex`. Or copy the skill folder (skills/doca-sha in NVIDIA/skills) into .agents/skills/doca-sha in your project. Codex loads it when a task matches its description.

Can I use Doca Sha in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/skills --skill doca-sha -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/doca-sha, .gemini/skills/doca-sha, .github/skills/doca-sha and .opencode/skills/doca-sha in your project.

What does Doca Sha need to run?

SKILL.md names no scripts, command-line tools or credentials: Doca Sha is instructions for the agent only. Compatibility (from SKILL.md): Requires DOCA SDK installed at /opt/mellanox/doca on Linux (Ubuntu 22.04/24.04 or RHEL/SLES) with a BlueField DPU or ConnectX NIC attached. Reads the user's local install via `pkg-config doca-sha` and inspects /opt/mellanox/doca/{lib,include,samples,applications}. .

Does Doca Sha access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Doca Sha safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Doca Sha use?

Doca Sha is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Doca Sha use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Doca Sha?

Skills that share tags, products or a category with Doca Sha: Bom Explore (cdxgen/cdxgen, 1.1k stars), Webcrypt MCP (putervision/state-memory-mcp, 111 stars), Security Review (valory-xyz/open-autonomy, 129 stars) and Hashcat Password Recovery Workflow (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Doca Sha?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/skills, which has 3,539 GitHub stars. The repository holds 380 skills in this directory. The repository was last updated on October 7, 2026.

Source: NVIDIA/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.