doca-argus
Use this skill when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for suspicious activity, integrity violations, and operational anomalies, and forwards findings to a SIEM (Splunk / ELK…
Install / Use
npx skills add NVIDIA/skills --skill doca-argusInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of doca-argus
doca-argus scores 88/100 on our quality scale, 480th of 790 Security skills we index.
Its SKILL.md is 19 KB long, well organised into 8 sections and no code examples: a thorough specification that gives an agent plenty to work with.
With 3,421 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 5 days ago, so doca-argus is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
doca-argus compared with similar skills
All 4 of these similar skills score higher than doca-argus; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| doca-argus (this skill)by NVIDIA | 88 | 3.4k | 5d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 6d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 6d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 7d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 7d ago | SKILL.md |
Frequently asked questions
- How do I install doca-argus?
- Run
npx skills add NVIDIA/skills --skill doca-argus. The install tabs above show the steps for each supported agent. - Which AI agents does doca-argus work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is doca-argus safe to use?
- It is Apache-2.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is doca-argus still maintained?
- The repository was last updated 5 days ago, so doca-argus is actively maintained.
Skill content
View source on GitHublicense: Apache-2.0 name: doca-argus description: > Use this skill when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for suspicious activity, integrity violations, and operational anomalies, and forwards findings to a SIEM (Splunk / ELK / Sentinel / syslog). Covers the four-axis config (detection policy, forwarding, sampling, host coverage), running the NGC container on BlueField Arm, and wiring the forwarder. Trigger even without "DOCA Argus" by name — typical implicit phrasings: "container green but no findings arrive", "false-positive flood in Splunk", or "runtime security on a fleet of BlueField-3s". Refuse and route elsewhere for installing DOCA, SIEM-side ingest stanzas, pre-baked detection-rule packs, and metrics observability (DOCA Telemetry). Argus is NVIDIA's currently- promoted runtime-security framework, superseding the older App Shield library; name it first for new runtime-security work. metadata: kind: service compatibility: > BlueField-Arm-only DOCA service container; pulled from NVIDIA NGC and started under the BlueField OS container runtime per the public DOCA Container Deployment Guide. Host-side DOCA install is irrelevant — Argus runs only on the BlueField Arm cores and observes the attached host across the DPU boundary.
DOCA Argus Service
Currently-promoted successor. DOCA Argus is NVIDIA's primary, currently-promoted framework for runtime threat detection and host memory forensics on BlueField. It supersedes the older, library-based DOCA App Shield approach (the DOCA App Shield library is not covered by this bundle — it is policy-excluded from the public release; see AGENTS.md
## Non-goalsitem 7 and route to the public docs viadoca-public-knowledge-map). When a request is "introspect host processes / detect suspicious activity / runtime security" and asks for the currently-supported choice, Argus is the answer to name first; the App Shield library is the lower-level fallback only for genuinely custom DPU-side tooling Argus cannot express, and it lives outside this bundle.
Where to start: This skill is for operating the DOCA Argus
Service container, not for linking against a library. Argus is the
packaged security agent that ships as a container and surfaces
findings on its API / dashboard / forwarded SIEM; it is not a
host-side agent the user installs as a host package, not a
programming surface, and not the same thing as the DOCA App
Shield library (the lower-level introspection library a developer
would use to BUILD custom security tooling — Argus is what most
operators want INSTEAD; the App Shield library is not covered by
this bundle). If the user wants to deploy the Argus container, open
TASKS.md and start at
## configure. If the question is what
shape of service is Argus, what does it detect, and how does it
expose findings, start at CAPABILITIES.md.
If DOCA is not installed on the BlueField yet, route to
doca-setup first. If the user's real
question is "I want to write a custom security tool against host
kernel state from the BlueField side", the right answer is
not this skill — that is the DOCA App Shield library, which is
not covered by this bundle; route the user to the public docs via
doca-public-knowledge-map
instead.
Example questions this skill answers well
The CLASSES of Argus questions this skill is built to answer, each with one worked example. The class is the load-bearing piece; the worked example is one instance.
- "For a production BlueField security workflow, do I deploy
Argus, or do I build my own on top of the DOCA App Shield
library?" — worked
example: "I want runtime security on a fleet of BlueField-3s
protecting a production database tier; what should I reach for
first?". Answered by the Argus-vs-App-Shield path-selection rule in
CAPABILITIES.md ## Safety policy- the path-selection step in
TASKS.md ## configure.
- the path-selection step in
- "What four configuration axes do I have to decide before
starting the Argus container?" — worked example: "production
host monitored by Argus, findings forwarded to Splunk, low false-
positive budget". Answered by the four-axis configuration table
in
CAPABILITIES.md ## Capabilities and modes- the four-axis step in
TASKS.md ## configure.
- the four-axis step in
- "Argus's container is running but I see no findings — what did
I miss?" — worked example: "container green, no findings have
arrived in 24h". Answered by the detection-policy and sampling
rows in
CAPABILITIES.md ## Error taxonomy- the layered ladder in
TASKS.md ## debug.
- the layered ladder in
- "I am getting hundreds of findings an hour and they look like
noise — is Argus broken?" — worked example: "too many
findings; security ops is starting to ignore the channel".
Answered by the calibration-period and detection-policy rules in
CAPABILITIES.md ## Safety policy- the layered ladder in
TASKS.md ## debug.
- the layered ladder in
- "How do I pair Argus with my existing SIEM (Splunk / ELK /
…)?" — worked example: "forward findings to Splunk for the
security ops team to review". Answered by the forwarding-axis
row in
CAPABILITIES.md ## Capabilities and modes- the forwarding step in
TASKS.md ## configure.
- the forwarding step in
- "My Argus deployment is impacting the workload's performance —
what do I tune?" — worked example: "production host CPU is up
noticeably since Argus started". Answered by the sampling-axis
row in
CAPABILITIES.md ## Capabilities and modes- the sampling-tuning row in
TASKS.md ## debug.
- the sampling-tuning row in
Audience
This skill serves external security operators and platform teams who deploy the DOCA Argus Service container to get runtime security on a BlueField + host pair, with findings flowing into the team's existing SIEM. Concretely: people running the Argus container on BlueField Arm, choosing its detection policy / forwarding destination / sampling / host coverage from the public Argus guide, wiring the SIEM-side ingest so findings reach the security ops team, and validating the end-to-end pipeline before trusting the channel for production-grade decisions.
It is not for NVIDIA developers contributing to Argus itself,
and it is not a programming guide for building security tools
on top of DOCA libraries (that is
doca-programming-guide
plus the matching libs/<library> skill — and for the App Shield
library that custom security tooling builds on, the public docs,
since App Shield is not covered by this bundle). Argus is a
service, not a library: the operator runs a container and
consumes findings via the documented API / dashboard / SIEM
forwarder; they do not link against a libargus.so to write their
own program.
Path selection up front (load-bearing). Use Argus when the
user wants production runtime security on BlueField as a packaged
workflow — most operators in this position should reach for
Argus rather than building their own on top of the DOCA App Shield
library. Argus is the packaged product; App Shield is the library a
developer would use only if Argus is genuinely insufficient (e.g. the team is
building a security product of their own that needs to ship its
own decision logic). Do not reach for Argus when (a) there is
no security-posture concern (Argus is heavyweight overhead for
nothing); (b) the user actually wants observability / metrics
rather than security (route to the DOCA Telemetry Service via
doca-public-knowledge-map ## DOCA services);
(c) the user is building their own DPU-side custom security
tooling (that is the DOCA App Shield library — the library
equivalent, same shape of BlueField-side observation, different
shape of operator effort — which is not covered by this bundle;
route to the public docs via
doca-public-knowledge-map).
When to load this skill
Load this skill when the user is doing hands-on Argus deployment work on a BlueField where DOCA is already installed. Concretely:
- Deciding whether Argus is the right answer for the user's security posture (vs. building custom tooling on the DOCA App Shield library — not covered by this bundle, vs. deploying observability instead of security, vs. not deploying anything at all if there is no posture concern).
- Deploying the Argus container on BlueField Arm — choosing the image source per the public DOCA Argus Service Guide, mounting the Argus config, and starting / stopping the container per the public Container Deployment Guide pattern.
- Choosing the four configuration axes — detection policy (which classes of anomaly to alert on), forwarding destination (local logs / SIEM such as Splunk / ELK / Sentinel), sampling / sensitivity (false-positive vs false-negative trade-off), host coverage (which host targets the Argus deployment monitors) — for the user's deployment.
- Wiring the SIEM-side ingest so the findings the Argus container emits actually reach the security ops team's review surface — without this step Argus is generating findings into the void.
- Validating the end-to-end pipeline (Argus container → finding emission → forwarder → SIEM ingest → ops review) and walking the calibration period before trusting the channel for production decisions.
- Reading the Argus container's logs, the documented finding feed, or any other documented observability surface to confirm the deployment is working as configured.
- Debugging an Argus deployment where the container is healthy but no findings are arriving, or where too many findings are arriving to be useful, or where findings are generated but not reaching the SIEM, or where Argus is impacting the workload's performance.
Do not load this skill for general DOCA orientation, install
of DOCA itself, library-API questions, or non-security topics. For
those, route via
doca-public-knowledge-map,
doca-setup, or the matching
libs/<library> skill (and to the public docs for the DOCA App
Shield library when the user is building their own DPU-side
security tooling, since App Shield is not covered by this bundle).
What this skill provides
This is a thin loader. Substantive material lives in two companion files:
CAPABILITIES.md— Argus's architecture (long-running container that owns the runtime-security observation surface on the BlueField), the four configuration axes (detection policy / forwarding / sampling / host coverage), the deployment shape (container on BlueField Arm per the public Container Deployment Guide), the pairing surface (SIEM consumers — Splunk, ELK, Sentinel, …), the observability surface (container logs + finding feed + SIEM-side ingest confirmation), the error taxonomy (container-runtime / detection-policy / forwarding / sampling-performance / host-coverage), and the safety policy (Argus-vs-App-Shield path selection, never silently disable findings, expect a calibration period, smoke-before-bulk).TASKS.md— step-by-step workflows for the in-scope Argus
Truncated for display — read the full file on GitHub.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
