[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-nvidia-doca-argus":3,"mdc--8hnlwf-key":31,"related-repo-nvidia-doca-argus":1255,"related-org-nvidia-doca-argus":1359},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":11,"stars":20,"repoUrl":21,"updatedAt":22,"license":23,"forks":24,"topics":25,"repo":26,"sourceUrl":29,"mdContent":30},"doca-argus","deploy and operate DOCA Argus security services","Use this skill when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for suspicious activity, integrity violations, and operational anomalies, and forwards findings to a SIEM (Splunk \u002F ELK \u002F Sentinel \u002F syslog). Covers the four-axis config (detection policy, forwarding, sampling, host coverage), running the NGC container on BlueField Arm, and wiring the forwarder. Trigger even without \"DOCA Argus\" by name — typical implicit phrasings: \"container green but no findings arrive\", \"false-positive flood in Splunk\", or \"runtime security on a fleet of BlueField-3s\". Refuse and route elsewhere for installing DOCA, SIEM-side ingest stanzas, pre-baked detection-rule packs, and metrics observability (DOCA Telemetry). Argus is NVIDIA's currently- promoted runtime-security framework, superseding the older App Shield library; name it first for new runtime-security work.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},"nvidia","NVIDIA","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Fnvidia.png",[12,16,19],{"name":13,"slug":14,"type":15},"Security","security","tag",{"name":17,"slug":18,"type":15},"Operations","operations",{"name":9,"slug":8,"type":15},2473,"https:\u002F\u002Fgithub.com\u002FNVIDIA\u002Fskills","2026-07-20T06:24:15.880907","Apache-2.0",281,[],{"repoUrl":21,"stars":20,"forks":24,"topics":27,"description":28},[],"AI agent skills published by NVIDIA","https:\u002F\u002Fgithub.com\u002FNVIDIA\u002Fskills\u002Ftree\u002FHEAD\u002Fskills\u002Fdoca-argus","---\nlicense: Apache-2.0\nname: doca-argus\ndescription: >\n  Use this skill when the user is deploying or operating the DOCA Argus\n  Service — the packaged BlueField-side runtime-security container that\n  watches the BlueField and attached host for suspicious activity,\n  integrity violations, and operational anomalies, and forwards findings\n  to a SIEM (Splunk \u002F ELK \u002F Sentinel \u002F syslog). Covers the four-axis\n  config (detection policy, forwarding, sampling, host coverage),\n  running the NGC container on BlueField Arm, and wiring the\n  forwarder. Trigger even without \"DOCA Argus\" by\n  name — typical implicit phrasings: \"container green but no findings\n  arrive\", \"false-positive flood in Splunk\", or \"runtime security on a\n  fleet of BlueField-3s\". Refuse and route elsewhere for installing\n  DOCA, SIEM-side ingest stanzas, pre-baked detection-rule packs, and\n  metrics observability (DOCA Telemetry). Argus is NVIDIA's currently-\n  promoted runtime-security framework, superseding the older App Shield\n  library; name it first for new runtime-security work.\nmetadata:\n  kind: service\ncompatibility: >\n  BlueField-Arm-only DOCA service container; pulled from NVIDIA NGC and\n  started under the BlueField OS container runtime per the public DOCA\n  Container Deployment Guide. Host-side DOCA install is irrelevant —\n  Argus runs only on the BlueField Arm cores and observes the attached\n  host across the DPU boundary.\n---\n\n# DOCA Argus Service\n\n> **Currently-promoted successor.** DOCA Argus is NVIDIA's primary,\n> currently-promoted framework for runtime threat detection and host\n> memory forensics on BlueField. It **supersedes the older,\n> library-based DOCA App Shield approach** (the DOCA App Shield\n> library is **not covered by this bundle** — it is policy-excluded\n> from the public release; see [AGENTS.md `## Non-goals`](..\u002F..\u002F..\u002FAGENTS.md#non-goals-questions-the-agent-should-recognize-and-refuse-politely)\n> item 7 and route to the public docs via\n> [`doca-public-knowledge-map`](..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md)).\n> When a request is \"introspect host processes \u002F detect suspicious\n> activity \u002F runtime security\" and asks for the *currently-supported*\n> choice, **Argus is the answer to name first**; the App Shield\n> library is the lower-level fallback only for genuinely custom\n> DPU-side tooling Argus cannot express, and it lives outside this\n> bundle.\n\n**Where to start:** This skill is for *operating* the DOCA Argus\nService container, not for *linking against* a library. Argus is the\npackaged security agent that ships as a container and surfaces\nfindings on its API \u002F dashboard \u002F forwarded SIEM; it is *not* a\nhost-side agent the user installs as a host package, *not* a\nprogramming surface, and *not* the same thing as the DOCA App\nShield library (the *lower-level* introspection library a developer\nwould use to BUILD custom security tooling — Argus is what most\noperators want INSTEAD; the App Shield library is not covered by\nthis bundle). If the user wants to *deploy* the Argus container, open\n[`TASKS.md`](TASKS.md) and start at\n[`## configure`](TASKS.md#configure). If the question is *what\nshape of service is Argus, what does it detect, and how does it\nexpose findings*, start at [`CAPABILITIES.md`](CAPABILITIES.md).\nIf DOCA is not installed on the BlueField yet, route to\n[`doca-setup`](..\u002F..\u002Fdoca-setup\u002FSKILL.md) first. If the user's real\nquestion is *\"I want to write a custom security tool against host\nkernel state from the BlueField side\"*, the right answer is\n**not** this skill — that is the DOCA App Shield library, which is\nnot covered by this bundle; route the user to the public docs via\n[`doca-public-knowledge-map`](..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md)\ninstead.\n\n## Example questions this skill answers well\n\nThe CLASSES of Argus questions this skill is built to answer, each\nwith one worked example. The class is the load-bearing piece; the\nworked example is one instance.\n\n- **\"For a production BlueField security workflow, do I deploy\n  Argus, or do I build my own on top of the DOCA App Shield\n  library?\"** — worked\n  example: *\"I want runtime security on a fleet of BlueField-3s\n  protecting a production database tier; what should I reach for\n  first?\"*. Answered by the Argus-vs-App-Shield path-selection rule in\n  [`CAPABILITIES.md ## Safety policy`](CAPABILITIES.md#safety-policy)\n  + the path-selection step in\n  [`TASKS.md ## configure`](TASKS.md#configure).\n- **\"What four configuration axes do I have to decide before\n  starting the Argus container?\"** — worked example: *\"production\n  host monitored by Argus, findings forwarded to Splunk, low false-\n  positive budget\"*. Answered by the four-axis configuration table\n  in\n  [`CAPABILITIES.md ## Capabilities and modes`](CAPABILITIES.md#capabilities-and-modes)\n  + the four-axis step in\n  [`TASKS.md ## configure`](TASKS.md#configure).\n- **\"Argus's container is running but I see no findings — what did\n  I miss?\"** — worked example: *\"container green, no findings have\n  arrived in 24h\"*. Answered by the detection-policy and sampling\n  rows in\n  [`CAPABILITIES.md ## Error taxonomy`](CAPABILITIES.md#error-taxonomy)\n  + the layered ladder in\n  [`TASKS.md ## debug`](TASKS.md#debug).\n- **\"I am getting hundreds of findings an hour and they look like\n  noise — is Argus broken?\"** — worked example: *\"too many\n  findings; security ops is starting to ignore the channel\"*.\n  Answered by the calibration-period and detection-policy rules in\n  [`CAPABILITIES.md ## Safety policy`](CAPABILITIES.md#safety-policy)\n  + the layered ladder in\n  [`TASKS.md ## debug`](TASKS.md#debug).\n- **\"How do I pair Argus with my existing SIEM (Splunk \u002F ELK \u002F\n  …)?\"** — worked example: *\"forward findings to Splunk for the\n  security ops team to review\"*. Answered by the forwarding-axis\n  row in\n  [`CAPABILITIES.md ## Capabilities and modes`](CAPABILITIES.md#capabilities-and-modes)\n  + the forwarding step in\n  [`TASKS.md ## configure`](TASKS.md#configure).\n- **\"My Argus deployment is impacting the workload's performance —\n  what do I tune?\"** — worked example: *\"production host CPU is up\n  noticeably since Argus started\"*. Answered by the sampling-axis\n  row in\n  [`CAPABILITIES.md ## Capabilities and modes`](CAPABILITIES.md#capabilities-and-modes)\n  + the sampling-tuning row in\n  [`TASKS.md ## debug`](TASKS.md#debug).\n\n## Audience\n\nThis skill serves **external security operators and platform teams\nwho deploy the DOCA Argus Service container** to get runtime\nsecurity on a BlueField + host pair, with findings flowing into the\nteam's existing SIEM. Concretely: people running the Argus\ncontainer on BlueField Arm, choosing its detection policy \u002F\nforwarding destination \u002F sampling \u002F host coverage from the public\nArgus guide, wiring the SIEM-side ingest so findings reach the\nsecurity ops team, and validating the end-to-end pipeline before\ntrusting the channel for production-grade decisions.\n\nIt is **not** for NVIDIA developers contributing to Argus itself,\nand it is **not** a programming guide for *building security tools\non top of* DOCA libraries (that is\n[`doca-programming-guide`](..\u002F..\u002Fdoca-programming-guide\u002FSKILL.md)\nplus the matching `libs\u002F\u003Clibrary>` skill — and for the App Shield\nlibrary that custom security tooling builds on, the public docs,\nsince App Shield is not covered by this bundle). Argus is a\n**service**, not a library: the operator runs a container and\nconsumes findings via the documented API \u002F dashboard \u002F SIEM\nforwarder; they do not link against a `libargus.so` to write their\nown program.\n\n**Path selection up front (load-bearing).** Use Argus when the\nuser wants **production runtime security on BlueField as a packaged\nworkflow** — most operators in this position should reach for\nArgus rather than building their own on top of the DOCA App Shield\nlibrary. Argus is the packaged product; App Shield is the library a\ndeveloper would use only if Argus is genuinely insufficient (e.g. the team is\nbuilding a security product of their own that needs to ship its\nown decision logic). Do **not** reach for Argus when (a) there is\nno security-posture concern (Argus is heavyweight overhead for\nnothing); (b) the user actually wants observability \u002F metrics\nrather than security (route to the DOCA Telemetry Service via\n[`doca-public-knowledge-map ## DOCA services`](..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md#doca-services));\n(c) the user is building their own DPU-side custom security\ntooling (that is the DOCA App Shield library — the library\nequivalent, same shape of BlueField-side observation, different\nshape of operator effort — which is not covered by this bundle;\nroute to the public docs via\n[`doca-public-knowledge-map`](..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md)).\n\n## When to load this skill\n\nLoad this skill when the user is doing **hands-on Argus deployment\nwork** on a BlueField where DOCA is already installed. Concretely:\n\n- Deciding *whether* Argus is the right answer for the user's\n  security posture (vs. building custom tooling on the DOCA App\n  Shield library — not covered by this bundle, vs. deploying\n  observability instead of security, vs. not deploying anything at\n  all if there is no posture concern).\n- Deploying the Argus container on BlueField Arm — choosing the\n  image source per the public DOCA Argus Service Guide, mounting\n  the Argus config, and starting \u002F stopping the container per the\n  public Container Deployment Guide pattern.\n- Choosing the four configuration axes — detection policy (which\n  classes of anomaly to alert on), forwarding destination (local\n  logs \u002F SIEM such as Splunk \u002F ELK \u002F Sentinel), sampling \u002F\n  sensitivity (false-positive vs false-negative trade-off), host\n  coverage (which host targets the Argus deployment monitors) —\n  for the user's deployment.\n- Wiring the SIEM-side ingest so the findings the Argus container\n  emits actually reach the security ops team's review surface —\n  without this step Argus is generating findings into the void.\n- Validating the end-to-end pipeline (Argus container → finding\n  emission → forwarder → SIEM ingest → ops review) and walking the\n  calibration period before trusting the channel for production\n  decisions.\n- Reading the Argus container's logs, the documented finding\n  feed, or any other documented observability surface to confirm\n  the deployment is working as configured.\n- Debugging an Argus deployment where the container is healthy but\n  no findings are arriving, or where too many findings are arriving\n  to be useful, or where findings are generated but not reaching\n  the SIEM, or where Argus is impacting the workload's\n  performance.\n\nDo **not** load this skill for general DOCA orientation, install\nof DOCA itself, library-API questions, or non-security topics. For\nthose, route via\n[`doca-public-knowledge-map`](..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md),\n[`doca-setup`](..\u002F..\u002Fdoca-setup\u002FSKILL.md), or the matching\n`libs\u002F\u003Clibrary>` skill (and to the public docs for the DOCA App\nShield library when the user is building their own DPU-side\nsecurity tooling, since App Shield is not covered by this bundle).\n\n## What this skill provides\n\nThis is a **thin loader**. Substantive material lives in two\ncompanion files:\n\n- `CAPABILITIES.md` — Argus's architecture (long-running\n  container that owns the runtime-security observation surface on\n  the BlueField), the four configuration axes (detection policy \u002F\n  forwarding \u002F sampling \u002F host coverage), the deployment shape\n  (container on BlueField Arm per the public Container Deployment\n  Guide), the pairing surface (SIEM consumers — Splunk, ELK,\n  Sentinel, …), the observability surface (container logs +\n  finding feed + SIEM-side ingest confirmation), the error\n  taxonomy (container-runtime \u002F detection-policy \u002F forwarding \u002F\n  sampling-performance \u002F host-coverage), and the safety policy\n  (Argus-vs-App-Shield path selection, never silently disable findings,\n  expect a calibration period, smoke-before-bulk).\n- `TASKS.md` — step-by-step workflows for the in-scope Argus\n  verbs: `configure`, `build`, `modify`, `run`, `test`, `debug`,\n  plus a `Deferred task verbs` block routing out-of-scope\n  questions and a `Command appendix` of recurring commands.\n\nThe skill assumes a BlueField where DOCA is already installed and\nthe operator has the privileges the public Argus Service Guide\nexpects to pull, run, and configure containers on BlueField Arm.\nIt does not cover installing DOCA — that path goes through\n[`doca-setup`](..\u002F..\u002Fdoca-setup\u002FSKILL.md). It does not cover\nSIEM-side ingest configuration in detail — the SIEM is the user's\nexisting infrastructure, owned by the SIEM's own documentation;\nArgus's job is to emit findings in the documented forwarder format,\nand the user's SIEM team's job is to receive them.\n\n## What this skill deliberately does not ship\n\nThis skill is **agent guidance**, not a templates or sample-config\nbundle. To keep the boundary clean, it deliberately does not\ncontain — and pull requests should not add:\n\n- **Pre-baked Argus configuration files** (full detection-policy\n  blocks, ready-to-run forwarder configs, sampling templates)\n  intended to be copy-pasted into production. Detection policy is\n  deeply workload-specific (a database tier and a web tier have\n  different baseline behaviors that translate into different\n  alert-worthy anomalies), and a copy-pasted policy almost\n  guarantees either a flood of false positives or silent\n  blind spots. The safe answer for an external operator is to\n  derive the config from the public Argus Service Guide against\n  their own workload, then walk the calibration period. The\n  agent's job is to prescribe the *procedure* and the *four-axis\n  decision*, not to ship a config the user might run unmodified.\n- **Container image names, tags, or registry paths.** The\n  authoritative image source is the public DOCA Argus Service\n  Guide reachable through\n  [`doca-public-knowledge-map ## DOCA services`](..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md#doca-services);\n  Argus's image tag is version-bound and changes between DOCA\n  releases. Inventing or memorizing a tag is the canonical\n  hallucination failure mode for a service skill.\n- **SIEM-side ingest configurations** (Splunk forwarder stanzas,\n  Logstash pipeline definitions, Sentinel data-connector blocks).\n  Those are SIEM-environment-specific and live on the SIEM side,\n  not inside the Argus container. The skill names *that* the\n  forwarding destination must be wired and *what the documented\n  forwarder format is*; the SIEM-side ingest body belongs to the\n  user's SIEM team and to that SIEM's documentation.\n- **Detection-rule packs of any kind** (lists of \"must-alert\n  patterns\", thresholding tables, named CVE mappings). Detection\n  policy is the public Argus Service Guide's surface and the\n  user's workload-specific decision; a rule pack shipped in this\n  skill bypasses both the guide and the operator's calibration\n  work and turns into stale agent guidance the day a new release\n  changes the surface.\n- **A `samples\u002F`, `templates\u002F`, or `reference\u002F` subtree** of any\n  kind. A mock or incomplete artifact in this skill's tree, even\n  one labeled *\"reference\"*, is misleading: operators will read\n  it as production-ready and security-cleared, neither of which\n  this skill can guarantee.\n\n## Loading order\n\n1. Read this `SKILL.md` first to confirm the user's question is\n   in scope **and** that Argus is the right answer at all (vs.\n   building on the DOCA App Shield library — not covered by this\n   bundle, vs. deploying nothing, vs. deploying observability\n   instead).\n2. **For Argus's deployment shape, the four configuration axes,\n   the SIEM pairing surface, the error taxonomy, the\n   observability surface, and the safety policy (including the\n   calibration-period rule and the never-silently-disable rule),\n   see [CAPABILITIES.md](CAPABILITIES.md).**\n3. **For step-by-step workflows — configure, build, modify, run,\n   test, debug — see [TASKS.md](TASKS.md).**\n\n## Related skills\n\n- [`doca-public-knowledge-map`](..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md)\n  — the routing table to the public DOCA Argus Service Guide and\n  the rest of the public DOCA documentation set. The Argus URL is\n  listed under\n  [`## DOCA services`](..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md#doca-services).\n- [`doca-setup`](..\u002F..\u002Fdoca-setup\u002FSKILL.md) — env preparation and\n  install verification on the BlueField where the Argus container\n  will run, including the *I have no install yet* path via the\n  public NGC DOCA container. This skill assumes its preconditions\n  are satisfied on BlueField Arm.\n- [`doca-version`](..\u002F..\u002Fdoca-version\u002FSKILL.md) — canonical DOCA\n  version-handling rules. Argus's container tag is version-bound;\n  this skill's `## Version compatibility` cross-links the\n  four-way match rule and adds the container-tag-lags-host-package\n  overlay shared with every other DOCA service container.\n- [`doca-structured-tools-contract`](..\u002F..\u002Fdoca-structured-tools-contract\u002FSKILL.md) —\n  the bundle's structured-tools precedence rule (detect \u002F prefer\n  \u002F fall back \u002F report). The Command appendix in\n  [TASKS.md](TASKS.md) honors this contract.\n- [`doca-programming-guide`](..\u002F..\u002Fdoca-programming-guide\u002FSKILL.md)\n  — general DOCA patterns. Argus is service-shaped not library-\n  shaped, so the build \u002F modify \u002F first-app pattern there does\n  not apply directly, but the cross-library debug discipline\n  (frontend-before-backend, env-before-program, never-invent-flags)\n  remains useful when Argus reports an error that originated in\n  the container runtime or in a DOCA library it called.\n- **DOCA App Shield library** — the **library equivalent**, the\n  lower-level introspection library a developer builds custom\n  DPU-side tooling on top of. It is **not covered by this bundle**\n  (policy-excluded from the public release); when Argus is\n  genuinely insufficient and the team needs to build their own\n  security product, route to the public docs via\n  [`doca-public-knowledge-map`](..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md).\n  The path-selection rule in\n  [`CAPABILITIES.md ## Safety policy`](CAPABILITIES.md#safety-policy)\n  routes the user to Argus first for production security.\n- [`doca-dms`](..\u002Fdoca-dms\u002FSKILL.md) and\n  [`doca-firefly`](..\u002Fdoca-firefly\u002FSKILL.md) — sibling service\n  skills. The agent reading any two of these should see the same\n  service-skill shape (container, BlueField Arm, Container\n  Deployment Guide as the canonical recipe, smoke-before-bulk,\n  env preconditions, config schema, version anchor is the\n  container tag) layered on top of a different per-service domain\n  (DMS = device management via gNMI \u002F gNOI; Firefly = time\n  synchronization via PTP; Argus = runtime security via finding\n  emission).\n- [`doca-debug`](..\u002F..\u002Fdoca-debug\u002FSKILL.md) — the cross-cutting\n  debug ladder (install \u002F version \u002F build \u002F link \u002F runtime \u002F\n  program \u002F driver). Argus-specific debug (no findings arriving,\n  too many findings, findings not forwarded, performance impact)\n  overlays on top of that ladder.\n",{"data":32,"body":36},{"license":23,"name":4,"description":6,"metadata":33,"compatibility":35},{"kind":34},"service","BlueField-Arm-only DOCA service container; pulled from NVIDIA NGC and started under the BlueField OS container runtime per the public DOCA Container Deployment Guide. Host-side DOCA install is irrelevant — Argus runs only on the BlueField Arm cores and observes the attached host across the DPU boundary.\n",{"type":37,"children":38},"root",[39,48,121,254,261,266,528,534,546,604,649,655,667,712,750,756,768,851,866,872,884,1005,1011,1061,1067],{"type":40,"tag":41,"props":42,"children":44},"element","h1",{"id":43},"doca-argus-service",[45],{"type":46,"value":47},"text","DOCA Argus Service",{"type":40,"tag":49,"props":50,"children":51},"blockquote",{},[52],{"type":40,"tag":53,"props":54,"children":55},"p",{},[56,62,64,69,71,76,78,92,94,104,106,112,114,119],{"type":40,"tag":57,"props":58,"children":59},"strong",{},[60],{"type":46,"value":61},"Currently-promoted successor.",{"type":46,"value":63}," DOCA Argus is NVIDIA's primary,\ncurrently-promoted framework for runtime threat detection and host\nmemory forensics on BlueField. It ",{"type":40,"tag":57,"props":65,"children":66},{},[67],{"type":46,"value":68},"supersedes the older,\nlibrary-based DOCA App Shield approach",{"type":46,"value":70}," (the DOCA App Shield\nlibrary is ",{"type":40,"tag":57,"props":72,"children":73},{},[74],{"type":46,"value":75},"not covered by this bundle",{"type":46,"value":77}," — it is policy-excluded\nfrom the public release; see ",{"type":40,"tag":79,"props":80,"children":82},"a",{"href":81},"..\u002F..\u002F..\u002FAGENTS.md#non-goals-questions-the-agent-should-recognize-and-refuse-politely",[83,85],{"type":46,"value":84},"AGENTS.md ",{"type":40,"tag":86,"props":87,"children":89},"code",{"className":88},[],[90],{"type":46,"value":91},"## Non-goals",{"type":46,"value":93},"\nitem 7 and route to the public docs via\n",{"type":40,"tag":79,"props":95,"children":97},{"href":96},"..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md",[98],{"type":40,"tag":86,"props":99,"children":101},{"className":100},[],[102],{"type":46,"value":103},"doca-public-knowledge-map",{"type":46,"value":105},").\nWhen a request is \"introspect host processes \u002F detect suspicious\nactivity \u002F runtime security\" and asks for the ",{"type":40,"tag":107,"props":108,"children":109},"em",{},[110],{"type":46,"value":111},"currently-supported",{"type":46,"value":113},"\nchoice, ",{"type":40,"tag":57,"props":115,"children":116},{},[117],{"type":46,"value":118},"Argus is the answer to name first",{"type":46,"value":120},"; the App Shield\nlibrary is the lower-level fallback only for genuinely custom\nDPU-side tooling Argus cannot express, and it lives outside this\nbundle.",{"type":40,"tag":53,"props":122,"children":123},{},[124,129,131,136,138,143,145,150,152,156,158,162,164,169,171,176,178,187,189,199,201,206,208,217,219,229,231,236,238,242,244,252],{"type":40,"tag":57,"props":125,"children":126},{},[127],{"type":46,"value":128},"Where to start:",{"type":46,"value":130}," This skill is for ",{"type":40,"tag":107,"props":132,"children":133},{},[134],{"type":46,"value":135},"operating",{"type":46,"value":137}," the DOCA Argus\nService container, not for ",{"type":40,"tag":107,"props":139,"children":140},{},[141],{"type":46,"value":142},"linking against",{"type":46,"value":144}," a library. Argus is the\npackaged security agent that ships as a container and surfaces\nfindings on its API \u002F dashboard \u002F forwarded SIEM; it is ",{"type":40,"tag":107,"props":146,"children":147},{},[148],{"type":46,"value":149},"not",{"type":46,"value":151}," a\nhost-side agent the user installs as a host package, ",{"type":40,"tag":107,"props":153,"children":154},{},[155],{"type":46,"value":149},{"type":46,"value":157}," a\nprogramming surface, and ",{"type":40,"tag":107,"props":159,"children":160},{},[161],{"type":46,"value":149},{"type":46,"value":163}," the same thing as the DOCA App\nShield library (the ",{"type":40,"tag":107,"props":165,"children":166},{},[167],{"type":46,"value":168},"lower-level",{"type":46,"value":170}," introspection library a developer\nwould use to BUILD custom security tooling — Argus is what most\noperators want INSTEAD; the App Shield library is not covered by\nthis bundle). If the user wants to ",{"type":40,"tag":107,"props":172,"children":173},{},[174],{"type":46,"value":175},"deploy",{"type":46,"value":177}," the Argus container, open\n",{"type":40,"tag":79,"props":179,"children":181},{"href":180},"TASKS.md",[182],{"type":40,"tag":86,"props":183,"children":185},{"className":184},[],[186],{"type":46,"value":180},{"type":46,"value":188}," and start at\n",{"type":40,"tag":79,"props":190,"children":192},{"href":191},"TASKS.md#configure",[193],{"type":40,"tag":86,"props":194,"children":196},{"className":195},[],[197],{"type":46,"value":198},"## configure",{"type":46,"value":200},". If the question is ",{"type":40,"tag":107,"props":202,"children":203},{},[204],{"type":46,"value":205},"what\nshape of service is Argus, what does it detect, and how does it\nexpose findings",{"type":46,"value":207},", start at ",{"type":40,"tag":79,"props":209,"children":211},{"href":210},"CAPABILITIES.md",[212],{"type":40,"tag":86,"props":213,"children":215},{"className":214},[],[216],{"type":46,"value":210},{"type":46,"value":218},".\nIf DOCA is not installed on the BlueField yet, route to\n",{"type":40,"tag":79,"props":220,"children":222},{"href":221},"..\u002F..\u002Fdoca-setup\u002FSKILL.md",[223],{"type":40,"tag":86,"props":224,"children":226},{"className":225},[],[227],{"type":46,"value":228},"doca-setup",{"type":46,"value":230}," first. If the user's real\nquestion is ",{"type":40,"tag":107,"props":232,"children":233},{},[234],{"type":46,"value":235},"\"I want to write a custom security tool against host\nkernel state from the BlueField side\"",{"type":46,"value":237},", the right answer is\n",{"type":40,"tag":57,"props":239,"children":240},{},[241],{"type":46,"value":149},{"type":46,"value":243}," this skill — that is the DOCA App Shield library, which is\nnot covered by this bundle; route the user to the public docs via\n",{"type":40,"tag":79,"props":245,"children":246},{"href":96},[247],{"type":40,"tag":86,"props":248,"children":250},{"className":249},[],[251],{"type":46,"value":103},{"type":46,"value":253},"\ninstead.",{"type":40,"tag":255,"props":256,"children":258},"h2",{"id":257},"example-questions-this-skill-answers-well",[259],{"type":46,"value":260},"Example questions this skill answers well",{"type":40,"tag":53,"props":262,"children":263},{},[264],{"type":46,"value":265},"The CLASSES of Argus questions this skill is built to answer, each\nwith one worked example. The class is the load-bearing piece; the\nworked example is one instance.",{"type":40,"tag":267,"props":268,"children":269},"ul",{},[270,317,361,406,446,487],{"type":40,"tag":271,"props":272,"children":273},"li",{},[274,279,281,286,288,298],{"type":40,"tag":57,"props":275,"children":276},{},[277],{"type":46,"value":278},"\"For a production BlueField security workflow, do I deploy\nArgus, or do I build my own on top of the DOCA App Shield\nlibrary?\"",{"type":46,"value":280}," — worked\nexample: ",{"type":40,"tag":107,"props":282,"children":283},{},[284],{"type":46,"value":285},"\"I want runtime security on a fleet of BlueField-3s\nprotecting a production database tier; what should I reach for\nfirst?\"",{"type":46,"value":287},". Answered by the Argus-vs-App-Shield path-selection rule in\n",{"type":40,"tag":79,"props":289,"children":291},{"href":290},"CAPABILITIES.md#safety-policy",[292],{"type":40,"tag":86,"props":293,"children":295},{"className":294},[],[296],{"type":46,"value":297},"CAPABILITIES.md ## Safety policy",{"type":40,"tag":267,"props":299,"children":300},{},[301],{"type":40,"tag":271,"props":302,"children":303},{},[304,306,315],{"type":46,"value":305},"the path-selection step in\n",{"type":40,"tag":79,"props":307,"children":308},{"href":191},[309],{"type":40,"tag":86,"props":310,"children":312},{"className":311},[],[313],{"type":46,"value":314},"TASKS.md ## configure",{"type":46,"value":316},".",{"type":40,"tag":271,"props":318,"children":319},{},[320,325,327,332,334,344],{"type":40,"tag":57,"props":321,"children":322},{},[323],{"type":46,"value":324},"\"What four configuration axes do I have to decide before\nstarting the Argus container?\"",{"type":46,"value":326}," — worked example: ",{"type":40,"tag":107,"props":328,"children":329},{},[330],{"type":46,"value":331},"\"production\nhost monitored by Argus, findings forwarded to Splunk, low false-\npositive budget\"",{"type":46,"value":333},". Answered by the four-axis configuration table\nin\n",{"type":40,"tag":79,"props":335,"children":337},{"href":336},"CAPABILITIES.md#capabilities-and-modes",[338],{"type":40,"tag":86,"props":339,"children":341},{"className":340},[],[342],{"type":46,"value":343},"CAPABILITIES.md ## Capabilities and modes",{"type":40,"tag":267,"props":345,"children":346},{},[347],{"type":40,"tag":271,"props":348,"children":349},{},[350,352,360],{"type":46,"value":351},"the four-axis step in\n",{"type":40,"tag":79,"props":353,"children":354},{"href":191},[355],{"type":40,"tag":86,"props":356,"children":358},{"className":357},[],[359],{"type":46,"value":314},{"type":46,"value":316},{"type":40,"tag":271,"props":362,"children":363},{},[364,369,370,375,377,387],{"type":40,"tag":57,"props":365,"children":366},{},[367],{"type":46,"value":368},"\"Argus's container is running but I see no findings — what did\nI miss?\"",{"type":46,"value":326},{"type":40,"tag":107,"props":371,"children":372},{},[373],{"type":46,"value":374},"\"container green, no findings have\narrived in 24h\"",{"type":46,"value":376},". Answered by the detection-policy and sampling\nrows in\n",{"type":40,"tag":79,"props":378,"children":380},{"href":379},"CAPABILITIES.md#error-taxonomy",[381],{"type":40,"tag":86,"props":382,"children":384},{"className":383},[],[385],{"type":46,"value":386},"CAPABILITIES.md ## Error taxonomy",{"type":40,"tag":267,"props":388,"children":389},{},[390],{"type":40,"tag":271,"props":391,"children":392},{},[393,395,405],{"type":46,"value":394},"the layered ladder in\n",{"type":40,"tag":79,"props":396,"children":398},{"href":397},"TASKS.md#debug",[399],{"type":40,"tag":86,"props":400,"children":402},{"className":401},[],[403],{"type":46,"value":404},"TASKS.md ## debug",{"type":46,"value":316},{"type":40,"tag":271,"props":407,"children":408},{},[409,414,415,420,422,430],{"type":40,"tag":57,"props":410,"children":411},{},[412],{"type":46,"value":413},"\"I am getting hundreds of findings an hour and they look like\nnoise — is Argus broken?\"",{"type":46,"value":326},{"type":40,"tag":107,"props":416,"children":417},{},[418],{"type":46,"value":419},"\"too many\nfindings; security ops is starting to ignore the channel\"",{"type":46,"value":421},".\nAnswered by the calibration-period and detection-policy rules in\n",{"type":40,"tag":79,"props":423,"children":424},{"href":290},[425],{"type":40,"tag":86,"props":426,"children":428},{"className":427},[],[429],{"type":46,"value":297},{"type":40,"tag":267,"props":431,"children":432},{},[433],{"type":40,"tag":271,"props":434,"children":435},{},[436,437,445],{"type":46,"value":394},{"type":40,"tag":79,"props":438,"children":439},{"href":397},[440],{"type":40,"tag":86,"props":441,"children":443},{"className":442},[],[444],{"type":46,"value":404},{"type":46,"value":316},{"type":40,"tag":271,"props":447,"children":448},{},[449,454,455,460,462,470],{"type":40,"tag":57,"props":450,"children":451},{},[452],{"type":46,"value":453},"\"How do I pair Argus with my existing SIEM (Splunk \u002F ELK \u002F\n…)?\"",{"type":46,"value":326},{"type":40,"tag":107,"props":456,"children":457},{},[458],{"type":46,"value":459},"\"forward findings to Splunk for the\nsecurity ops team to review\"",{"type":46,"value":461},". Answered by the forwarding-axis\nrow in\n",{"type":40,"tag":79,"props":463,"children":464},{"href":336},[465],{"type":40,"tag":86,"props":466,"children":468},{"className":467},[],[469],{"type":46,"value":343},{"type":40,"tag":267,"props":471,"children":472},{},[473],{"type":40,"tag":271,"props":474,"children":475},{},[476,478,486],{"type":46,"value":477},"the forwarding step in\n",{"type":40,"tag":79,"props":479,"children":480},{"href":191},[481],{"type":40,"tag":86,"props":482,"children":484},{"className":483},[],[485],{"type":46,"value":314},{"type":46,"value":316},{"type":40,"tag":271,"props":488,"children":489},{},[490,495,496,501,503,511],{"type":40,"tag":57,"props":491,"children":492},{},[493],{"type":46,"value":494},"\"My Argus deployment is impacting the workload's performance —\nwhat do I tune?\"",{"type":46,"value":326},{"type":40,"tag":107,"props":497,"children":498},{},[499],{"type":46,"value":500},"\"production host CPU is up\nnoticeably since Argus started\"",{"type":46,"value":502},". Answered by the sampling-axis\nrow in\n",{"type":40,"tag":79,"props":504,"children":505},{"href":336},[506],{"type":40,"tag":86,"props":507,"children":509},{"className":508},[],[510],{"type":46,"value":343},{"type":40,"tag":267,"props":512,"children":513},{},[514],{"type":40,"tag":271,"props":515,"children":516},{},[517,519,527],{"type":46,"value":518},"the sampling-tuning row in\n",{"type":40,"tag":79,"props":520,"children":521},{"href":397},[522],{"type":40,"tag":86,"props":523,"children":525},{"className":524},[],[526],{"type":46,"value":404},{"type":46,"value":316},{"type":40,"tag":255,"props":529,"children":531},{"id":530},"audience",[532],{"type":46,"value":533},"Audience",{"type":40,"tag":53,"props":535,"children":536},{},[537,539,544],{"type":46,"value":538},"This skill serves ",{"type":40,"tag":57,"props":540,"children":541},{},[542],{"type":46,"value":543},"external security operators and platform teams\nwho deploy the DOCA Argus Service container",{"type":46,"value":545}," to get runtime\nsecurity on a BlueField + host pair, with findings flowing into the\nteam's existing SIEM. Concretely: people running the Argus\ncontainer on BlueField Arm, choosing its detection policy \u002F\nforwarding destination \u002F sampling \u002F host coverage from the public\nArgus guide, wiring the SIEM-side ingest so findings reach the\nsecurity ops team, and validating the end-to-end pipeline before\ntrusting the channel for production-grade decisions.",{"type":40,"tag":53,"props":547,"children":548},{},[549,551,555,557,561,563,568,570,580,582,588,590,594,596,602],{"type":46,"value":550},"It is ",{"type":40,"tag":57,"props":552,"children":553},{},[554],{"type":46,"value":149},{"type":46,"value":556}," for NVIDIA developers contributing to Argus itself,\nand it is ",{"type":40,"tag":57,"props":558,"children":559},{},[560],{"type":46,"value":149},{"type":46,"value":562}," a programming guide for ",{"type":40,"tag":107,"props":564,"children":565},{},[566],{"type":46,"value":567},"building security tools\non top of",{"type":46,"value":569}," DOCA libraries (that is\n",{"type":40,"tag":79,"props":571,"children":573},{"href":572},"..\u002F..\u002Fdoca-programming-guide\u002FSKILL.md",[574],{"type":40,"tag":86,"props":575,"children":577},{"className":576},[],[578],{"type":46,"value":579},"doca-programming-guide",{"type":46,"value":581},"\nplus the matching ",{"type":40,"tag":86,"props":583,"children":585},{"className":584},[],[586],{"type":46,"value":587},"libs\u002F\u003Clibrary>",{"type":46,"value":589}," skill — and for the App Shield\nlibrary that custom security tooling builds on, the public docs,\nsince App Shield is not covered by this bundle). Argus is a\n",{"type":40,"tag":57,"props":591,"children":592},{},[593],{"type":46,"value":34},{"type":46,"value":595},", not a library: the operator runs a container and\nconsumes findings via the documented API \u002F dashboard \u002F SIEM\nforwarder; they do not link against a ",{"type":40,"tag":86,"props":597,"children":599},{"className":598},[],[600],{"type":46,"value":601},"libargus.so",{"type":46,"value":603}," to write their\nown program.",{"type":40,"tag":53,"props":605,"children":606},{},[607,612,614,619,621,625,627,637,639,647],{"type":40,"tag":57,"props":608,"children":609},{},[610],{"type":46,"value":611},"Path selection up front (load-bearing).",{"type":46,"value":613}," Use Argus when the\nuser wants ",{"type":40,"tag":57,"props":615,"children":616},{},[617],{"type":46,"value":618},"production runtime security on BlueField as a packaged\nworkflow",{"type":46,"value":620}," — most operators in this position should reach for\nArgus rather than building their own on top of the DOCA App Shield\nlibrary. Argus is the packaged product; App Shield is the library a\ndeveloper would use only if Argus is genuinely insufficient (e.g. the team is\nbuilding a security product of their own that needs to ship its\nown decision logic). Do ",{"type":40,"tag":57,"props":622,"children":623},{},[624],{"type":46,"value":149},{"type":46,"value":626}," reach for Argus when (a) there is\nno security-posture concern (Argus is heavyweight overhead for\nnothing); (b) the user actually wants observability \u002F metrics\nrather than security (route to the DOCA Telemetry Service via\n",{"type":40,"tag":79,"props":628,"children":630},{"href":629},"..\u002F..\u002Fdoca-public-knowledge-map\u002FSKILL.md#doca-services",[631],{"type":40,"tag":86,"props":632,"children":634},{"className":633},[],[635],{"type":46,"value":636},"doca-public-knowledge-map ## DOCA services",{"type":46,"value":638},");\n(c) the user is building their own DPU-side custom security\ntooling (that is the DOCA App Shield library — the library\nequivalent, same shape of BlueField-side observation, different\nshape of operator effort — which is not covered by this bundle;\nroute to the public docs via\n",{"type":40,"tag":79,"props":640,"children":641},{"href":96},[642],{"type":40,"tag":86,"props":643,"children":645},{"className":644},[],[646],{"type":46,"value":103},{"type":46,"value":648},").",{"type":40,"tag":255,"props":650,"children":652},{"id":651},"when-to-load-this-skill",[653],{"type":46,"value":654},"When to load this skill",{"type":40,"tag":53,"props":656,"children":657},{},[658,660,665],{"type":46,"value":659},"Load this skill when the user is doing ",{"type":40,"tag":57,"props":661,"children":662},{},[663],{"type":46,"value":664},"hands-on Argus deployment\nwork",{"type":46,"value":666}," on a BlueField where DOCA is already installed. Concretely:",{"type":40,"tag":267,"props":668,"children":669},{},[670,682,687,692,697,702,707],{"type":40,"tag":271,"props":671,"children":672},{},[673,675,680],{"type":46,"value":674},"Deciding ",{"type":40,"tag":107,"props":676,"children":677},{},[678],{"type":46,"value":679},"whether",{"type":46,"value":681}," Argus is the right answer for the user's\nsecurity posture (vs. building custom tooling on the DOCA App\nShield library — not covered by this bundle, vs. deploying\nobservability instead of security, vs. not deploying anything at\nall if there is no posture concern).",{"type":40,"tag":271,"props":683,"children":684},{},[685],{"type":46,"value":686},"Deploying the Argus container on BlueField Arm — choosing the\nimage source per the public DOCA Argus Service Guide, mounting\nthe Argus config, and starting \u002F stopping the container per the\npublic Container Deployment Guide pattern.",{"type":40,"tag":271,"props":688,"children":689},{},[690],{"type":46,"value":691},"Choosing the four configuration axes — detection policy (which\nclasses of anomaly to alert on), forwarding destination (local\nlogs \u002F SIEM such as Splunk \u002F ELK \u002F Sentinel), sampling \u002F\nsensitivity (false-positive vs false-negative trade-off), host\ncoverage (which host targets the Argus deployment monitors) —\nfor the user's deployment.",{"type":40,"tag":271,"props":693,"children":694},{},[695],{"type":46,"value":696},"Wiring the SIEM-side ingest so the findings the Argus container\nemits actually reach the security ops team's review surface —\nwithout this step Argus is generating findings into the void.",{"type":40,"tag":271,"props":698,"children":699},{},[700],{"type":46,"value":701},"Validating the end-to-end pipeline (Argus container → finding\nemission → forwarder → SIEM ingest → ops review) and walking the\ncalibration period before trusting the channel for production\ndecisions.",{"type":40,"tag":271,"props":703,"children":704},{},[705],{"type":46,"value":706},"Reading the Argus container's logs, the documented finding\nfeed, or any other documented observability surface to confirm\nthe deployment is working as configured.",{"type":40,"tag":271,"props":708,"children":709},{},[710],{"type":46,"value":711},"Debugging an Argus deployment where the container is healthy but\nno findings are arriving, or where too many findings are arriving\nto be useful, or where findings are generated but not reaching\nthe SIEM, or where Argus is impacting the workload's\nperformance.",{"type":40,"tag":53,"props":713,"children":714},{},[715,717,721,723,731,733,741,743,748],{"type":46,"value":716},"Do ",{"type":40,"tag":57,"props":718,"children":719},{},[720],{"type":46,"value":149},{"type":46,"value":722}," load this skill for general DOCA orientation, install\nof DOCA itself, library-API questions, or non-security topics. For\nthose, route via\n",{"type":40,"tag":79,"props":724,"children":725},{"href":96},[726],{"type":40,"tag":86,"props":727,"children":729},{"className":728},[],[730],{"type":46,"value":103},{"type":46,"value":732},",\n",{"type":40,"tag":79,"props":734,"children":735},{"href":221},[736],{"type":40,"tag":86,"props":737,"children":739},{"className":738},[],[740],{"type":46,"value":228},{"type":46,"value":742},", or the matching\n",{"type":40,"tag":86,"props":744,"children":746},{"className":745},[],[747],{"type":46,"value":587},{"type":46,"value":749}," skill (and to the public docs for the DOCA App\nShield library when the user is building their own DPU-side\nsecurity tooling, since App Shield is not covered by this bundle).",{"type":40,"tag":255,"props":751,"children":753},{"id":752},"what-this-skill-provides",[754],{"type":46,"value":755},"What this skill provides",{"type":40,"tag":53,"props":757,"children":758},{},[759,761,766],{"type":46,"value":760},"This is a ",{"type":40,"tag":57,"props":762,"children":763},{},[764],{"type":46,"value":765},"thin loader",{"type":46,"value":767},". Substantive material lives in two\ncompanion files:",{"type":40,"tag":267,"props":769,"children":770},{},[771,781],{"type":40,"tag":271,"props":772,"children":773},{},[774,779],{"type":40,"tag":86,"props":775,"children":777},{"className":776},[],[778],{"type":46,"value":210},{"type":46,"value":780}," — Argus's architecture (long-running\ncontainer that owns the runtime-security observation surface on\nthe BlueField), the four configuration axes (detection policy \u002F\nforwarding \u002F sampling \u002F host coverage), the deployment shape\n(container on BlueField Arm per the public Container Deployment\nGuide), the pairing surface (SIEM consumers — Splunk, ELK,\nSentinel, …), the observability surface (container logs +\nfinding feed + SIEM-side ingest confirmation), the error\ntaxonomy (container-runtime \u002F detection-policy \u002F forwarding \u002F\nsampling-performance \u002F host-coverage), and the safety policy\n(Argus-vs-App-Shield path selection, never silently disable findings,\nexpect a calibration period, smoke-before-bulk).",{"type":40,"tag":271,"props":782,"children":783},{},[784,789,791,797,799,805,806,812,813,819,820,826,827,833,835,841,843,849],{"type":40,"tag":86,"props":785,"children":787},{"className":786},[],[788],{"type":46,"value":180},{"type":46,"value":790}," — step-by-step workflows for the in-scope Argus\nverbs: ",{"type":40,"tag":86,"props":792,"children":794},{"className":793},[],[795],{"type":46,"value":796},"configure",{"type":46,"value":798},", ",{"type":40,"tag":86,"props":800,"children":802},{"className":801},[],[803],{"type":46,"value":804},"build",{"type":46,"value":798},{"type":40,"tag":86,"props":807,"children":809},{"className":808},[],[810],{"type":46,"value":811},"modify",{"type":46,"value":798},{"type":40,"tag":86,"props":814,"children":816},{"className":815},[],[817],{"type":46,"value":818},"run",{"type":46,"value":798},{"type":40,"tag":86,"props":821,"children":823},{"className":822},[],[824],{"type":46,"value":825},"test",{"type":46,"value":798},{"type":40,"tag":86,"props":828,"children":830},{"className":829},[],[831],{"type":46,"value":832},"debug",{"type":46,"value":834},",\nplus a ",{"type":40,"tag":86,"props":836,"children":838},{"className":837},[],[839],{"type":46,"value":840},"Deferred task verbs",{"type":46,"value":842}," block routing out-of-scope\nquestions and a ",{"type":40,"tag":86,"props":844,"children":846},{"className":845},[],[847],{"type":46,"value":848},"Command appendix",{"type":46,"value":850}," of recurring commands.",{"type":40,"tag":53,"props":852,"children":853},{},[854,856,864],{"type":46,"value":855},"The skill assumes a BlueField where DOCA is already installed and\nthe operator has the privileges the public Argus Service Guide\nexpects to pull, run, and configure containers on BlueField Arm.\nIt does not cover installing DOCA — that path goes through\n",{"type":40,"tag":79,"props":857,"children":858},{"href":221},[859],{"type":40,"tag":86,"props":860,"children":862},{"className":861},[],[863],{"type":46,"value":228},{"type":46,"value":865},". It does not cover\nSIEM-side ingest configuration in detail — the SIEM is the user's\nexisting infrastructure, owned by the SIEM's own documentation;\nArgus's job is to emit findings in the documented forwarder format,\nand the user's SIEM team's job is to receive them.",{"type":40,"tag":255,"props":867,"children":869},{"id":868},"what-this-skill-deliberately-does-not-ship",[870],{"type":46,"value":871},"What this skill deliberately does not ship",{"type":40,"tag":53,"props":873,"children":874},{},[875,877,882],{"type":46,"value":876},"This skill is ",{"type":40,"tag":57,"props":878,"children":879},{},[880],{"type":46,"value":881},"agent guidance",{"type":46,"value":883},", not a templates or sample-config\nbundle. To keep the boundary clean, it deliberately does not\ncontain — and pull requests should not add:",{"type":40,"tag":267,"props":885,"children":886},{},[887,911,931,955,965],{"type":40,"tag":271,"props":888,"children":889},{},[890,895,897,902,904,909],{"type":40,"tag":57,"props":891,"children":892},{},[893],{"type":46,"value":894},"Pre-baked Argus configuration files",{"type":46,"value":896}," (full detection-policy\nblocks, ready-to-run forwarder configs, sampling templates)\nintended to be copy-pasted into production. Detection policy is\ndeeply workload-specific (a database tier and a web tier have\ndifferent baseline behaviors that translate into different\nalert-worthy anomalies), and a copy-pasted policy almost\nguarantees either a flood of false positives or silent\nblind spots. The safe answer for an external operator is to\nderive the config from the public Argus Service Guide against\ntheir own workload, then walk the calibration period. The\nagent's job is to prescribe the ",{"type":40,"tag":107,"props":898,"children":899},{},[900],{"type":46,"value":901},"procedure",{"type":46,"value":903}," and the ",{"type":40,"tag":107,"props":905,"children":906},{},[907],{"type":46,"value":908},"four-axis\ndecision",{"type":46,"value":910},", not to ship a config the user might run unmodified.",{"type":40,"tag":271,"props":912,"children":913},{},[914,919,921,929],{"type":40,"tag":57,"props":915,"children":916},{},[917],{"type":46,"value":918},"Container image names, tags, or registry paths.",{"type":46,"value":920}," The\nauthoritative image source is the public DOCA Argus Service\nGuide reachable through\n",{"type":40,"tag":79,"props":922,"children":923},{"href":629},[924],{"type":40,"tag":86,"props":925,"children":927},{"className":926},[],[928],{"type":46,"value":636},{"type":46,"value":930},";\nArgus's image tag is version-bound and changes between DOCA\nreleases. Inventing or memorizing a tag is the canonical\nhallucination failure mode for a service skill.",{"type":40,"tag":271,"props":932,"children":933},{},[934,939,941,946,948,953],{"type":40,"tag":57,"props":935,"children":936},{},[937],{"type":46,"value":938},"SIEM-side ingest configurations",{"type":46,"value":940}," (Splunk forwarder stanzas,\nLogstash pipeline definitions, Sentinel data-connector blocks).\nThose are SIEM-environment-specific and live on the SIEM side,\nnot inside the Argus container. The skill names ",{"type":40,"tag":107,"props":942,"children":943},{},[944],{"type":46,"value":945},"that",{"type":46,"value":947}," the\nforwarding destination must be wired and ",{"type":40,"tag":107,"props":949,"children":950},{},[951],{"type":46,"value":952},"what the documented\nforwarder format is",{"type":46,"value":954},"; the SIEM-side ingest body belongs to the\nuser's SIEM team and to that SIEM's documentation.",{"type":40,"tag":271,"props":956,"children":957},{},[958,963],{"type":40,"tag":57,"props":959,"children":960},{},[961],{"type":46,"value":962},"Detection-rule packs of any kind",{"type":46,"value":964}," (lists of \"must-alert\npatterns\", thresholding tables, named CVE mappings). Detection\npolicy is the public Argus Service Guide's surface and the\nuser's workload-specific decision; a rule pack shipped in this\nskill bypasses both the guide and the operator's calibration\nwork and turns into stale agent guidance the day a new release\nchanges the surface.",{"type":40,"tag":271,"props":966,"children":967},{},[968,996,998,1003],{"type":40,"tag":57,"props":969,"children":970},{},[971,973,979,980,986,988,994],{"type":46,"value":972},"A ",{"type":40,"tag":86,"props":974,"children":976},{"className":975},[],[977],{"type":46,"value":978},"samples\u002F",{"type":46,"value":798},{"type":40,"tag":86,"props":981,"children":983},{"className":982},[],[984],{"type":46,"value":985},"templates\u002F",{"type":46,"value":987},", or ",{"type":40,"tag":86,"props":989,"children":991},{"className":990},[],[992],{"type":46,"value":993},"reference\u002F",{"type":46,"value":995}," subtree",{"type":46,"value":997}," of any\nkind. A mock or incomplete artifact in this skill's tree, even\none labeled ",{"type":40,"tag":107,"props":999,"children":1000},{},[1001],{"type":46,"value":1002},"\"reference\"",{"type":46,"value":1004},", is misleading: operators will read\nit as production-ready and security-cleared, neither of which\nthis skill can guarantee.",{"type":40,"tag":255,"props":1006,"children":1008},{"id":1007},"loading-order",[1009],{"type":46,"value":1010},"Loading order",{"type":40,"tag":1012,"props":1013,"children":1014},"ol",{},[1015,1035,1048],{"type":40,"tag":271,"props":1016,"children":1017},{},[1018,1020,1026,1028,1033],{"type":46,"value":1019},"Read this ",{"type":40,"tag":86,"props":1021,"children":1023},{"className":1022},[],[1024],{"type":46,"value":1025},"SKILL.md",{"type":46,"value":1027}," first to confirm the user's question is\nin scope ",{"type":40,"tag":57,"props":1029,"children":1030},{},[1031],{"type":46,"value":1032},"and",{"type":46,"value":1034}," that Argus is the right answer at all (vs.\nbuilding on the DOCA App Shield library — not covered by this\nbundle, vs. deploying nothing, vs. deploying observability\ninstead).",{"type":40,"tag":271,"props":1036,"children":1037},{},[1038],{"type":40,"tag":57,"props":1039,"children":1040},{},[1041,1043,1047],{"type":46,"value":1042},"For Argus's deployment shape, the four configuration axes,\nthe SIEM pairing surface, the error taxonomy, the\nobservability surface, and the safety policy (including the\ncalibration-period rule and the never-silently-disable rule),\nsee ",{"type":40,"tag":79,"props":1044,"children":1045},{"href":210},[1046],{"type":46,"value":210},{"type":46,"value":316},{"type":40,"tag":271,"props":1049,"children":1050},{},[1051],{"type":40,"tag":57,"props":1052,"children":1053},{},[1054,1056,1060],{"type":46,"value":1055},"For step-by-step workflows — configure, build, modify, run,\ntest, debug — see ",{"type":40,"tag":79,"props":1057,"children":1058},{"href":180},[1059],{"type":46,"value":180},{"type":46,"value":316},{"type":40,"tag":255,"props":1062,"children":1064},{"id":1063},"related-skills",[1065],{"type":46,"value":1066},"Related skills",{"type":40,"tag":267,"props":1068,"children":1069},{},[1070,1093,1113,1136,1157,1170,1213,1240],{"type":40,"tag":271,"props":1071,"children":1072},{},[1073,1081,1083,1092],{"type":40,"tag":79,"props":1074,"children":1075},{"href":96},[1076],{"type":40,"tag":86,"props":1077,"children":1079},{"className":1078},[],[1080],{"type":46,"value":103},{"type":46,"value":1082},"\n— the routing table to the public DOCA Argus Service Guide and\nthe rest of the public DOCA documentation set. The Argus URL is\nlisted under\n",{"type":40,"tag":79,"props":1084,"children":1085},{"href":629},[1086],{"type":40,"tag":86,"props":1087,"children":1089},{"className":1088},[],[1090],{"type":46,"value":1091},"## DOCA services",{"type":46,"value":316},{"type":40,"tag":271,"props":1094,"children":1095},{},[1096,1104,1106,1111],{"type":40,"tag":79,"props":1097,"children":1098},{"href":221},[1099],{"type":40,"tag":86,"props":1100,"children":1102},{"className":1101},[],[1103],{"type":46,"value":228},{"type":46,"value":1105}," — env preparation and\ninstall verification on the BlueField where the Argus container\nwill run, including the ",{"type":40,"tag":107,"props":1107,"children":1108},{},[1109],{"type":46,"value":1110},"I have no install yet",{"type":46,"value":1112}," path via the\npublic NGC DOCA container. This skill assumes its preconditions\nare satisfied on BlueField Arm.",{"type":40,"tag":271,"props":1114,"children":1115},{},[1116,1126,1128,1134],{"type":40,"tag":79,"props":1117,"children":1119},{"href":1118},"..\u002F..\u002Fdoca-version\u002FSKILL.md",[1120],{"type":40,"tag":86,"props":1121,"children":1123},{"className":1122},[],[1124],{"type":46,"value":1125},"doca-version",{"type":46,"value":1127}," — canonical DOCA\nversion-handling rules. Argus's container tag is version-bound;\nthis skill's ",{"type":40,"tag":86,"props":1129,"children":1131},{"className":1130},[],[1132],{"type":46,"value":1133},"## Version compatibility",{"type":46,"value":1135}," cross-links the\nfour-way match rule and adds the container-tag-lags-host-package\noverlay shared with every other DOCA service container.",{"type":40,"tag":271,"props":1137,"children":1138},{},[1139,1149,1151,1155],{"type":40,"tag":79,"props":1140,"children":1142},{"href":1141},"..\u002F..\u002Fdoca-structured-tools-contract\u002FSKILL.md",[1143],{"type":40,"tag":86,"props":1144,"children":1146},{"className":1145},[],[1147],{"type":46,"value":1148},"doca-structured-tools-contract",{"type":46,"value":1150}," —\nthe bundle's structured-tools precedence rule (detect \u002F prefer\n\u002F fall back \u002F report). The Command appendix in\n",{"type":40,"tag":79,"props":1152,"children":1153},{"href":180},[1154],{"type":46,"value":180},{"type":46,"value":1156}," honors this contract.",{"type":40,"tag":271,"props":1158,"children":1159},{},[1160,1168],{"type":40,"tag":79,"props":1161,"children":1162},{"href":572},[1163],{"type":40,"tag":86,"props":1164,"children":1166},{"className":1165},[],[1167],{"type":46,"value":579},{"type":46,"value":1169},"\n— general DOCA patterns. Argus is service-shaped not library-\nshaped, so the build \u002F modify \u002F first-app pattern there does\nnot apply directly, but the cross-library debug discipline\n(frontend-before-backend, env-before-program, never-invent-flags)\nremains useful when Argus reports an error that originated in\nthe container runtime or in a DOCA library it called.",{"type":40,"tag":271,"props":1171,"children":1172},{},[1173,1178,1180,1185,1187,1191,1193,1201,1203,1211],{"type":40,"tag":57,"props":1174,"children":1175},{},[1176],{"type":46,"value":1177},"DOCA App Shield library",{"type":46,"value":1179}," — the ",{"type":40,"tag":57,"props":1181,"children":1182},{},[1183],{"type":46,"value":1184},"library equivalent",{"type":46,"value":1186},", the\nlower-level introspection library a developer builds custom\nDPU-side tooling on top of. It is ",{"type":40,"tag":57,"props":1188,"children":1189},{},[1190],{"type":46,"value":75},{"type":46,"value":1192},"\n(policy-excluded from the public release); when Argus is\ngenuinely insufficient and the team needs to build their own\nsecurity product, route to the public docs via\n",{"type":40,"tag":79,"props":1194,"children":1195},{"href":96},[1196],{"type":40,"tag":86,"props":1197,"children":1199},{"className":1198},[],[1200],{"type":46,"value":103},{"type":46,"value":1202},".\nThe path-selection rule in\n",{"type":40,"tag":79,"props":1204,"children":1205},{"href":290},[1206],{"type":40,"tag":86,"props":1207,"children":1209},{"className":1208},[],[1210],{"type":46,"value":297},{"type":46,"value":1212},"\nroutes the user to Argus first for production security.",{"type":40,"tag":271,"props":1214,"children":1215},{},[1216,1226,1228,1238],{"type":40,"tag":79,"props":1217,"children":1219},{"href":1218},"..\u002Fdoca-dms\u002FSKILL.md",[1220],{"type":40,"tag":86,"props":1221,"children":1223},{"className":1222},[],[1224],{"type":46,"value":1225},"doca-dms",{"type":46,"value":1227}," and\n",{"type":40,"tag":79,"props":1229,"children":1231},{"href":1230},"..\u002Fdoca-firefly\u002FSKILL.md",[1232],{"type":40,"tag":86,"props":1233,"children":1235},{"className":1234},[],[1236],{"type":46,"value":1237},"doca-firefly",{"type":46,"value":1239}," — sibling service\nskills. The agent reading any two of these should see the same\nservice-skill shape (container, BlueField Arm, Container\nDeployment Guide as the canonical recipe, smoke-before-bulk,\nenv preconditions, config schema, version anchor is the\ncontainer tag) layered on top of a different per-service domain\n(DMS = device management via gNMI \u002F gNOI; Firefly = time\nsynchronization via PTP; Argus = runtime security via finding\nemission).",{"type":40,"tag":271,"props":1241,"children":1242},{},[1243,1253],{"type":40,"tag":79,"props":1244,"children":1246},{"href":1245},"..\u002F..\u002Fdoca-debug\u002FSKILL.md",[1247],{"type":40,"tag":86,"props":1248,"children":1250},{"className":1249},[],[1251],{"type":46,"value":1252},"doca-debug",{"type":46,"value":1254}," — the cross-cutting\ndebug ladder (install \u002F version \u002F build \u002F link \u002F runtime \u002F\nprogram \u002F driver). Argus-specific debug (no findings arriving,\ntoo many findings, findings not forwarded, performance impact)\noverlays on top of that ladder.",{"items":1256,"total":1358},[1257,1274,1288,1302,1314,1331,1344],{"slug":1258,"name":1258,"fn":1259,"description":1260,"org":1261,"tags":1262,"stars":20,"repoUrl":21,"updatedAt":1273},"accelerated-computing-cudf","accelerate data processing with cuDF","Official NVIDIA-authored guidance for NVIDIA cuDF GPU DataFrames, pandas acceleration, dask-cuDF, ETL, joins, groupby, CSV\u002FParquet I\u002FO, nullable semantics, and multi-GPU DataFrame workloads.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1263,1266,1269,1270],{"name":1264,"slug":1265,"type":15},"Data Analysis","data-analysis",{"name":1267,"slug":1268,"type":15},"Data Engineering","data-engineering",{"name":9,"slug":8,"type":15},{"name":1271,"slug":1272,"type":15},"Performance","performance","2026-07-14T05:28:43.176466",{"slug":1275,"name":1275,"fn":1276,"description":1277,"org":1278,"tags":1279,"stars":20,"repoUrl":21,"updatedAt":1287},"aiq-deploy","deploy and manage NVIDIA AI-Q infrastructure","Use when asked to install, deploy, run, validate, troubleshoot, or stop NVIDIA AI-Q Blueprint infrastructure.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1280,1283,1286],{"name":1281,"slug":1282,"type":15},"Deployment","deployment",{"name":1284,"slug":1285,"type":15},"Infrastructure","infrastructure",{"name":9,"slug":8,"type":15},"2026-07-14T05:29:06.667109",{"slug":1289,"name":1289,"fn":1290,"description":1291,"org":1292,"tags":1293,"stars":20,"repoUrl":21,"updatedAt":1301},"aiq-research","conduct deep research with AI-Q","Use when asked to run deep research or AI-Q research through a reachable NVIDIA AI-Q Blueprint backend.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1294,1297,1298],{"name":1295,"slug":1296,"type":15},"Agents","agents",{"name":9,"slug":8,"type":15},{"name":1299,"slug":1300,"type":15},"Research","research","2026-07-14T05:28:06.816956",{"slug":1303,"name":1303,"fn":1304,"description":1305,"org":1306,"tags":1307,"stars":20,"repoUrl":21,"updatedAt":1313},"amc-run-sample-calibration","run AMC sample dataset calibration","Run end-to-end calibration on the shipped sample dataset (sdg_08_2_sample_data_010926.zip) against a running AMC microservice. Use when user says 'test sample dataset', 'run sample calibration', 'verify AMC install', or 'launch and test'.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1308,1309,1310],{"name":1264,"slug":1265,"type":15},{"name":9,"slug":8,"type":15},{"name":1311,"slug":1312,"type":15},"Testing","testing","2026-07-17T05:29:03.913266",{"slug":1315,"name":1315,"fn":1316,"description":1317,"org":1318,"tags":1319,"stars":20,"repoUrl":21,"updatedAt":1330},"amc-run-video-calibration","calibrate video datasets with AutoMagicCalib","Calibrate a new dataset from pre-recorded video files via the AutoMagicCalib REST API. Use when user has local MP4s and says 'calibrate my videos', 'run AMC on these videos', or similar. For RTSP\u002Flive streams, use amc-run-rtsp-calibration instead.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1320,1323,1326,1327],{"name":1321,"slug":1322,"type":15},"Automation","automation",{"name":1324,"slug":1325,"type":15},"Imaging","imaging",{"name":9,"slug":8,"type":15},{"name":1328,"slug":1329,"type":15},"Video","video","2026-07-17T05:28:53.905004",{"slug":1332,"name":1332,"fn":1333,"description":1334,"org":1335,"tags":1336,"stars":20,"repoUrl":21,"updatedAt":1343},"amc-setup-calibration-stack","deploy AutoMagicCalib microservice with Docker","Launch AutoMagicCalib microservice and web UI from NGC release images via Docker Compose. Use when user says 'deploy auto calibration', 'launch auto calibration', 'launch AMC', 'start MS+UI', or 'set up auto-magic-calib'. Requires NGC API key.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1337,1338,1341,1342],{"name":1281,"slug":1282,"type":15},{"name":1339,"slug":1340,"type":15},"Docker","docker",{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},"2026-07-17T05:28:56.913999",{"slug":1345,"name":1345,"fn":1346,"description":1347,"org":1348,"tags":1349,"stars":20,"repoUrl":21,"updatedAt":1357},"cudaq-guide","develop quantum applications with CUDA-Q","CUDA-Q onboarding guide for installation, test programs, GPU simulation, QPU hardware, and quantum applications.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1350,1351,1354],{"name":9,"slug":8,"type":15},{"name":1352,"slug":1353,"type":15},"Quantum Computing","quantum-computing",{"name":1355,"slug":1356,"type":15},"Simulation","simulation","2026-07-14T05:26:58.898253",305,{"items":1360,"total":1511},[1361,1379,1395,1406,1418,1432,1445,1459,1470,1479,1493,1502],{"slug":1362,"name":1362,"fn":1363,"description":1364,"org":1365,"tags":1366,"stars":1376,"repoUrl":1377,"updatedAt":1378},"nemoclaw-user-guide","retrieve NemoClaw documentation and configuration","Guides human users' AI agents to the NemoClaw docs MCP server and canonical Fern documentation in Markdown form. Use when users ask how to install, configure, operate, troubleshoot, secure, or learn NemoClaw with an AI coding assistant. Trigger keywords - nemoclaw docs, use nemoclaw with ai agent, nemoclaw mcp docs, nemoclaw install help, nemoclaw quickstart, nemoclaw markdown docs, llms.txt, agent skills.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1367,1370,1373],{"name":1368,"slug":1369,"type":15},"Documentation","documentation",{"name":1371,"slug":1372,"type":15},"MCP","mcp",{"name":1374,"slug":1375,"type":15},"Search","search",21777,"https:\u002F\u002Fgithub.com\u002FNVIDIA\u002FNemoClaw","2026-07-20T06:00:01.461044",{"slug":1380,"name":1380,"fn":1381,"description":1382,"org":1383,"tags":1384,"stars":1392,"repoUrl":1393,"updatedAt":1394},"mcore-build-and-dependency","manage Megatron-LM development environments","Container-based dev environment setup and dependency management for Megatron-LM. Covers acquiring and launching the CI container, uv package management, and updating uv.lock.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1385,1388,1389],{"name":1386,"slug":1387,"type":15},"Containers","containers",{"name":1281,"slug":1282,"type":15},{"name":1390,"slug":1391,"type":15},"Python","python",17049,"https:\u002F\u002Fgithub.com\u002FNVIDIA\u002FMegatron-LM","2026-07-27T06:06:11.249662",{"slug":1396,"name":1396,"fn":1397,"description":1398,"org":1399,"tags":1400,"stars":1392,"repoUrl":1393,"updatedAt":1405},"mcore-bump-base-image","update NVIDIA PyTorch base images","Bump the NVIDIA PyTorch base image (`nvcr.io\u002Fnvidia\u002Fpytorch:YY.MM-py3`) used by Megatron-LM CI. Covers the two pin sites (GitHub CI in `docker\u002F.ngc_version.dev` and GitLab CI in `.gitlab\u002Fstages\u002F01.build.yml`), the post-bump CI loop (re-run functional tests, refresh golden values, mark broken tests), and the gotchas that bit PRs",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1401,1404],{"name":1402,"slug":1403,"type":15},"CI\u002FCD","ci-cd",{"name":1281,"slug":1282,"type":15},"2026-07-14T05:25:59.97109",{"slug":1407,"name":1407,"fn":1408,"description":1409,"org":1410,"tags":1411,"stars":1392,"repoUrl":1393,"updatedAt":1417},"mcore-cicd","manage CI\u002FCD pipelines for Megatron-LM","CI\u002FCD reference for Megatron-LM. Covers CI pipeline structure, PR scope labels, triggering internal GitLab CI (which force-pushes the current branch to a pull-request\u002FBRANCH ref — always dry-run and verify the destination first; never run against shared or protected branches), and CI failure investigation.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1412,1413,1414],{"name":1402,"slug":1403,"type":15},{"name":1281,"slug":1282,"type":15},{"name":1415,"slug":1416,"type":15},"GitHub","github","2026-07-27T06:06:12.278222",{"slug":1419,"name":1419,"fn":1420,"description":1421,"org":1422,"tags":1423,"stars":1392,"repoUrl":1393,"updatedAt":1431},"mcore-create-issue","investigate CI failures and create issues","Investigate a failing GitHub Actions run or job and create a GitHub issue for the failure.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1424,1427,1428],{"name":1425,"slug":1426,"type":15},"Debugging","debugging",{"name":1415,"slug":1416,"type":15},{"name":1429,"slug":1430,"type":15},"Triage","triage","2026-07-14T05:25:57.442089",{"slug":1433,"name":1433,"fn":1434,"description":1435,"org":1436,"tags":1437,"stars":1392,"repoUrl":1393,"updatedAt":1444},"mcore-linting-and-formatting","lint and format Megatron-LM code","Linting and formatting for Megatron-LM. Covers running autoformat.sh, tools (ruff, black, isort, pylint, mypy), and code style rules.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1438,1441],{"name":1439,"slug":1440,"type":15},"Best Practices","best-practices",{"name":1442,"slug":1443,"type":15},"Code Analysis","code-analysis","2026-07-14T05:25:56.18433",{"slug":1446,"name":1446,"fn":1447,"description":1448,"org":1449,"tags":1450,"stars":1392,"repoUrl":1393,"updatedAt":1458},"mcore-migrate-gpt-to-hybrid","migrate Megatron-LM models to HybridModel","Migration guide for moving Megatron Core GPTModel checkpoints, model providers, training commands, and layer mappings to HybridModel.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1451,1454,1457],{"name":1452,"slug":1453,"type":15},"Machine Learning","machine-learning",{"name":1455,"slug":1456,"type":15},"Migration","migration",{"name":9,"slug":8,"type":15},"2026-07-17T06:07:11.777011",{"slug":1460,"name":1460,"fn":1461,"description":1462,"org":1463,"tags":1464,"stars":1392,"repoUrl":1393,"updatedAt":1469},"mcore-onboard-gb200-1node-tests","onboard functional tests for GB200","Onboard 1-node GitHub MR functional tests for GB200 from existing mr-scoped 2-node tests.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1465,1468],{"name":1466,"slug":1467,"type":15},"QA","qa",{"name":1311,"slug":1312,"type":15},"2026-07-14T05:25:53.673039",{"slug":1471,"name":1471,"fn":1472,"description":1473,"org":1474,"tags":1475,"stars":1392,"repoUrl":1393,"updatedAt":1478},"mcore-run-on-slurm","launch distributed training jobs on SLURM","How to launch distributed Megatron-LM training jobs on a SLURM cluster. Covers a minimal sbatch skeleton, environment-variable setup for torch.distributed.run, CUDA_DEVICE_MAX_CONNECTIONS rules across hardware and parallelism modes, container conventions, monitoring, and per-rank failure diagnosis.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1476,1477],{"name":1281,"slug":1282,"type":15},{"name":1284,"slug":1285,"type":15},"2026-07-14T05:25:49.362534",{"slug":1480,"name":1480,"fn":1481,"description":1482,"org":1483,"tags":1484,"stars":1392,"repoUrl":1393,"updatedAt":1492},"mcore-split-pr","split pull requests to reduce review load","Split a PR into multiple PRs to reduce the number of required CODEOWNERS reviewer groups.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1485,1488,1489],{"name":1486,"slug":1487,"type":15},"Code Review","code-review",{"name":1415,"slug":1416,"type":15},{"name":1490,"slug":1491,"type":15},"Pull Requests","pull-requests","2026-07-14T05:26:01.226578",{"slug":1494,"name":1494,"fn":1495,"description":1496,"org":1497,"tags":1498,"stars":1392,"repoUrl":1393,"updatedAt":1501},"mcore-testing","run and manage Megatron-LM tests","Test system for Megatron-LM. Covers test layout, recipe YAML structure, adding and running unit and functional tests, golden values, marker filters, and CI parity.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1499,1500],{"name":1466,"slug":1467,"type":15},{"name":1311,"slug":1312,"type":15},"2026-07-14T05:25:54.928983",{"slug":1503,"name":1503,"fn":1504,"description":1505,"org":1506,"tags":1507,"stars":1392,"repoUrl":1393,"updatedAt":1510},"nightly-sync","manage nightly main-to-dev sync workflows","Domain knowledge for the nightly main-to-dev sync workflow. Covers merge strategy, CI architecture, failure investigation, and known issues.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":9},[1508,1509],{"name":1321,"slug":1322,"type":15},{"name":1402,"slug":1403,"type":15},"2026-07-30T05:29:03.275638",496]