Validate and sign the NV-Reason-CT skill - #68
Merged
Merged
Conversation
Distinguish local test and historical inference evidence from current-source managed evaluation and signature verification. Clarify that the skill signature does not cover downloaded model assets or grant custom-code execution consent. Co-authored-by: Codex <noreply@openai.com> Signed-off-by: Wenqi Li <wenqil@nvidia.com>
Collaborator
Author
|
/nvskills-ci |
7 of 12 tasks
wyli
marked this pull request as ready for review
September 23, 2026 21:54
Signed-off-by: nvskills-svc-account <svc-nvskills-signing@nvidia.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Follow up on #67 with current-source managed evaluation and CI-generated signing artifacts for
skills/nv-reason-ct/.#67 was merged into
devas an explicitly approved unsigned engineering checkpoint. Its repository lint/tests and compliance passed, but managed evaluation failed during model-service preflight with HTTP 503, before skill trials ran. This follow-up does not treat that failure as a pass or carry forward an old signature.Scope
EXAMPLES.mddistinguishing local tests and the historical GPU baseline from managed evaluation and signing. Explain that a skill signature does not cover separately downloaded model code or weights, or replace explicit custom-code consent./nvskills-cion this open, same-repository PR to evaluate the current skill and generateBENCHMARK.md,skill-card.md, andskill.oms.sigthrough the managed service.Local validation
Completed validation and signing
The final signed head is
243139ef9122074ae9a06587a05d7563862de1f4. Repository lint/tests, compliance, NVSkills CI, and the required-status check all pass on that revision. The signing-only follow-up verification also passed.BENCHMARK.md,skill-card.md, andskill.oms.sig.The combined benchmark reports PASS — Recommended for publication. All 47 evaluation attempts were scored without execution or judge-service errors, and both supported agents passed the report's aggregate dimension thresholds. This is not a claim that every individual task succeeded, or a fresh GPU-inference result. Static advisory findings remain visible in the generated report. The signing commit adds only the three generated artifacts and does not alter the evaluated source.
The NVIDIA/skills#608 catalog registration is open for review; catalog onboarding should be refreshed after this signed revision reaches
dev. The manifest's immutable-public-model-revision requirement is not waived by this follow-up. The known security finding in the recorded historical environment remains disclosed; dependency compatibility and installation requirements remain upstream-owned.AI-assisted: Created with Codex/GPT at the user's request.