Skip to content

Validate and sign the NV-Reason-CT skill - #68

Merged
wyli merged 2 commits into
devfrom
codex/nv-reason-ct-signing-20260923
Sep 23, 2026
Merged

wyli merged 2 commits into
devfrom
codex/nv-reason-ct-signing-20260923

Conversation

@wyli

@wyli wyli commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Purpose

Follow up on #67 with current-source managed evaluation and CI-generated signing artifacts for skills/nv-reason-ct/.

#67 was merged into dev as an explicitly approved unsigned engineering checkpoint. Its repository lint/tests and compliance passed, but managed evaluation failed during model-service preflight with HTTP 503, before skill trials ran. This follow-up does not treat that failure as a pass or carry forward an old signature.

Scope

  • Add one paragraph to EXAMPLES.md distinguishing local tests and the historical GPU baseline from managed evaluation and signing. Explain that a skill signature does not cover separately downloaded model code or weights, or replace explicit custom-code consent.
  • Request /nvskills-ci on this open, same-repository PR to evaluate the current skill and generate BENCHMARK.md, skill-card.md, and skill.oms.sig through the managed service.
  • No inference, dependency, fixture, test, evaluation-policy, or shared-infrastructure changes. No generated artifacts are authored or edited by hand.

Local validation

  • Offline skill tests: 125 passed, 5 skipped. The skips require separately staged upstream volumes or authorized live CUDA inference.
  • Skill frontmatter validation, repository-configured markdownlint, and whitespace checks passed.
  • These local tests do not represent fresh GPU inference. Managed evaluation and signature verification are recorded separately below.

Completed validation and signing

The final signed head is 243139ef9122074ae9a06587a05d7563862de1f4. Repository lint/tests, compliance, NVSkills CI, and the required-status check all pass on that revision. The signing-only follow-up verification also passed.

  • Repository lint/tests and compliance pass on the final head.
  • Managed evaluation passes for the current skill contents; coverage and report consistency reviewed.
  • The service generated public-safe BENCHMARK.md, skill-card.md, and skill.oms.sig.
  • Generated-only changes inspected; the final skill signature verifies against the current NVIDIA trust anchor with unsigned additions rejected.
  • Required checks pass on the final signed revision.

The combined benchmark reports PASS — Recommended for publication. All 47 evaluation attempts were scored without execution or judge-service errors, and both supported agents passed the report's aggregate dimension thresholds. This is not a claim that every individual task succeeded, or a fresh GPU-inference result. Static advisory findings remain visible in the generated report. The signing commit adds only the three generated artifacts and does not alter the evaluated source.

The NVIDIA/skills#608 catalog registration is open for review; catalog onboarding should be refreshed after this signed revision reaches dev. The manifest's immutable-public-model-revision requirement is not waived by this follow-up. The known security finding in the recorded historical environment remains disclosed; dependency compatibility and installation requirements remain upstream-owned.

AI-assisted: Created with Codex/GPT at the user's request.

Distinguish local test and historical inference evidence from current-source managed evaluation and signature verification. Clarify that the skill signature does not cover downloaded model assets or grant custom-code execution consent.

Co-authored-by: Codex <noreply@openai.com>
Signed-off-by: Wenqi Li <wenqil@nvidia.com>
@wyli wyli mentioned this pull request Sep 23, 2026
3 tasks
@wyli

wyli commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator Author

/nvskills-ci

@wyli
wyli marked this pull request as ready for review September 23, 2026 21:54
Signed-off-by: nvskills-svc-account <svc-nvskills-signing@nvidia.com>
@wyli
wyli merged commit 0cda282 into dev Sep 23, 2026
7 checks passed
@wyli
wyli deleted the codex/nv-reason-ct-signing-20260923 branch September 23, 2026 23:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants