# How Anthropic Cybersecurity Skills Align with the NIST AI Risk Management Framework

> Discover how Anthropic Cybersecurity Skills map to the NIST AI Risk Management Framework AI RMF. Filter security workflows by Govern, Map, Measure, and Manage functions.

- Repository: [Mahipal/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills)
- Tags: deep-dive
- Published: 2026-05-24

---

**The Anthropic Cybersecurity Skills repository maps every skill to the NIST AI Risk Management Framework using the `nist_ai_rmf` field in each skill's YAML front-matter, enabling AI agents to filter and execute security workflows based on specific risk management functions like Govern, Map, Measure, and Manage.**

The Anthropic Cybersecurity Skills repository provides a structured approach to aligning security operations with the NIST AI Risk Management Framework (AI RMF). By embedding AI RMF sub-category identifiers directly into skill definitions, the repository transforms generic cybersecurity procedures into traceable, risk-aware actions that AI agents can programmatically select and audit according to the mukul975/Anthropic-Cybersecurity-Skills source code.

## How Skills Map to the NIST AI Risk Management Framework

### Front-Matter Schema for AI RMF Compliance

Each skill in the repository stores its metadata in YAML front-matter at the top of its [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file. The key field `nist_ai_rmf` contains an array of sub-category identifiers that explicitly link the skill to the NIST AI RMF taxonomy.

```yaml
---
name: analyzing-network-traffic-of-malware
nist_ai_rmf:
  - MEASURE-2.6

# ... other metadata

---

```

The AI RMF defines **4 core functions**—**Govern**, **Map**, **Measure**, and **Manage**—which are further broken down into **72 sub-categories** describing concrete AI risk management activities. When a skill lists `MEASURE-2.6` in its `nist_ai_rmf` array, it indicates that executing this skill satisfies the AI RMF requirement to "measure AI model performance and residual risk."

### Cross-Framework Coverage

The repository provides simultaneous mapping to multiple security frameworks, allowing AI agents to operate across compliance boundaries:

| Framework | Mapping Field in [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) | Example Value |
|-----------|----------------------------|---------------|
| NIST AI RMF | `nist_ai_rmf` | `[MEASURE-2.6]` |
| NIST CSF 2.0 | `nist_csf` | `[DE.CM-01]` |
| MITRE ATT&CK | `atlas_techniques` / `d3fend_techniques` | `AML.T0047` |
| MITRE ATLAS | `atlas_techniques` | `AML.T0047` |
| MITRE D3FEND | `d3fend_techniques` | `D3-MA` |

For example, the skill **`analyzing-network-traffic-of-malware`** simultaneously maps to AI RMF sub-category **MEASURE-2.6**, NIST CSF identifiers, and MITRE ATLAS techniques. This multi-framework alignment enables agents to discover the skill based on governance intent while executing concrete security workflows.

## Runtime Filtering by AI RMF Sub-Categories

During runtime, an AI agent can filter the skill set using the `nist_ai_rmf` field to surface only capabilities that satisfy a specific governance or risk-mitigation need. This enables three critical operations:

1. **Discover** skills based on AI risk management intent (e.g., filtering for all skills tagged `MEASURE-2.6` to assess residual risk).
2. **Execute** concrete security workflows (e.g., capturing network traffic, running malware sandboxing, and generating risk metrics).
3. **Report** findings back to the AI RMF governance process (e.g., feeding measurements into a risk dashboard).

By embedding AI RMF references directly in `skills/<skill>/SKILL.md`, the repository turns generic security procedures into *AI-risk-aware* actions that can be programmatically selected, audited, and traced to the NIST framework.

## Programmatically Querying Skills by AI RMF Category

You can extract and filter skills by AI RMF sub-category using Python to parse the YAML front-matter. The following script loads all skills from the `skills/` directory and prints those matching a specific AI RMF identifier:

```python
import yaml
import pathlib
import re

def load_frontmatter(skill_path: pathlib.Path) -> dict:
    """Parse the YAML front-matter at the top of a SKILL.md file."""
    text = skill_path.read_text()
    # Front-matter is bounded by --- lines

    fm = re.search(r'^---\n(.*?)\n---', text, re.DOTALL).group(1)
    return yaml.safe_load(fm)

def skills_by_ai_rmf(subcategory: str):
    root = pathlib.Path("skills")
    for skill_dir in root.iterdir():
        md = skill_dir / "SKILL.md"
        if not md.exists():
            continue
        fm = load_frontmatter(md)
        ai_rmfs = fm.get("nist_ai_rmf", [])
        if subcategory in ai_rmfs:
            print(f"{fm['name']} → {ai_rmfs}")

if __name__ == "__main__":
    # Example: list all skills that measure AI model risk (MEASURE-2.6)

    skills_by_ai_rmf("MEASURE-2.6")

```

This pattern applies to any AI RMF sub-category (e.g., `GOVERN-1.3`, `MANAGE-4.2`) to drive policy-driven skill selection. The script reads each [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) front-matter, looks for the `nist_ai_rmf` key, and lists matching skills.

## Summary

- The repository uses the `nist_ai_rmf` field in `skills/<skill>/SKILL.md` front-matter to declare alignment with the NIST AI Risk Management Framework.
- Skills map to the AI RMF's **4 core functions** and **72 sub-categories**, such as `MEASURE-2.6` for measuring residual risk.
- **Cross-framework coverage** allows simultaneous alignment with NIST CSF 2.0, MITRE ATT&CK, ATLAS, and D3FEND.
- Agents can **filter skills at runtime** by AI RMF sub-category to ensure security actions match governance requirements.
- The [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) file and individual [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) files provide traceability for audit and compliance workflows.

## Frequently Asked Questions

### What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework developed by the National Institute of Standards and Technology to help organizations manage risks associated with AI systems. It organizes risk management activities into four core functions—Govern, Map, Measure, and Manage—comprising 72 sub-categories that define specific controls and activities. The Anthropic Cybersecurity Skills repository references these sub-categories (e.g., `MEASURE-2.6`) to tag skills with their risk management purpose.

### How do I find skills for a specific AI RMF sub-category?

You can filter skills by parsing the `nist_ai_rmf` field in each skill's front-matter. Use the provided Python script to iterate through the `skills/` directory, load each [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file, and check for your target sub-category identifier. Alternatively, consult the [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) file in the repository root, which summarizes AI RMF coverage across the entire skill set.

### Can a single skill map to multiple frameworks simultaneously?

Yes. A single skill can declare alignment with multiple frameworks in its front-matter. For example, the `analyzing-network-traffic-of-malware` skill includes both `nist_ai_rmf: [MEASURE-2.6]` and MITRE ATLAS identifiers in the same file. This multi-framework tagging allows AI agents to satisfy diverse compliance requirements using unified security workflows.

### Where is the AI RMF mapping defined in the repository?

The mapping is defined in the YAML front-matter of individual skill files located at `skills/<skill-name>/SKILL.md`. The repository overview in [`README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md) explains the mapping scheme, while [`ATTACK_COVERAGE.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/ATTACK_COVERAGE.md) provides a summary table of AI RMF coverage across all skills. Each skill explicitly lists its `nist_ai_rmf` sub-categories to ensure traceability to the NIST framework.