How Anthropic Cybersecurity Skills Align with the NIST AI Risk Management Framework

The Anthropic Cybersecurity Skills repository maps every skill to the NIST AI Risk Management Framework using the nist_ai_rmf field in each skill's YAML front-matter, enabling AI agents to filter and execute security workflows based on specific risk management functions like Govern, Map, Measure, and Manage.

The Anthropic Cybersecurity Skills repository provides a structured approach to aligning security operations with the NIST AI Risk Management Framework (AI RMF). By embedding AI RMF sub-category identifiers directly into skill definitions, the repository transforms generic cybersecurity procedures into traceable, risk-aware actions that AI agents can programmatically select and audit according to the mukul975/Anthropic-Cybersecurity-Skills source code.

How Skills Map to the NIST AI Risk Management Framework

Front-Matter Schema for AI RMF Compliance

Each skill in the repository stores its metadata in YAML front-matter at the top of its SKILL.md file. The key field nist_ai_rmf contains an array of sub-category identifiers that explicitly link the skill to the NIST AI RMF taxonomy.

---
name: analyzing-network-traffic-of-malware
nist_ai_rmf:
  - MEASURE-2.6

# ... other metadata

---

The AI RMF defines 4 core functions—Govern, Map, Measure, and Manage—which are further broken down into 72 sub-categories describing concrete AI risk management activities. When a skill lists MEASURE-2.6 in its nist_ai_rmf array, it indicates that executing this skill satisfies the AI RMF requirement to "measure AI model performance and residual risk."

Cross-Framework Coverage

The repository provides simultaneous mapping to multiple security frameworks, allowing AI agents to operate across compliance boundaries:

Framework Mapping Field in SKILL.md Example Value
NIST AI RMF nist_ai_rmf [MEASURE-2.6]
NIST CSF 2.0 nist_csf [DE.CM-01]
MITRE ATT&CK atlas_techniques / d3fend_techniques AML.T0047
MITRE ATLAS atlas_techniques AML.T0047
MITRE D3FEND d3fend_techniques D3-MA

For example, the skill analyzing-network-traffic-of-malware simultaneously maps to AI RMF sub-category MEASURE-2.6, NIST CSF identifiers, and MITRE ATLAS techniques. This multi-framework alignment enables agents to discover the skill based on governance intent while executing concrete security workflows.

Runtime Filtering by AI RMF Sub-Categories

During runtime, an AI agent can filter the skill set using the nist_ai_rmf field to surface only capabilities that satisfy a specific governance or risk-mitigation need. This enables three critical operations:

  1. Discover skills based on AI risk management intent (e.g., filtering for all skills tagged MEASURE-2.6 to assess residual risk).
  2. Execute concrete security workflows (e.g., capturing network traffic, running malware sandboxing, and generating risk metrics).
  3. Report findings back to the AI RMF governance process (e.g., feeding measurements into a risk dashboard).

By embedding AI RMF references directly in skills/<skill>/SKILL.md, the repository turns generic security procedures into AI-risk-aware actions that can be programmatically selected, audited, and traced to the NIST framework.

Programmatically Querying Skills by AI RMF Category

You can extract and filter skills by AI RMF sub-category using Python to parse the YAML front-matter. The following script loads all skills from the skills/ directory and prints those matching a specific AI RMF identifier:

import yaml
import pathlib
import re

def load_frontmatter(skill_path: pathlib.Path) -> dict:
    """Parse the YAML front-matter at the top of a SKILL.md file."""
    text = skill_path.read_text()
    # Front-matter is bounded by --- lines

    fm = re.search(r'^---\n(.*?)\n---', text, re.DOTALL).group(1)
    return yaml.safe_load(fm)

def skills_by_ai_rmf(subcategory: str):
    root = pathlib.Path("skills")
    for skill_dir in root.iterdir():
        md = skill_dir / "SKILL.md"
        if not md.exists():
            continue
        fm = load_frontmatter(md)
        ai_rmfs = fm.get("nist_ai_rmf", [])
        if subcategory in ai_rmfs:
            print(f"{fm['name']} → {ai_rmfs}")

if __name__ == "__main__":
    # Example: list all skills that measure AI model risk (MEASURE-2.6)

    skills_by_ai_rmf("MEASURE-2.6")

This pattern applies to any AI RMF sub-category (e.g., GOVERN-1.3, MANAGE-4.2) to drive policy-driven skill selection. The script reads each SKILL.md front-matter, looks for the nist_ai_rmf key, and lists matching skills.

Summary

  • The repository uses the nist_ai_rmf field in skills/<skill>/SKILL.md front-matter to declare alignment with the NIST AI Risk Management Framework.
  • Skills map to the AI RMF's 4 core functions and 72 sub-categories, such as MEASURE-2.6 for measuring residual risk.
  • Cross-framework coverage allows simultaneous alignment with NIST CSF 2.0, MITRE ATT&CK, ATLAS, and D3FEND.
  • Agents can filter skills at runtime by AI RMF sub-category to ensure security actions match governance requirements.
  • The ATTACK_COVERAGE.md file and individual SKILL.md files provide traceability for audit and compliance workflows.

Frequently Asked Questions

What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework developed by the National Institute of Standards and Technology to help organizations manage risks associated with AI systems. It organizes risk management activities into four core functions—Govern, Map, Measure, and Manage—comprising 72 sub-categories that define specific controls and activities. The Anthropic Cybersecurity Skills repository references these sub-categories (e.g., MEASURE-2.6) to tag skills with their risk management purpose.

How do I find skills for a specific AI RMF sub-category?

You can filter skills by parsing the nist_ai_rmf field in each skill's front-matter. Use the provided Python script to iterate through the skills/ directory, load each SKILL.md file, and check for your target sub-category identifier. Alternatively, consult the ATTACK_COVERAGE.md file in the repository root, which summarizes AI RMF coverage across the entire skill set.

Can a single skill map to multiple frameworks simultaneously?

Yes. A single skill can declare alignment with multiple frameworks in its front-matter. For example, the analyzing-network-traffic-of-malware skill includes both nist_ai_rmf: [MEASURE-2.6] and MITRE ATLAS identifiers in the same file. This multi-framework tagging allows AI agents to satisfy diverse compliance requirements using unified security workflows.

Where is the AI RMF mapping defined in the repository?

The mapping is defined in the YAML front-matter of individual skill files located at skills/<skill-name>/SKILL.md. The repository overview in README.md explains the mapping scheme, while ATTACK_COVERAGE.md provides a summary table of AI RMF coverage across all skills. Each skill explicitly lists its nist_ai_rmf sub-categories to ensure traceability to the NIST framework.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →