How Skills Integrate with NIST CSF 2.0 for Compliance Mapping

Anthropic Cybersecurity Skills embeds NIST CSF 2.0 compliance directly into every skill’s metadata and documentation, enabling automated evidence collection and gap analysis through machine-readable front-matter declarations and a repository-wide alignment matrix.

The mukul975/Anthropic-Cybersecurity-Skills repository provides a structured framework for AI-driven security automation, where each skill is pre-mapped to the NIST Cybersecurity Framework 2.0. This integration allows organizations to programmatically filter capabilities by CSF functions, generate audit reports, and validate compliance posture without manual cross-referencing of controls.

Front-Matter Metadata Declarations

Each skill in the repository includes a SKILL.md file that contains a nist_csf field in its YAML front-matter. This field lists the exact CSF categories and sub-categories the skill satisfies.

In skills/validating-backup-integrity-for-recovery/SKILL.md, lines 17-22 declare alignment with recovery-related categories such as RC.RP-03 (Backup Integrity Verification). The front-matter structure follows this pattern:

---
name: "Validating Backup Integrity for Recovery"
nist_csf:
  - "RS.MA-01"
  - "RS.MA-02"
  - "RS.AN-03"
  - "RC.RP-01"
---

Reference Documentation and Citations

Beyond metadata tags, each skill includes authoritative citations in its reference documentation. The references/standards.md file (or the standards section within SKILL.md lines 30-31) provides the formal NIST CSF 2.0 citation, ensuring auditors can trace every mapping to its official source. For example, the backup integrity skill cites "NIST CSF 2.0 RC.RP-03: Backup Integrity Verification" to establish provenance.

Global CSF Alignment Matrix

The repository maintains a centralized mapping document at mappings/nist-csf/csf-alignment.md that cross-references every security subdomain to the six CSF functions: Govern, Identify, Protect, Detect, Respond, and Recover.

Lines 24-27 of this file demonstrate how the incident-response subdomain maps to both the Respond (RS) and Recover (RC) functions, covering categories such as RS.MA (Mitigation), RS.AN (Analysis), and RC.RP (Recovery Planning). This matrix enables high-level gap analysis across the entire skill library.

Runtime Integration and Automation

AI agents can consume these mappings programmatically to drive compliance workflows. Each skill includes a runtime script—typically located at scripts/agent.py—that exposes the CSF tags via command-line arguments such as --nist-csf. This allows downstream tools to:

  • Filter skill execution by CSF category
  • Generate evidence logs mapped to specific controls
  • Automate policy verification against current framework requirements

Programmatic Compliance Workflows

Security teams can leverage Python scripts to extract and operationalize these mappings for automated compliance reporting.

Extracting CSF Categories from Skill Metadata

The following script parses the YAML front-matter of any SKILL.md file to retrieve its NIST CSF classifications:

import yaml
import pathlib

def load_nist_csf(skill_path: pathlib.Path) -> list[str]:
    """Return the list of NIST CSF categories defined in a skill."""
    with open(skill_path, "r", encoding="utf-8") as f:
        # Front-matter starts and ends with ---; yaml.safe_load parses it.

        front = ""
        for line in f:
            if line.strip() == "---":
                if front:
                    break          # second --- ends front-matter

                continue
            front += line
    data = yaml.safe_load(front)
    return data.get("nist_csf", [])

# Example – get CSF tags for the backup-validation skill

skill_file = pathlib.Path(
    "skills/validating-backup-integrity-for-recovery/SKILL.md"
)
csf_tags = load_nist_csf(skill_file)
print("NIST CSF tags:", csf_tags)

# Output: NIST CSF tags: ['RS.MA-01', 'RS.MA-02', 'RS.AN-03', 'RC.RP-01']

Filtering Skills by CSF Category

To identify all skills that satisfy a specific control, iterate through the repository and filter by the nist_csf field:

import pathlib, yaml

def skills_for_csf(category: str) -> list[pathlib.Path]:
    """Return a list of skill directories that map to the given CSF category."""
    matches = []
    for skill_md in pathlib.Path("skills").rglob("SKILL.md"):
        with open(skill_md) as f:
            front = ""
            for line in f:
                if line.strip() == "---":
                    if front:
                        break
                    continue
                front += line
        if category in yaml.safe_load(front).get("nist_csf", []):
            matches.append(skill_md.parent)
    return matches

# Find all skills that contribute to RC.RP (Recover – Recovery Planning)

recovery_skills = skills_for_csf("RC.RP-03")
print(f"Found {len(recovery_skills)} skills for RC.RP-03")

Generating Compliance Reports from the Alignment Table

Parse the global alignment matrix to map subdomains to CSF functions for executive reporting:

import csv
from pathlib import Path

ALIGNMENT_CSV = Path("mappings/nist-csf/csf-alignment.md")

def parse_alignment() -> dict[str, list[str]]:
    """Parse the markdown table into a dict {CSF function → [subdomains]}."""
    mapping = {}
    with open(ALIGNMENT_CSV) as f:
        for line in f:
            if line.startswith("|") and "Subdomain" not in line:
                cols = [c.strip() for c in line.strip("|\n").split("|")]
                # Columns: Subdomain | Skills | GV | ID | PR | PR | DE | RS | RC

                functions = ["GV", "ID", "PR", "PR", "DE", "RS", "RC"]
                subdomain = cols[0]
                for fn, val in zip(functions, cols[3:]):
                    if val:
                        mapping.setdefault(fn, []).append(subdomain)
    return mapping

alignment = parse_alignment()
print("Subdomains mapped to the Recover (RC) function:", alignment.get("RC"))

# Example output: ['incident-response', 'ransomware-defense']

Summary

  • Front-matter mapping: Every SKILL.md file declares its NIST CSF 2.0 categories in machine-readable YAML metadata at lines 17-22.
  • Reference citations: Authoritative standard references are embedded in references/standards.md files (documented at lines 30-31 of skill definitions) for audit traceability.
  • Global alignment: The mappings/nist-csf/csf-alignment.md matrix cross-references all skills to the six CSF functions, with subdomain mappings documented at lines 24-27.
  • Runtime automation: scripts/agent.py exposes --nist-csf arguments for filtering and automated compliance checks.
  • Programmatic access: Python scripts can extract metadata, filter skills by control, and generate compliance reports without manual intervention.

Frequently Asked Questions

What NIST CSF 2.0 functions are covered by the alignment matrix?

The alignment matrix in mappings/nist-csf/csf-alignment.md covers all six CSF functions: Govern (GV), Identify (ID), Protect (PR), Detect (DE), Respond (RS), and Recover (RC). Each subdomain within the repository maps to one or more of these functions, ensuring comprehensive framework coverage.

How can I find all skills mapped to a specific CSF category?

Use the Python filtering script to search the nist_csf field across all SKILL.md files. For example, calling skills_for_csf("RC.RP-03") returns every skill directory that contributes to the Backup Integrity Verification control, enabling targeted gap remediation.

Can these skills generate automatic compliance reports for auditors?

Yes. The runtime scripts/agent.py accepts --nist-csf arguments to expose control tags, while the alignment matrix and front-matter metadata provide the structured data needed to generate evidence logs. Security teams can programmatically compile audit-ready reports that map skill execution directly to NIST CSF 2.0 requirements.

Where is the authoritative NIST CSF 2.0 citation stored for each skill?

Each skill stores its authoritative citation in the references/standards.md file (or the references section of SKILL.md), documenting the specific CSF categories and sub-categories satisfied. For example, the backup validation skill cites "NIST CSF 2.0 RC.RP-03" to establish clear provenance for compliance mapping.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →