framework-gap-analysis

Analyze compliance framework controls against current attacker TTPs to produce structured gap declarations.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill framework-gap-analysis
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: framework-gap-analysis
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/framework-gap-analysis
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill framework-gap-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Compliance frameworks like NIST 800-53, ISO 27001, and SOC 2 were designed for pre-AI, network-centric threat models and lag years behind mid-2026 attack patterns. Organizations regularly pass audits for controls that are fully bypassed by current attacker TTPs, creating unaddressed risk masked as compliance.

Core Features & Use Cases

  • Pre-Analyzed Gap Catalog: Built-in documentation of proven gaps for common controls (e.g., NIST 800-53 SI-2, ISO 27001 A.8.8) paired with real CVE evidence and MITRE ATLAS/ATT&CK TTP mappings.
  • Structured Gap Declarations: Generates standardized, audit-ready gap declarations with RWEP-justified remediation requirements, global jurisdictional cross-walks, and D3FEND defensive technique mappings.
  • Compliance Theater Detection: Includes a built-in test to identify when claimed compensating controls are effectively useless against current threats.
  • Use Case: A security team evaluating NIST 800-53 AC-2 for AI agent access control can input the control ID and prompt injection threat scenario to get a documented gap showing the control is fully bypassed by AML.T0051, plus concrete remediation steps.

Quick Start

Use the framework-gap-analysis skill to produce a gap declaration for PCI DSS 4.0 Requirement 6.3.3 against AI-accelerated exploit weaponization.

Frequently Asked Questions about framework-gap-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check if NIST 800-53 or ISO 27001 controls cover AI prompt injection threats?

To check compliance control coverage for AI prompt injection, you map current attacker TTPs against framework requirements. This reveals unaddressed threat exposure where legacy controls are fully bypassed by emerging attack patterns.

What is compliance theater detection in security frameworks?

Compliance theater detection identifies when claimed compensating controls are effectively useless against current threats. It tests whether passing audits masks unaddressed risk by evaluating control efficacy against modern attack techniques.

How do I generate a gap declaration for PCI DSS 4.0 against new exploit weaponization?

You generate a gap declaration for PCI DSS by analyzing the gap between compliance requirements and live attacker TTPs. The output includes structured, audit-ready documentation with remediation requirements and D3FEND defensive technique mappings.

Can I map MITRE ATLAS techniques to specific NIST 800-53 control gaps?

Yes, you can map MITRE ATLAS techniques to NIST 800-53 control gaps. The Skill pairs real CVE evidence and TTP mappings with control IDs to document when specific controls are bypassed by AI threats.

Does this framework gap analysis support global jurisdictional cross-walks for compliance?

Framework gap analysis supports global jurisdictional cross-walks by producing structured gap declarations. These declarations map control efficacy failures across multiple compliance regimes against mid-2026 attack patterns.

What are the limitations of using traditional compliance frameworks against ephemeral infrastructure risks?

Traditional compliance frameworks lag years behind ephemeral infrastructure risks because they were designed for pre-AI, network-centric threat models. They often pass audits for controls fully bypassed by current attacker TTPs, masking unaddressed risk.