nist-ai-rmf

Identify NIST AI RMF Subcategories and GenAI Profile actions with verbatim citations.

630|79|Updated Dec 18, 2025
One-click install
npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill nist-ai-rmf-lawve-ai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nist-ai-rmf
Source: https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/nist-ai-rmf-rafal-fryc
Command: npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill nist-ai-rmf-lawve-ai

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

The NIST AI RMF Skill enables organizations to apply the AI Risk Management Framework (NIST AI 100-1 + NIST AI 600-1) to a specific AI system, providing verbatim citations and structured output formats that map risks to core Subcategories and GenAI Profile actions for governance, measurement, and management. It serves as an auditable, stand-alone reference for policy, risk assessment, and governance workstreams.

Core Features & Use Cases

  • Three modes (Consult, Governance plan, Assessment) that generate mode-specific outputs using the official NIST frontmatter, core Subcategories, and GAI Profile actions, with inline verbatim citations.
  • Distinguishes GenAI vs non-GenAI contexts and loads the appropriate references, ensuring compliance across the AI lifecycle.
  • Produces machine-actionable artifacts suitable for risk governance, policy updates, and due-diligence reporting.

Quick Start

Describe your AI system and run this skill in consult mode to obtain a NIST-aligned risk snapshot.

Frequently Asked Questions about nist-ai-rmf

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I apply the NIST AI RMF to a specific AI system for risk governance?

The NIST AI RMF Skill distinguishes GenAI components from non-GenAI components by analyzing your system description, automatically loading the appropriate NIST AI 100-1 Core Subcategories or NIST AI 600-1 GenAI Profile actions with verbatim citations.

Can I generate a formal NIST AI risk assessment or governance plan?

Yes, the Skill supports three output modes—Consult, Governance plan, and Assessment—each generating mode-specific structured artifacts with official NIST frontmatter, Subcategory IDs, and Action IDs suitable for policy updates and risk reporting.

What is the difference between NIST AI 100-1 and NIST AI 600-1 framework profiles?

NIST AI 100-1 provides the Core Subcategories for general AI risk management, while NIST AI 600-1 provides the GenAI Profile actions for generative AI contexts. The Skill determines which applies based on your system's components.

Do I need verbatim NIST citations for my AI risk compliance audit?

Verbatim NIST citations are required for robust AI risk compliance audits. The Skill outputs structured Subcategory IDs and Action IDs with inline citations, plus an Open items section and recommended next steps for full auditability.