nist-ai-rmf

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily a collection of Markdown-based reference documents containing verbatim text from the NIST AI Risk Management Framework (NIST AI 100-1 and NIST AI 600-1). It does not include any executable code, scripts, or external dependencies.
  • [PROMPT_INJECTION]: The instructions in SKILL.md are designed to ensure safety and accuracy. It explicitly directs the agent to distinguish between official NIST text and 'model judgment', and to decline requests to invent information or provide legal advice. There are no patterns suggesting attempts to bypass underlying model safety filters.
  • [DATA_EXFILTRATION]: The skill does not utilize network-enabled tools. All operations are performed locally on the provided reference files. No access to sensitive user files or environment variables is requested.
  • [REMOTE_CODE_EXECUTION]: There are no commands that download or execute external scripts. The skill relies entirely on natural language processing of the provided context.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes user-provided descriptions of AI systems to generate assessments.
  • Ingestion points: User prompts describing an AI system, governance question, or impact assessment.
  • Boundary markers: The skill uses structured templates (references/templates/) and specific tags like [model judgment — verify against system specifics] to separate NIST text from generated analysis.
  • Capability inventory: The skill only reads Markdown files from the references/ directory. It has no capabilities for file writing, network access, or subprocess execution.
  • Sanitization: The skill enforces strict output formatting and verbatim citation requirements which act as structural constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:34 PM
Security Audit — agent-trust-hub — nist-ai-rmf