nist-ai-rmf

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a reference and assessment tool for the NIST AI Risk Management Framework. All content is descriptive markdown and reference material.- [NO_CODE]: No scripts, executables, or code snippets are present in the skill distribution. It operates entirely through prompt instructions and text processing.- [EXTERNAL_DOWNLOADS]: The skill contains URLs to official NIST documentation and academic research (arXiv, OECD, etc.), which are well-known and trusted sources. No runtime downloads or installations are performed.- [PROMPT_INJECTION]: The skill processes user-provided descriptions of AI systems for analysis. The risk of indirect prompt injection is mitigated by the skill's strict instructions to use verbatim text from local reference files and to clearly label all AI-generated assessments and recommendations. The skill has no capabilities beyond generating markdown output, limiting the potential impact of adversarial input.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 08:53 AM
Security Audit — agent-trust-hub — nist-ai-rmf