Agent skill

Nist Csf Specialist

by borghei in borghei/Claude-Skills

NIST Cybersecurity Framework 2.0 implementation, assessment, and compliance management.

MITAuto-check passedLegal & Compliance

Install Nist Csf Specialist

skills CLI
$ npx skills add borghei/Claude-Skills --skill nist-csf-specialist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills nist-csf-specialist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/nist-csf-specialist .claude/skills/nist-csf-specialist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nist-csf-specialist
GitHub stars
891
Token cost
~1.7k tokens
SKILL.md length
637 words
Files
8 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

NIST Cybersecurity Framework 2.0 implementation, assessment, and compliance management.

  • CSF 2.0 gap analysis
  • SKILL.md covers Core Capabilities, When to Use, Clarify First and Quick Start, plus 3 more sections
  • Runs Python scripts from its folder; calls python
  • Cybersecurity risk management

What it does

Nist Csf Specialist is an agent skill from borghei/Claude-Skills. NIST Cybersecurity Framework 2.0 implementation, assessment, and compliance management. Use for CSF 2.0 gap analysis, cybersecurity risk management, maturity assessment, CSF profiles, and cross-framework compliance mapping.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `references/assessment-and-roadmap.md`, `references/csf-functions-guide.md` and `references/csf-implementation-playbook.md`).

It sits in Legal & Compliance. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • CSF 2.0 gap analysis
  • Cybersecurity risk management
  • Maturity assessment
  • Cross-framework compliance mapping

Example prompts

  • “/nist-csf-specialist”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nist Csf Specialist loads about 1.7k tokens when it runs, and up to ~24k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 637 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~24k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 637 words, ~1,710 tokens.

Download SKILL.mdSave it as .claude/skills/nist-csf-specialist/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
nist-csf-specialist
description
NIST Cybersecurity Framework 2.0 implementation, assessment, and compliance management. Use for CSF 2.0 gap analysis, cybersecurity risk management, maturity assessment, CSF profiles, and cross-framework compliance mapping.
license
MIT + Commons Clause
metadata.version
1.1.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
cybersecurity-framework
metadata.updated
2026-06-15
metadata.tags
nist-csf, cybersecurity, maturity-assessment, risk-management

NIST CSF 2.0 Specialist

Implement, assess, and manage cybersecurity programs aligned with the NIST Cybersecurity Framework 2.0 — the definitive standard for organizational cybersecurity risk management. CSF 2.0 (Feb 2024) applies to all organizations and adds GOVERN as a sixth, top-level function alongside IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER.

Core Capabilities

  • Maturity assessment — score all 22 categories across 6 functions on the 1–4 tier scale (Partial → Risk Informed → Repeatable → Adaptive) with evidence-backed gap analysis
  • Profiles & gap analysis — build current and target profiles, then derive a prioritized, phased remediation roadmap
  • Cross-framework mapping — map CSF categories to ISO 27001:2022, SOC 2 TSC, HIPAA Security Rule, and PCI-DSS v4.0 to reduce dual-audit burden
  • Program implementation — 12-month phased roadmap covering governance, core protections, detection/response, and resilience

When to Use

Use this skill when you hear: "NIST cybersecurity framework", "CSF 2.0", "NIST compliance", "cybersecurity risk management", "NIST controls", "NIST assessment", "cybersecurity maturity", "NIST CSF profile", "cybersecurity governance", "cybersecurity program assessment", "CSF gap analysis", or "cross-framework compliance mapping".

Clarify First

Before running the assessment, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Target tier — Partial, Risk Informed, Repeatable, or Adaptive goal (drives the gap analysis and remediation roadmap)
  • Current-state data — the present maturity scores across the 6 functions / 22 categories (the scoring depends on it)
  • Task — maturity assessment, profile/gap analysis, or cross-framework mapping (selects the script and any target framework)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the maturity report.

Quick Start

bash
# Assess cybersecurity maturity against a target tier
python scripts/csf_maturity_assessor.py --input assessment.json --target-tier 3 --output maturity_report.json

# Map controls across frameworks
python scripts/csf_control_mapper.py --source-framework nist-csf --target-framework iso27001 --output mapping.json

# Generate a markdown gap analysis
python scripts/csf_maturity_assessor.py --input assessment.json --target-tier 4 --format markdown --output gap_analysis.md

# Build a multi-framework unified matrix
python scripts/csf_control_mapper.py --source-framework nist-csf --target-framework all --output unified_matrix.json

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • references/framework-reference.md — CSF 2.0 overview, the six functions with all categories (key activities, implementation guidance, maturity indicators), profiles, tiers, and the full cross-framework mapping tables (ISO 27001, SOC 2, HIPAA, PCI-DSS). Read when you need framework foundations or mapping detail.
  • references/assessment-and-roadmap.md — per-function assessment checklists, the 5-week maturity-assessment workflow, the 12-month implementation roadmap, validation checkpoints, and success criteria. Read when planning or running an engagement.
  • references/tools-and-troubleshooting.md — detailed tool capabilities, input JSON format, full usage examples, flag reference tables, and the troubleshooting guide. Read when running the scripts or debugging output.
  • references/csf-functions-guide.md — complete CSF 2.0 taxonomy: every function, category, subcategory, evidence requirement, and common assessment question. Read for subcategory-level depth during detailed assessment.
  • references/csf-implementation-playbook.md — step-by-step implementation guide with templates, prioritization, and budgeting. Read when standing up or maturing a program.
Show full SKILL.md (233 more words)Show less

Scope & Limitations

In Scope:

  • NIST CSF 2.0 maturity assessment across all 6 functions and 22 categories
  • Current and target profile creation with gap analysis
  • Cross-framework control mapping to ISO 27001:2022, SOC 2 TSC, HIPAA Security Rule, and PCI-DSS v4.0
  • Implementation roadmap generation with phased milestones
  • Tier-based scoring (Partial, Risk Informed, Repeatable, Adaptive)

Out of Scope:

  • NIST SP 800-53 control-level implementation (CSF is a framework, not a control catalog; use SP 800-53 for prescriptive controls)
  • Technical security testing, vulnerability scanning, or penetration testing (use infrastructure-compliance-auditor)
  • Sector-specific Community Profiles (the tool provides organizational profiles; community profiles require sector-specific customization)
  • Real-time security monitoring or SIEM configuration
  • Compliance certification (NIST CSF is voluntary and does not offer formal certification)
  • Legal or regulatory advice on specific compliance obligations

Integration Points

SkillIntegration
soc2-compliance-expertSOC 2 TSC maps directly to CSF functions; use the control mapper to generate a unified control matrix reducing dual-audit burden
information-security-manager-iso27001ISO 27001 Annex A controls are the implementation backbone for CSF categories; CSF maturity scores inform ISMS continual improvement
infrastructure-compliance-auditorValidates technical controls (access, encryption, monitoring, endpoints) that underpin PROTECT and DETECT function scores
pci-dss-specialistPCI-DSS v4.0 requirements map to CSF categories; use cross-framework mapper for payment environments
nis2-directive-specialistNIS2 Article 21 measures align to CSF functions; CSF maturity assessment benchmarks NIS2 compliance posture
dora-compliance-expertDORA ICT risk management pillars map to GOVERN and IDENTIFY functions; use CSF as the unifying assessment framework

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references) in ra-qm-team/nist-csf-specialist of borghei/Claude-Skills.

  • SKILL.md
  • references/assessment-and-roadmap.md
  • references/csf-functions-guide.md
  • references/csf-implementation-playbook.md
  • references/framework-reference.md
  • references/tools-and-troubleshooting.md
  • scripts/csf_control_mapper.py
  • scripts/csf_maturity_assessor.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Nist Csf Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nist Csf Specialist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nist Csf Specialist this skillborghei/Claude-Skills891—~1.7kAutomated safety check: PassMIT
Paper to Chinese Patent DrafterYuan1z0825/nature-skills47k1 repos~1.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Legal Clinic Client Intakeanthropics/claude-for-legal9.6k3 repos~3.2kAutomated safety check: PassApache-2.0
Paper To Cn Patentsnipp-zha/Paper-to-patent-Skill1071 repos~959Automated safety check: PassNone

Similar skills

  • Paper to Chinese Patent Drafter

    Yuan1z0825/nature-skills

    Drafts Chinese invention patent applications and technical disclosures from research papers or inventor materials, tying each claim feature to source evidence.

    47k GitHub starsUsed in 1 repo~1.1k tokens
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Legal & ComplianceAuto-check passed
  • Paper To Cn Patent

    snipp-zha/Paper-to-patent-Skill

    Convert scientific papers, theses, technical reports, source code, figures, or research manuscripts into evidence-grounded Chinese invention patent drafts.

    107 GitHub starsUsed in 1 repo~959 tokens
    Legal & ComplianceAuto-check passed
  • Employment Contract Templates

    ynulihao/AgentSkillOS

    Create employment contracts, offer letters, and HR policy documents following legal best practices.

    618 GitHub starsUsed in 12 repos~4.1k tokens
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    891 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    891 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    891 GitHub stars~3.6k tokensUpdated 3 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    891 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    891 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed

Questions about Nist Csf Specialist

What does Nist Csf Specialist do?

NIST Cybersecurity Framework 2.0 implementation, assessment, and compliance management. Nist Csf Specialist is an agent skill from borghei/Claude-Skills.0 implementation, assessment, and compliance management.

When should I use Nist Csf Specialist?

Nist Csf Specialist fits situations like: CSF 2.0 gap analysis; cybersecurity risk management; maturity assessment; cross-framework compliance mapping.

How do I install Nist Csf Specialist in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill nist-csf-specialist -a claude-code`. Or copy the skill folder (ra-qm-team/nist-csf-specialist in borghei/Claude-Skills) into .claude/skills/nist-csf-specialist in your project. Claude Code loads it when a task matches its description.

How do I install Nist Csf Specialist in Codex?

Run `npx skills add borghei/Claude-Skills --skill nist-csf-specialist -a codex`. Or copy the skill folder (ra-qm-team/nist-csf-specialist in borghei/Claude-Skills) into .agents/skills/nist-csf-specialist in your project. Codex loads it when a task matches its description.

Can I use Nist Csf Specialist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill nist-csf-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nist-csf-specialist, .gemini/skills/nist-csf-specialist, .github/skills/nist-csf-specialist and .opencode/skills/nist-csf-specialist in your project.

What does Nist Csf Specialist need to run?

Going by SKILL.md and its folder, Nist Csf Specialist needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Nist Csf Specialist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nist Csf Specialist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Nist Csf Specialist use?

Nist Csf Specialist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nist Csf Specialist use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 22k tokens, read only when the agent opens those files.

What are the alternatives to Nist Csf Specialist?

Skills that share tags, products or a category with Nist Csf Specialist: Paper to Chinese Patent Drafter (Yuan1z0825/nature-skills, 47k stars), C15t (c15t/c15t, 1.9k stars), Contract Review (evolsb/claude-legal-skill, 464 stars) and Legal Clinic Client Intake (anthropics/claude-for-legal, 9.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nist Csf Specialist?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.