Iso42001
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Apply the NIST AI Risk Management Framework (NIST AI 100-1 + the NIST AI 600-1 Generative AI Profile) to a specific AI system, governance question, or impact assessment.
$ npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install lawve-ai/awesome-legal-skills nist-ai-rmf --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/nist-ai-rmf-rafal-fryc .claude/skills/nist-ai-rmf && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nist-ai-rmf" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/nist-ai-rmf-rafal-fryc into .claude/skills/nist-ai-rmf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nist-ai-rmf", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/nist-ai-rmf-rafal-frycType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install lawve-ai/awesome-legal-skills nist-ai-rmf --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/nist-ai-rmf-rafal-fryc .agents/skills/nist-ai-rmf && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nist-ai-rmf" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/nist-ai-rmf-rafal-fryc into .agents/skills/nist-ai-rmf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nist-ai-rmf", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install lawve-ai/awesome-legal-skills nist-ai-rmf --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/nist-ai-rmf-rafal-fryc .cursor/skills/nist-ai-rmf && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nist-ai-rmf" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/nist-ai-rmf-rafal-fryc into .cursor/skills/nist-ai-rmf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nist-ai-rmf", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/lawve-ai/awesome-legal-skills.git --path skills/nist-ai-rmf-rafal-fryc--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install lawve-ai/awesome-legal-skills nist-ai-rmf --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/nist-ai-rmf-rafal-fryc .gemini/skills/nist-ai-rmf && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nist-ai-rmf" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/nist-ai-rmf-rafal-fryc into .gemini/skills/nist-ai-rmf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nist-ai-rmf", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install lawve-ai/awesome-legal-skills nist-ai-rmfInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/nist-ai-rmf-rafal-fryc .github/skills/nist-ai-rmf && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nist-ai-rmf" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/nist-ai-rmf-rafal-fryc into .github/skills/nist-ai-rmf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nist-ai-rmf", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install lawve-ai/awesome-legal-skills nist-ai-rmf --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/nist-ai-rmf-rafal-fryc .opencode/skills/nist-ai-rmf && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nist-ai-rmf" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/nist-ai-rmf-rafal-fryc into .opencode/skills/nist-ai-rmf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nist-ai-rmf", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nist-ai-rmfApply the NIST AI Risk Management Framework (NIST AI 100-1 + the NIST AI 600-1 Generative AI Profile) to a specific AI system, governance question, or impact assessment.
Nist AI Rmf is an agent skill from lawve-ai/awesome-legal-skills. Apply the NIST AI Risk Management Framework (NIST AI 100-1 + the NIST AI 600-1 Generative AI Profile) to a specific AI system, governance question, or impact assessment. Three modes — consult, governance plan, full assessment — all cite Subcategories (GOVERN 1.1) and Profile Action IDs (GV-1.2-001) verbatim. Use when the user mentions the AI RMF, NIST RMF, NIST AI 100-1, NIST AI 600-1, GenAI Profile, the four functions (Govern / Map / Measure / Manage), the trustworthy AI characteristics, the 12 GAI risks…
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 24 other files, including reference files (for example `README.md`, `references/README.md` and `references/core/functions.md`).
It sits in Legal & Compliance, covering AI governance. The repository describes itself as: A curated list of awesome Agent Skills for automating legal work. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 045f738. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nist AI Rmf loads about 3k tokens when it runs, and up to ~55k if it reads all its reference files. Until then it costs about 165 tokens; SKILL.md has 1,446 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from lawve-ai/awesome-legal-skills at commit 045f738, republished under its MIT licence (© lawve-ai). 1,446 words, ~2,952 tokens.
.claude/skills/nist-ai-rmf/SKILL.md (or your agent's skills folder). This skill also uses 21 other files; get the full folder from GitHub.Applies the NIST AI RMF — by name, by Subcategory, by Action ID — to whatever AI use case, governance question, or assessment the user brings. Three modes; pick one based on the user's question, default to consult if unsure.
All three modes share the same source-of-truth: verbatim NIST text in references/. Quote the files; don't invent or paraphrase.
Two NIST publications underlie the skill. The verbatim extracted markdown ships in references/; the raw source HTMLs and maintainer-only re-extraction tooling live outside this distribution.
references/core/.GV-X.Y-NNN etc., each mapped to a Core Subcategory. Extracted into references/gai-profile/.The Core applies to any AI system. The Profile is an overlay on top of the Core for generative systems. So:
Other NIST AI Profiles exist; they aren't loaded here. If the user asks about one, say so plainly.
This skill ships as a standalone skill. The provenance of every claim must be unambiguous to a reader who never saw the conversation.
The skill will:
references/. The wording in the output must match the file.[model judgment — verify against system specifics] (or the more specific variants in the templates).GV-/MP-/MS-/MG- action IDs.The skill will decline to:
references/, it does not exist in NIST's framework. Say so plainly rather than fabricating one.In order, every invocation:
references/README.md first. It's the routing index — it tells you which reference files to load for which question. Don't load files greedily.references/README.md.references/templates/<mode>.md when drafting output.When to use: the user is asking "what should we do?" or "what does NIST say about?" with a specific system or scenario in mind. Fast turnaround. Not a deliverable artifact.
Procedure:
gai-profile/risks.md + crosswalk.md. Be honest — if a risk obviously doesn't apply (e.g., CBRN for a customer-service chatbot), say so and exclude it. Don't pad.Output template: references/templates/consult.md — load when drafting.
When to use: the user is building or auditing an AI governance program, not assessing one specific system. They want structure, not a system-specific deep dive.
Procedure:
Output template: references/templates/governance-plan.md — load when drafting.
When to use: the user wants a documented artifact assessing one specific system end-to-end. Heavier than a consult. The output should be self-contained — a reader who never saw the conversation should understand it.
Procedure:
Output template: references/templates/assessment.md — load when drafting.
Work-product header. Default to CONFIDENTIAL — Internal Use at the top of every output. If the user is operating in a legal context and asks for an attorney-work-product header, switch to ATTORNEY WORK PRODUCT. PRIVILEGED AND CONFIDENTIAL. for that output.
Markdown to stdout. Don't write files. The output is markdown for the user to copy, edit, route, or save themselves.
Citations. Always include the Subcategory or Action ID as a clear citation (e.g., **GOVERN 1.1** or `GV-1.2-001`). The verbatim NIST statement goes right after. Never bury the citation in a footnote.
It is: a way to apply the NIST AI RMF rigorously, with verbatim citations, to specific questions and systems. It saves a lawyer or governance professional from re-reading the full PDF every time.
It isn't:
references/, it doesn't exist (in NIST's framework). Don't invent.© lawve-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 21 other files (references) in skills/nist-ai-rmf-rafal-fryc of lawve-ai/awesome-legal-skills.
Open the folder on GitHubat commit 045f738
Nist AI Rmf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nist AI Rmf this skilllawve-ai/awesome-legal-skills | 847 | — | ~3k | Automated safety check: Pass | MIT | |
| Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| AI Risk Managementbriiirussell/cybersecurity-skills | 413 | — | ~3.7k | Automated safety check: Notes | MIT | |
| EU AI Act System Inventoryanthropics/claude-for-legal | 9.6k | 3 repos | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Eu AI Act Readinessseb1n/awesome-ai-agent-skills | 206 | — | ~3.3k | Automated safety check: Pass | MIT | |
| AI GovernanceHack23/cia | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
briiirussell/cybersecurity-skills
Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…
anthropics/claude-for-legal
Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
petrkindlmann/qa-skills
Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…
lawve-ai/awesome-legal-skills
U.S. An agent skill from lawve-ai/awesome-legal-skills.
lawve-ai/awesome-legal-skills
Practitioner skill for advising on EU Regulation 2023/2854 (Data Act).
lawve-ai/awesome-legal-skills
Calendar litigation and arbitration deadlines from a scheduling order.
lawve-ai/awesome-legal-skills
Read, search, and download emails and attachments from Microsoft Outlook via OAuth2.
lawve-ai/awesome-legal-skills
Turn an interpretive-ambiguity audit of a legal text — contract, statute, regulation, or judicial opinion — into a polished deliverable.
lawve-ai/awesome-legal-skills
Audits a website for compliance with Azerbaijan's Law on Personal Data No.
Categories
Apply the NIST AI Risk Management Framework (NIST AI 100-1 + the NIST AI 600-1 Generative AI Profile) to a specific AI system, governance question, or impact assessment. Nist AI Rmf is an agent skill from lawve-ai/awesome-legal-skills. Apply the NIST AI Risk Management Framework (NIST AI 100-1 + the NIST AI 600-1 Generative AI Profile) to a specific AI system, governance question, or impact assessment.
Nist AI Rmf fits situations like: the user mentions the AI RMF; the four functions (Govern / Map / Measure / Manage); the trustworthy AI characteristics; the 12 GAI risks (confabulation.
Run `npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf -a claude-code`. Or copy the skill folder (skills/nist-ai-rmf-rafal-fryc in lawve-ai/awesome-legal-skills) into .claude/skills/nist-ai-rmf in your project. Claude Code loads it when a task matches its description.
Run `npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf -a codex`. Or copy the skill folder (skills/nist-ai-rmf-rafal-fryc in lawve-ai/awesome-legal-skills) into .agents/skills/nist-ai-rmf in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nist-ai-rmf, .gemini/skills/nist-ai-rmf, .github/skills/nist-ai-rmf and .opencode/skills/nist-ai-rmf in your project.
SKILL.md names no scripts, command-line tools or credentials: Nist AI Rmf is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nist AI Rmf is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 52k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Nist AI Rmf: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), AI Risk Management (briiirussell/cybersecurity-skills, 413 stars), EU AI Act System Inventory (anthropics/claude-for-legal, 9.6k stars) and Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
lawve-ai (a GitHub organization) maintains it in lawve-ai/awesome-legal-skills, which has 847 GitHub stars. The repository holds 154 skills in this directory. The repository was last updated on October 2, 2026.
Source: lawve-ai/awesome-legal-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.