Install any skill in seconds. Free to start, no credit card required.
Get Started Free →NIST AI 100-1 (AI RMF 1.0) expert. Stub-depth framework plugin that routes to the SCF crosswalk. Level up by adding framework-specific context, assessment workflow, and evidence patterns.
.claude/skills/grcengclub-nist-ai-rmf-expert/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | 22% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -16% | 0% |
| case-07 | ✗→✓ | ▲ Improved | -52% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -54% | 0% |
| case-15 | ✗→✓ | ▲ Improved | -59% | 0% |
Stub-depth expertise for NIST AI 100-1 (AI RMF 1.0). This plugin is scaffolded from the SCF crosswalk (158 SCF controls map to 91 framework controls) and defers to /grc-engineer:gap-assessment for the actual compliance check.
general-nist-100-1-ai-rmfAI RMF is an outcomes framework, not a control catalog and not a certification. It organizes outcomes as Function → Category → Subcategory across four functions — GOVERN, MAP, MEASURE, MANAGE — applied across the AI system lifecycle. Subcategories describe desired risk-management outcomes; they do not prescribe specific controls. Concrete controls come from the SCF crosswalk: 158 SCF controls map to 91 AI RMF subcategories, referenced by subcategory ID (e.g. GOVERN 1.1, MAP 2.3), never by paraphrased prose.
Common failure modes when working with this framework: treating AI RMF as a control catalog to "implement", confusing the four functions with maturity levels, and mapping to subcategory prose instead of subcategory IDs.
TODO: replace with framework-specific overview. Minimum sections for Reference-depth upgrade:
All commands in this plugin route through /grc-engineer:gap-assessment with framework ID general-nist-100-1-ai-rmf. Reference-depth plugins add:
evidence-checklist — framework-native evidence by control familyscope — applicability determination for the organizationFull-depth plugins add framework-specific workflow commands (examples in sibling plugins like soc2, fedramp-rev5, pci-dss).
See the Framework Plugin Guide for the Stub → Reference → Full progression checklist.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-18 | pass→pass | 14,509 | 12,142 | -16% | 1 | 1 | 0% | 2,155 | 2,415 | +12% | 0 | 0 | — |
case-01 | fail→fail | 21,103 | 19,088 | -10% | 1 | 1 | 0% | 3,449 | 3,139 | -9% | 0 | 0 | — |
case-02 | fail→pass | 8,847 | 6,461 | -27% | 1 | 1 | 0% | 1,310 | 1,597 | +22% | 0 | 0 | — |
case-03 | fail→fail | 20,847 | 18,045 | -13% | 1 | 1 | 0% | 3,348 | 3,425 | +2% | 0 | 0 | — |
case-04 | pass→pass | 1,842 | 1,914 | +4% | 1 | 1 | 0% | 283 | 843 | +198% | 0 | 0 | — |
case-05 | fail→pass | 6,398 | 1,988 | -69% | 1 | 1 | 0% | 1,030 | 865 | -16% | 0 | 0 | — |
case-06 | pass→pass | 9,236 | 9,000 | -3% | 1 | 1 | 0% | 1,471 | 1,952 | +33% | 0 | 0 | — |
case-07 | fail→pass | 11,465 | 2,227 | -81% | 1 | 1 | 0% | 1,868 | 899 | -52% | 0 | 0 | — |
case-08 | fail→pass | 10,921 | 2,634 | -76% | 1 | 1 | 0% | 2,186 | 999 | -54% | 0 | 0 | — |
case-09 | pass→pass | 13,561 | 5,789 | -57% | 1 | 1 | 0% | 1,896 | 1,551 | -18% | 0 | 0 | — |
case-10 | pass→pass | 16,794 | 13,381 | -20% | 1 | 1 | 0% | 2,495 | 2,622 | +5% | 0 | 0 | — |
case-11 | pass→pass | 5,550 | 3,971 | -28% | 1 | 1 | 0% | 921 | 1,194 | +30% | 0 | 0 | — |
case-12 | pass→pass | 4,768 | 4,166 | -13% | 1 | 1 | 0% | 717 | 1,253 | +75% | 0 | 0 | — |
case-13 | pass→pass | 8,835 | 3,017 | -66% | 1 | 1 | 0% | 1,561 | 1,065 | -32% | 0 | 0 | — |
case-14 | pass→pass | 8,560 | 2,536 | -70% | 1 | 1 | 0% | 1,441 | 997 | -31% | 0 | 0 | — |
case-15 | fail→pass | 15,158 | 2,527 | -83% | 1 | 1 | 0% | 2,301 | 933 | -59% | 0 | 0 | — |
case-16 | fail→pass | 19,856 | 1,875 | -91% | 1 | 1 | 0% | 2,749 | 830 | -70% | 0 | 0 | — |
case-17 | fail→pass | 15,693 | 3,337 | -79% | 1 | 1 | 0% | 2,272 | 1,106 | -51% | 0 | 0 | — |
case-19 | fail→pass | 11,524 | 3,012 | -74% | 1 | 1 | 0% | 1,697 | 1,060 | -38% | 0 | 0 | — |
case-20 | fail→fail | 17,646 | 15,966 | -10% | 1 | 1 | 0% | 2,926 | 3,079 | +5% | 0 | 0 | — |
case-21 | fail→pass | 37,682 | 12,990 | -66% | 1 | 1 | 0% | 5,982 | 2,676 | -55% | 0 | 0 | — |
case-22 | fail→fail | 18,468 | 15,091 | -18% | 1 | 1 | 0% | 2,740 | 2,770 | +1% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +41 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.