CtrlK
BlogDocsLog inGet started
Tessl Logo

ai-risk-management

Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency, accountability, third-party model risk, monitoring for drift, and AI incident response. Broader than prompt-injection (which is the security slice). Use when the user mentions 'AI risk,' 'AI governance,' 'NIST AI RMF,' 'AI compliance,' 'ML governance,' 'model risk management,' 'AI fairness,' 'AI bias,' 'algorithmic accountability,' 'AI Bill of Rights,' 'EU AI Act,' 'AI transparency,' 'model card,' 'AI red team,' 'AI safety,' 'responsible AI,' 'model drift,' 'concept drift,' 'AI monitoring,' 'AI incident,' or needs to assess or govern an AI / ML system.

71

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a strong, well-structured governance skill with concrete metrics, tooling, laws, and a usable output template. It earns 4s across the board: efficient but with minor padding, actionable but not fully copy-paste, sequenced with implicit checkpoints, and well-organized but monolithic without bundle files.

Suggestions

Trim editorial asides (e.g., 'Most organizations underestimate how much AI they actually deploy', 'overengineering kills the process') to tighten conciseness.

Add explicit validation checkpoints between workflow steps — e.g., confirm inventory completeness before MAP, or require metric thresholds to be agreed before MANAGE — to reach the top workflow-clarity anchor.

Consider moving the detailed regulatory layer and/or the full output-format template into separate reference files so SKILL.md stays a lean overview pointing one level deep.

DimensionReasoningScore

Conciseness

Largely efficient and information-dense (named metrics, tools, laws, an output template), but contains occasional editorial asides like 'Most organizations underestimate how much AI they actually deploy' and 'overengineering kills the process' that could be trimmed.

4 / 5

Actionability

Provides concrete, executable guidance throughout — specific metrics (demographic parity, equalized odds), tools (Fairlearn, AI Fairness 360, SHAP/LIME), benchmarks (HELM, MMLU), named laws, and a full output-format template — with only minor gaps in copy-paste specificity.

4 / 5

Workflow Clarity

A clearly sequenced 5-step workflow (Inventory → MAP → MEASURE → MANAGE → GOVERN) with checklists in the output template, but validation checkpoints between steps are more implicit than the explicit validate-then-proceed feedback loops of the top anchor.

4 / 5

Progressive Disclosure

Well-organized into clear sections with a real References list, but the skill is monolithic — all content is inline in SKILL.md with no bundle files, and the detailed regulatory layer plus full output template could plausibly live in separate reference files.

4 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: it states concrete capabilities, provides a comprehensive set of natural trigger terms, answers both 'what' and 'when' explicitly, and clearly distinguishes itself from the adjacent prompt-injection skill. It fully matches the top anchor on every dimension.

DimensionReasoningScore

Specificity

Lists multiple specific concrete capabilities — 'model lifecycle governance, fairness and bias evaluation, robustness, transparency, accountability, third-party model risk, monitoring for drift, and AI incident response' — giving comprehensive coverage of the domain.

5 / 5

Completeness

Explicitly answers both what ('Apply the NIST AI Risk Management Framework ... and adjacent guidance') and when ('Use when the user mentions ... or needs to assess or govern an AI / ML system') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Provides extensive natural trigger terms users would actually say — 'AI risk,' 'AI governance,' 'NIST AI RMF,' 'AI fairness,' 'AI bias,' 'model drift,' 'concept drift,' 'AI incident,' and many more, covering synonyms and regulatory names.

5 / 5

Distinctiveness Conflict Risk

Carves out a clear niche distinct from adjacent skills via 'Broader than prompt-injection (which is the security slice),' with trigger terms unlikely to fire for the wrong skill.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.