CtrlK
BlogDocsLog inGet started
Tessl Logo

csf-mapping

Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). Produce a gap analysis, current/target tier assessment, and roadmap in the governance language that boards, auditors, and CISOs actually use. Use when the user mentions 'NIST CSF,' 'CSF 2.0,' 'cybersecurity framework,' 'security posture,' 'governance mapping,' 'CSF gap analysis,' 'CSF tiers,' 'cybersecurity maturity,' 'security roadmap,' 'CISO report,' 'board reporting,' 'security program,' or needs to translate technical findings into governance language.

69

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable instruction skill with a clear five-step workflow and concrete templates, tables, and prioritization criteria. The main gaps are mild verbosity in places, no worked example, and the absence of an explicit validation feedback loop.

Suggestions

Trim the 'High-impact gaps most orgs have' list and reference annotations to the highest-signal items to improve token efficiency.

Add a short worked example (one Subcategory assessed end-to-end) to lift actionability from concrete guidance to copy-paste-ready.

Add an explicit validate→fix→retry checkpoint after Step 3, e.g., 'Re-check each Tier rating against documented evidence before moving to gap analysis.'

DimensionReasoningScore

Conciseness

The body is mostly efficient and assumes Claude's competence, but sections like 'High-impact gaps most orgs have' and the references list carry some explanatory padding that could be trimmed without losing utility.

4 / 5

Actionability

Concrete, specific guidance throughout — a per-Subcategory recording table, tier definitions, a Risk × Cost-to-close prioritization scheme, a phased roadmap structure, and a full output-format template — though no worked filled-in example is provided.

4 / 5

Workflow Clarity

A clearly sequenced five-step methodology (scope → profile → assess → gaps → roadmap) with implicit evidence-based checkpoints ('evidence, not aspiration', 'refuse to inflate tier ratings without evidence'), but no explicit validate→fix→retry feedback loop.

4 / 5

Progressive Disclosure

Well-organized into clearly headed sections in a single self-contained file with no bundle files to offload; minor organization gaps where the large Subcategory cross-reference and high-impact-gaps tables could arguably live in a reference file.

4 / 5

Total

16

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that pairs concrete capabilities with an extensive, natural trigger-term list and an explicit 'Use when' clause. The only weakness is second-person voice ('your security posture'), which costs one specificity point under the rubric.

Suggestions

Rewrite in third person to avoid the specificity penalty, e.g., 'Maps an organization's security posture against the NIST Cybersecurity Framework 2.0 ...' instead of 'Map your security posture ...'.

DimensionReasoningScore

Specificity

Names the domain and several concrete actions — 'Produce a gap analysis, current/target tier assessment, and roadmap' — for comprehensive coverage; docked one point because the phrasing 'Map your security posture' is second-person, which the rubric penalizes on specificity.

4 / 5

Completeness

Explicitly answers both what the skill does (map posture, gap analysis, tier assessment, roadmap) and when to use it via a concrete 'Use when the user mentions ...' clause with many trigger phrases.

5 / 5

Trigger Term Quality

A comprehensive, natural list including synonyms and variants — 'NIST CSF,' 'CSF 2.0,' 'cybersecurity framework,' 'security posture,' 'governance mapping,' 'CSF gap analysis,' 'CSF tiers,' 'cybersecurity maturity,' 'security roadmap,' 'CISO report,' 'board reporting,' 'security program.'

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (NIST CSF 2.0 posture/governance assessment) with distinctive triggers that would not fire for the repo's audit skills, minimizing conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.