← 返回 Skills 市场
221
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install toolweb-nist-csf-mapper
功能描述
Map your security controls and tools to NIST CSF 2.0, receive coverage scores, gap analysis, tier rating, regulatory crosswalk, and a prioritized improvement...
安全使用建议
This skill appears to be a thin wrapper around an external API (portal.toolweb.in) that will receive detailed information about your security posture. Before installing or using it: 1) Confirm the provider identity and homepage/source (metadata lists none). 2) Do not send production-sensitive or confidential data until you verify the vendor's security/privacy policies and TLS ownership. 3) Ask the publisher why no credential is declared in the metadata even though SKILL.md requires an API key; require that the skill declare a primary credential or prompt for it explicitly. 4) Test with synthetic or redacted data first. 5) If you must provide an API key, use least-privilege credentials and short-lived keys where possible and review audit logs for API use. 6) If you need an on‑premise or offline mapping for compliance reasons, prefer tools that run locally rather than outsourcing security posture data to an external service.
功能分析
Type: OpenClaw Skill
Name: toolweb-nist-csf-mapper
Version: 1.0.0
The skill is designed to collect and transmit highly sensitive organizational security architecture data—including specific security tools (e.g., CrowdStrike, Palo Alto, Splunk) and internal control gaps—to an external third-party API (portal.toolweb.in). While this behavior is aligned with the stated purpose of NIST CSF mapping, the aggregation of such detailed reconnaissance-grade information by an external service poses a significant security risk. There is no evidence of intentional malice or unauthorized local file access, but the inherent risk of data exposure justifies a suspicious classification.
能力评估
Purpose & Capability
The skill claims to call an external service (portal.toolweb.in) to generate NIST CSF mappings and expects an API key in its API reference, yet the skill metadata lists no required environment variables or primary credential. That omission is inconsistent: a remote API integration normally requires the caller to provide an API key or token.
Instruction Scope
SKILL.md is instruction-only and stays within the stated purpose: it asks for company profile, tools, boolean posture fields, and describes POSTing that data to /nist-mapping. It does not instruct reading local files, arbitrary env vars, or other system state. The instructions do send potentially sensitive organizational security data to an external endpoint.
Install Mechanism
There is no install spec and no code files; this is instruction-only, which minimizes on-disk installation risk.
Credentials
The API reference requires an API key via X-API-Key or mcp_api_key, but the skill metadata declares no required env vars/primary credential. That discrepancy means the skill's declared permissions understate the secret/API access it needs. Also, the skill will transmit detailed security posture data to an external endpoint — sensitive information that warrants explicit justification and documented handling.
Persistence & Privilege
The skill does not request always: true, does not modify other skills, and declares no config paths. It does allow autonomous invocation (default), but that is the platform norm and not by itself a problem.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install toolweb-nist-csf-mapper - 安装完成后,直接呼叫该 Skill 的名称或使用
/toolweb-nist-csf-mapper触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
- Initial release of NIST CSF Mapper skill.
- Enables mapping of your organization's security controls and tools to NIST Cybersecurity Framework (CSF) 2.0.
- Provides function-by-function CSF coverage, gap analysis, maturity tier rating, and prioritized improvement roadmap.
- Outputs tool-to-CSF mapping, regulatory crosswalk, and an executive summary.
- Includes clear API usage instructions, required parameters, and example output.
元数据
常见问题
NIST CSF Mapper 是什么?
Map your security controls and tools to NIST CSF 2.0, receive coverage scores, gap analysis, tier rating, regulatory crosswalk, and a prioritized improvement... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 221 次。
如何安装 NIST CSF Mapper?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install toolweb-nist-csf-mapper」即可一键安装,无需额外配置。
NIST CSF Mapper 是免费的吗?
是的,NIST CSF Mapper 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
NIST CSF Mapper 支持哪些平台?
NIST CSF Mapper 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 NIST CSF Mapper?
由 ToolWeb(@krishnakumarmahadevan-cmd)开发并维护,当前版本 v1.0.0。
推荐 Skills