Claims
The skill is a governance and compliance utility designed to guide a defense contractor through the CMMC Level 2 certification process. It claims to scope Controlled Unclassified Information (CUI), implement 110 NIST SP 800-171 requirements, compute the SPRS score, manage Plans of Action and Milestones (POA&M), and prepare for C3PAO assessments.
Actual behavior
The skill operates as a static knowledge base and procedural guide. It defines the rules for scoping assets, classifying requirements, and calculating scores based on the DoD Assessment Methodology. It does not execute external code, modify system configurations, or interact with live APIs to fetch real-time data. It relies on the agent to apply its logic to the current context (e.g., existing asset inventories or contract details).
No non-informational findings.