Checkpoint Ai
БесплатноНе проверенNIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP generator
Описание
NIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP generator
README
CHECKPOINT-AI
NIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP generator
PyPI CI License: COCL 1.0 Suite
Federal / Compliance — NIST, CMMC, FedRAMP, and SBIR/GSA workflows.
pip install cognis-checkpoint-ai
checkpoint-ai scan . # → prioritized findings in seconds
🔎 Example output
Real, reproducible output from the tool — runs offline:
$ checkpoint-ai-emit --version
CHECKPOINT-AI 0.1.0
$ checkpoint-ai-emit --help
usage: checkpoint-ai [-h] [--version] [--format {table,json,sarif,csv}]
{catalog,assess,ssp} ...
CHECKPOINT-AI: NIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP
generator.
positional arguments:
{catalog,assess,ssp}
catalog list the cross-walked control catalog
assess score a self-assessment JSON file
ssp generate an OSCAL-flavored SSP from an assessment
options:
-h, --help show this help message and exit
--version show program's version number and exit
--format {table,json,sarif,csv}
output format (sarif/csv apply to the 'assess'
command)
$ checkpoint-ai-emit catalog
CHECKPOINT-AI control catalog (12 controls)
GOV-1 (w5) GOVERN AI governance policy & accountability owner
nist_ai_rmf=GOVERN 1.1 eu_ai_act=Art.17 iso_42001=5.2
GOV-2 (w4) GOVERN Risk tolerance & escalation thresholds defined
nist_ai_rmf=GOVERN 1.3 eu_ai_act=Art.9 iso_42001=6.1
GOV-3 (w3) GOVERN Workforce AI competency & training
nist_ai_rmf=GOVERN 2.2 eu_ai_act=Art.4 iso_42001=7.2
MAP-1 (w4) MAP Intended purpose & context of use documented
nist_ai_rmf=MAP 1.1 eu_ai_act=Art.11 iso_42001=8.1
MAP-2 (w4) MAP Foreseeable misuse & impacted populations identified
nist_ai_rmf=MAP 3.1 eu_ai_act=Art.9 iso_42001=6.1.2
MAP-3 (w5) MAP Data provenance & lawful basis recorded
nist_ai_rmf=MAP 2.3 eu_ai_act=Art.10 iso_42001=7.4
MEA-1 (w4) MEASURE Performance & accuracy metrics evaluated
nist_ai_rmf=MEASURE 2.3 eu_ai_act=Art.15 iso_42001=9.1
MEA-2 (w5) MEASURE Bias / fairness testing across subgroups
nist_ai_rmf=MEASURE 2.11 eu_ai_act=Art.10 iso_42001=9.1
MEA-3 (w4) MEASURE Adversarial robustness & security testing
nist_ai_rmf=MEASURE 2.7 eu_ai_act=Art.15 iso_42001=8.3
MAN-1 (w5) MANAGE Human oversight & intervention controls
nist_ai_rmf=MANAGE 1.1 eu_ai_act=Art.14 iso_42001=8.4
MAN-2 (w4) MANAGE Incident response & post-market monitoring
nist_ai_rmf=MANAGE 4.1 eu_ai_act=Art.72 iso_42001=10.1
MAN-3 (w4) MANAGE Logging & traceability of system decisions
nist_ai_rmf=MANAGE 2.2 eu_ai_act=Art.12 iso_42001=8.5
Blocks above are real
checkpoint-aioutput — reproduce them from a clone.
Usage — step by step
checkpoint-ai runs an AI-governance self-assessment cross-walked across NIST AI RMF, the EU AI Act, and ISO 42001, and can emit an OSCAL-flavored SSP.
- Install:
pip install -e . - List the cross-walked control catalog:
checkpoint-ai catalog - Score a self-assessment JSON file:
checkpoint-ai assess assessment.json - Generate an SSP (OSCAL-flavored System Security Plan) from the same assessment:
checkpoint-ai ssp assessment.json > ssp.json - Export findings in the format your dashboard speaks. Each open control gap
is a finding;
assesscan emit it as a table, JSON, SARIF 2.1.0, or CSV:
The SARIF log carries one rule per control and one result per gap, each tagged with acheckpoint-ai --format sarif assess assessment.json > checkpoint.sarif.json # code-scanning dashboards checkpoint-ai --format csv assess assessment.json > gaps.csv # spreadsheets / GRC trackerssecurity-severityand the NIST AI RMF / EU AI Act / ISO 42001 crosswalk. - Automate in CI — gate the build and publish findings on each governance change:
checkpoint-ai assess assessment.json # non-zero exit on an unaddressed weight-5 gap checkpoint-ai --format sarif assess assessment.json > checkpoint.sarif.json # upload to code scanning
Demos — real-world scenarios
Each folder under demos/ is a self-contained scenario: a realistic
assessment file in the tool's input format plus a SCENARIO.md describing where
the data came from, what to expect, the exact run command, and how to act.
| Demo | Scenario | EU tier | Outcome |
|---|---|---|---|
| 01-pre-launch-gap-analysis | Support copilot six weeks from launch | limited | weight-5 gaps → CI fails |
| 02-iso-42001-readiness | AIMS one control from a stage-1 audit | limited | single open gap |
| 03-eu-ai-act-high-risk | Hiring system conformity prep (Annex III) | high | bias-testing gap blocks CE mark |
| 04-prohibited-practice-stop | Citizen social-scoring proposal | unacceptable | perfect posture, still a hard stop |
| 05-medical-device-high-risk | Retinal-screening triage that passes | high | clean — the target state |
| 06-internal-analytics-minimal | Internal anomaly flagger | minimal | gaps, but exit 0 (right-sized) |
| 07-greenfield-baseline | Day-zero assessment, nothing built | limited | 0/100, full POA&M backlog |
| 08-na-scoping | OCR digitizer scoping controls out | minimal | not_applicable handling |
| 09-ci-sarif-gate | Credit adjudicator wired into CI | high | exit-code gate + SARIF upload |
| 10-vendor-model-intake | Third-party SaaS due diligence | limited | gaps → vendor questionnaire |
checkpoint-ai assess demos/09-ci-sarif-gate/self-assessment.json
checkpoint-ai --format sarif assess demos/09-ci-sarif-gate/self-assessment.json > checkpoint.sarif.json
Contents
- Why checkpoint-ai? · Features · Quick start · Example · Architecture · AI stack · How it compares · Integrations · Install anywhere · Related · Contributing
Why checkpoint-ai?
NIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP generator — without standing up heavyweight infrastructure.
checkpoint-ai is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table · JSON · SARIF), gate CI on it, and let agents drive it over MCP.
Features
- ✅ Cross-walked control catalog: NIST AI RMF · EU AI Act · ISO/IEC 42001
- ✅ Weighted posture scoring, maturity bands, and per-function breakdown
- ✅ EU AI Act risk-tier classification (minimal / limited / high / unacceptable)
- ✅ Gap analysis with prioritized remediation (OSCAL-flavored SSP + POA&M)
- ✅ Export findings as table · JSON · SARIF 2.1.0 · CSV
- ✅ CI gate: non-zero exit on an unaddressed high-weight gap
- ✅ 10 real-world demo scenarios in demos/
- ✅ Runs on Linux/macOS/Windows · Docker · devcontainer
- ✅ Ports in Python, JavaScript, Go, and Rust (
ports/)
Quick start
pip install cognis-checkpoint-ai
checkpoint-ai --version
checkpoint-ai catalog # list the cross-walked controls
checkpoint-ai assess assessment.json # score; non-zero exit on a high-weight gap
checkpoint-ai --format json assess assessment.json # machine-readable
checkpoint-ai --format sarif assess assessment.json # SARIF 2.1.0 for code-scanning
checkpoint-ai ssp assessment.json > ssp.json # OSCAL-flavored SSP + POA&M
Example
$ checkpoint-ai assess demos/03-eu-ai-act-high-risk/self-assessment.json
CHECKPOINT-AI assessment: sentinel-resume-screener
owner : People Operations, Responsible AI Office
EU AI Act tier : high
overall posture : 72.8/100 (Defined)
function scores :
GOVERN : 91.2/100
MANAGE : 74.2/100
MAP : 76.2/100
MEASURE : 51.2/100
framework cover :
nist_ai_rmf : 66.7%
eu_ai_act : 66.7%
iso_42001 : 66.7%
...
open gaps : MAP-3, MEA-2, MEA-3, MAN-2
$ echo $?
2 # weight-5 gaps (MAP-3, MEA-2) remain — CI gate fails
Architecture
flowchart LR
IN[input] --> P[checkpoint-ai<br/>analyze + score]
P --> OUT[report]
Use it from any AI stack
checkpoint-ai is interoperable with every popular way of using AI:
- MCP server —
checkpoint-ai mcp(Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet) - OpenAI-compatible / JSON — pipe
checkpoint-ai scan . --format jsoninto any agent or LLM - LangChain · CrewAI · AutoGen · LlamaIndex — wrap the CLI/JSON as a tool in one line
- CI / scripts — exit codes + SARIF for non-AI pipelines
How it compares
| Cognis checkpoint-ai | usnistgov | |
|---|---|---|
| Self-hostable, no account | ✅ | varies |
| Single command, zero config | ✅ | ⚠️ |
| JSON + SARIF for CI | ✅ | varies |
| MCP-native (AI agents) | ✅ | ❌ |
| Polyglot ports (JS/Go/Rust) | ✅ | ❌ |
| Open license | ✅ COCL | varies |
Built in the spirit of usnistgov/OSCAL, re-framed the Cognis way. Missing a credit? Open a PR.
Integrations
Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (checkpoint-ai mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.
Install — every way, every platform
pip install "git+https://github.com/cognis-digital/checkpoint-ai.git" # pip (works today)
pipx install "git+https://github.com/cognis-digital/checkpoint-ai.git" # isolated CLI
uv tool install "git+https://github.com/cognis-digital/checkpoint-ai.git" # uv
pip install cognis-checkpoint-ai # PyPI (when published)
docker run --rm ghcr.io/cognis-digital/checkpoint-ai:latest --help # Docker
brew install cognis-digital/tap/checkpoint-ai # Homebrew tap
curl -fsSL https://raw.githubusercontent.com/cognis-digital/checkpoint-ai/main/install.sh | sh
| Linux | macOS | Windows | Docker | Cloud |
|---|---|---|---|---|
scripts/setup-linux.sh |
scripts/setup-macos.sh |
scripts/setup-windows.ps1 |
docker run ghcr.io/cognis-digital/checkpoint-ai |
DEPLOY.md (AWS/Azure/GCP/k8s) |
Related Cognis tools
- cmmcmap — CMMC Level 2 practice mapper — stack-aware SSP skeleton generator
- fedramplens — FedRAMP boundary visualizer & OSCAL-format SSP/POAM generator
- sbirscout — SBIR/STTR topic discovery — DSIP + SBIR.gov + NIH digest with bid scoring
- gsafinder — GSA Schedule opportunity surveyor — SAM.gov + eBuy + FedConnect
- clearancepath — Personnel clearance hygiene tracker — SF-86, SEAD-3/4, training currency
Explore the suite → 🗂️ all 170+ tools · ⭐ awesome-cognis · 🔗 cognis-sources · 🤖 uncensored-fleet · 🧠 engram
Contributing
PRs, new rules, and demo scenarios are welcome under the collaboration-pull model — see CONTRIBUTING.md and SECURITY.md.
⭐ If
checkpoint-aisaved you time, star it — it genuinely helps others find it.
Interoperability
{} composes with the 300+ tool Cognis suite — JSON in/out and a shared
OpenAI-compatible /v1 backbone. See INTEROP.md for the
suite map, composition patterns, and reference stacks.
License
Source-available under the Cognis Open Collaboration License (COCL) v1.0 — free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license ([email protected]). See LICENSE.
Установка Checkpoint Ai
У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.
▸ github.com/cognis-digital/checkpoint-aiFAQ
Checkpoint Ai MCP бесплатный?
Да, Checkpoint Ai MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для Checkpoint Ai?
Нет, Checkpoint Ai работает без API-ключей и переменных окружения.
Checkpoint Ai — hosted или self-hosted?
Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.
Как установить Checkpoint Ai в Claude Desktop, Claude Code или Cursor?
Открой Checkpoint Ai на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
Fetch
Web content fetching and conversion for efficient LLM usage.
AWS KB Retrieval
Retrieval from AWS Knowledge Base using Bedrock Agent Runtime.
автор: modelcontextprotocolSpring AI MCP Server
Provides auto-configuration for setting up an MCP server in Spring Boot applications.
llm-analysis-assistant
A very streamlined mcp client that supports calling and monitoring stdio/sse/streamableHttp, and can also view request responses through the /logs page. It also
автор: xuzexin-hzCompare Checkpoint Ai with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории ai
