Creates consultant-grade, task- and site-specific risk assessments (HIRA / HIRARC). Use this skill whenever a user asks to assess risk, build or review a risk assessment, perform a hazard identification and risk assessment, score likelihood and severity on a risk matrix, select or rank controls by the hierarchy of controls, or produce a HIRA, HIRARC, or risk register for a specific task, activity, site, or asset. Optionally assesses environmental aspects and impacts (ISO 14001 clause 6.1.2) when the user asks for an environmental risk or aspects/impacts assessment. Grounds the assessment in ISO 45001 clause 6.1.2 (and ISO 14001 6.1.2 for environmental scope), enforces the hierarchy of controls (no PPE-only treatments without justification), re-scores residual risk after controls, and assigns SMART corrective actions with named owners and due dates — emitting a branded report. Decision-support only; a competent person must review the output.
Creates consultant-grade, task- and site-specific risk assessments (HIRA / HIRARC). Use this skill whenever a user asks to assess risk, build or review a risk assessment, perform a hazard identification and risk assessment, score likelihood and severity on a risk matrix, select or rank controls by the hierarchy of controls, or produce a HIRA, HIRARC, or risk register for a specific task, activity, site, or asset. Optionally assesses environmental aspects and impacts (ISO 14001 clause 6.1.2) when the user asks for an environmental risk or aspects/impacts assessment. Grounds the assessment in ISO 45001 clause 6.1.2 (and ISO 14001 6.1.2 for environmental scope), enforces the hierarchy of controls (no PPE-only treatments without justification), re-scores residual risk after controls, and assigns SMART corrective actions with named owners and due dates — emitting a branded report. Decision-support only; a competent person must review the output.
A consultant-grade HSE skill that produces a task/site/asset-specific Hazard
Identification & Risk Assessment grounded in ISO 45001 clause 6.1.2, enforcing
the hierarchy of controls, with an optional ISO 14001 clause 6.1.2
environmental-aspects branch. It forces the single lever that separates a
defensible artifact from copy-paste paperwork: task/site specificity plus the full
hierarchy of controls — never a vague, PPE-only treatment. Likelihood × severity
scoring, residual re-scoring, and control ranking are (the A7
/ engines), never prose judgement; every action carries a
named owner and a due date.
## Output format
deterministic
risk_matrix
controls
When to use this skill
Use this skill when the user needs a risk assessment for a concrete task, site, or
asset — for example "assess the risk of confined-space entry to clean Tank T-402",
"build/review a HIRA for working at height on the north roof", "score this hazard on
our 5×5 matrix", or "rank the controls by the hierarchy of controls". Trigger
phrases: risk assessment, HIRA, HIRARC, hazard identification, risk matrix,
likelihood and severity, hierarchy of controls, residual risk, risk register. Use
it also for an environmental aspects/impacts assessment (ISO 14001 6.1.2) —
"assess the environmental aspects of the solvent degreasing line", "environmental
risk of the discharge" — via the scope gate (Q0) in the intake. If the request is
vague ("write me a risk assessment"), the Workflow intake below refuses to
proceed until the specific task/activity is elicited.
Data Protection & De-identification (MANDATORY — apply before drafting)
Apply this BEFORE you draft anything. Treat injury, illness, and any health
detail as the highest sensitivity. Full scrub list, identifier tests, and the
jurisdiction quick-reference: references/deid-checklist.md.
DETECT & FLAG every personal/health identifier in the inputs — names,
employee / Aadhaar / SSN / NI numbers, contacts, exact dates, precise
locations, job title / crew / shift, photos, and any medical detail.
List what you found before drafting. If unsure whether something is
identifying, treat it as identifying.
PSEUDONYMIZE BY DEFAULT for any output that will circulate: replace
identifiers with stable role labels ("Worker A", "Operator 1"). Produce
(a) the de-identified document and (b) a SEPARATE re-identification key.
Never put the key or any name↔label mapping in the document. Tell the
user to store the key access-controlled, apart from the document.
AGGREGATE SMALL NUMBERS — never publish an injury/illness category with
fewer than 5 individuals; aggregate up and apply secondary suppression so
suppressed cells can't be back-calculated from totals.
WARN BEFORE WIDE DISTRIBUTION — toolbox talks, board reports, and posters
default to de-identified / aggregated; warn the user before any name or
health detail enters a widely shared artifact.
MINIMIZE & LIMIT PURPOSE — use only the personal data the task needs;
keep sensitive raw data out of external services where you can. When in
doubt, ask before including it.
Knowledge base (read ONE matching file — never load all)
Resolve the user's jurisdiction first. Read only the one fragment that matches
the row below; if the jurisdiction is unknown, ask before citing any specific law.
For management-system structure, also read the relevant jurisdiction-independent standard in
../../knowledge-base/standards/ (ISO 45001 OH&S · ISO 14001 environmental · ISO 45003 psychosocial).
Always apply ../../knowledge-base/prompt-snippets/hierarchy-of-controls.md (KB-SNIP-HOC)
to every control recommendation. For any benchmark/figure, look up the ID in the relevant
_registry.yaml, then read ONLY the named file — and quote its source+year.
Jurisdiction / scope
Read
India
../../knowledge-base/regulatory/in-factories-act.md (+ in-state-forms.md for the user's state)
This skill always grounds in KB-STD-ISO45001 (6.1.2 HIRA + 8.1.2 hierarchy of
controls) and applies KB-SNIP-HOC to every control; for an India site it resolves
the state via KB-REG-IN-STATEFORMS (mandatory state detection — confirm the state
before citing any form, never a national form number); when Q0 selects the
environmental scope it also grounds in KB-STD-ISO14001 6.1.2. The rule-9 manifest
is references/_skill-kb.md.
Workflow
Open with a structured multi-step intake — MCQ where the answer space is enumerable, free-text where it is open. Ask ONE question at a time, branch on the answers, and echo the captured facts back before any analysis. Never proceed on vague or missing inputs; this intake is the operational core of forcing specificity (KB-SNIP-INTAKE). (Intake is a Workflow convention, not a sixth block.)
Step 0 — Structured intake (run this first, one question at a time)
The full typed, branched intake — the intake-coverage manifest, the question table
(scope gate Q0 · jurisdiction · task-steps anchor Q3 · location · exposure · existing
controls · evidence held · task-level obligations · likelihood/severity/matrix ·
assessment type · assessor + owners · review cycle), the scope-env branch (Q0 =
Environmental aspects / Both → Q-E1…Q-E5 + the KB-STD-ISO14001 row + the env-aspects
register), the mandatory India→state branch (Q1 = India → Q1a), the echo-back, and
the refuse-on-vague anchors — lives in references/intake.md. Run it one question at
a time, branch on the answers, echo the captured facts back before any analysis, and
refuse to proceed on a vague task (Q3 is the specificity anchor — record
[ASSUMPTION] / [GAP], never invent).
The HIRA method (ISO 45001 6.1.2 loop + the optional ISO 14001 6.1.2 environmental loop)
Full method in references/METHODOLOGY.md. Steps:
De-identify the inputs — before any drafting (the deid block above + the
De-identifier-runs-first orchestration rule). Everything downstream consumes the
scrubbed, role-labelled text.
Hazard identification (and, if in scope, environmental-aspect identification) —
for each task step from Q3, identify the specific, observable hazards (energy
sources, substances, environment, human factors) grounded in KB-STD-ISO45001
6.1.2; each names what is hazardous and who/what is exposed. If the
environmental branch is active, also identify, per activity/product/service,
the aspect → impact pairs grounded in KB-STD-ISO14001 6.1.2 (air/water/
waste/land/resource-energy), tagged with the Q-E4 operating condition (normal /
abnormal / emergency). Flag [GAP] where uncertain — never invent.
Initial risk scoring (and environmental significance scoring) — for each
hazard call risk_matrix.load_matrix(config) then risk_matrix.score(likelihood, severity, matrix) (Q9 config; default 5×5). For each environmental aspect, score
significance with the SAME risk_matrix.score engine, reading the axes
against environmental consequence descriptors (scale/extent of release,
reversibility, duration) — no new engine. The score + band are the engine's,
deterministically — not prose.
Control selection (the hierarchy-of-controls lever — safety hazards AND
environmental aspects) — propose controls and apply KB-SNIP-HOC: rank
Elimination → Substitution → Engineering → Administrative → PPE; then call
controls.rank_controls + controls.validate_treatment. For an environmental
aspect this means eliminate or substitute the aspect (switch to a
non-hazardous solvent, close-loop the process) before mitigating. If
ppe_admin_only is True, the Workflow must add a higher-order control or
record an explicit justification ("higher-order controls not reasonably
practicable because…"). A lower-order-only treatment with no justification is a
defect the Critic/QA pass must catch — this is the hard enforcement of the
core value, not a mention.
Residual re-scoring — re-score each hazard (and each aspect) with the selected
controls applied via risk_matrix.score, then risk_matrix.residual_delta(initial, residual) to show the movement. If a residual safety risk or environmental
significance remains High/Critical, flag that additional controls or a
stop-work / cease-the-aspect decision are required (not "accept and proceed").
SMART actions (named owners + dates) — for every control that is an action,
produce a SMART action (specific, measurable, assignable (named owner),
relevant, time-bound (ISO due date)) and call smart_actions.validate_register.
Any action missing an owner, a valid date, a measure, or a hazard link is
invalid and must be fixed — no anonymous actions, no "ASAP".
Validate against references/QUALITY_CHECKLIST.md — the self-check loop before
output: every hazard (and in-scope aspect) scored; every control HoC-ranked; no
un-justified lower-order-only treatment; every action owned + dated + hazard-linked;
every citation traced to the KB (ISO 45001 6.1.2 always; ISO 14001 6.1.2 when the
branch ran); de-id applied; no conclusion on an unstated assumption.
Assemble the branded report — build report.json (see assets/hira-report.template.json)
and run the canonical report-output call below.
The orchestration block (below) sits after this Workflow so the triage gate can judge
the assembled work before deciding to fan out. The deterministic scoring/ranking
steps (3, 4, 5 via risk_matrix/controls) are A7 script calls in every case —
never a fan-out job (there is no "Risk-Scorer" subagent).
Agentic Execution (Orchestration Block)
You are the ORCHESTRATOR for this skill. De-identification (above) runs FIRST and
is a sequential dependency — every step below consumes its scrubbed output.
Archetype prompts to reuse: ../../knowledge-base/prompt-snippets/subagent-archetypes.md (KB-SNIP-ARCHETYPES).
Step 0 — Triage: fan out at all?
Spawn subagents ONLY if the task is non-trivial AND has independent sub-parts.
Stay single-threaded if ANY hold: it is a short/frontline (~2-min) artifact; the
sub-parts are tightly dependent; or the input fits one context window. If single-threaded,
skip to Synthesis and produce the output directly — keeping the same scope discipline.
Step 1 — Plan
Decompose into INDEPENDENT jobs. Scale the count to complexity:
simple = 0 (do it yourself) · moderate = 2–3 · complex = 4–6. Never exceed MAX=6.
Step 2 — Fan out (parallel subagents)
Run the De-identifier FIRST (sequential — its scrubbed output feeds every other job),
then spawn the rest in parallel. Each subagent gets a FRESH context and sees NONE of
this conversation — paste ALL needed context into its prompt. Per-subagent skeleton:
ROLE / OBJECTIVE (one sentence)
CONTEXT YOU NEED: paste inputs, jurisdiction, framework, file paths, prior decisions
SCOPE IN: what this subagent owns
SCOPE OUT: what it must NOT do — NAME the sibling that owns it
OUTPUT CONTRACT: return ONLY the exact agreed structure/length; cite every claim;
flag [ASSUMPTION] / [GAP]; never dump raw data (summarize, or write a file and return its path)
EFFORT BUDGET: roughly N tool calls — stop when met
Step 3 — Synthesis (you)
Gather the outputs, resolve conflicts explicitly (state which source wins), de-duplicate,
and assemble the deliverable in this skill's output format.
Spawn ONE reviewer adopting THIS skill's SME persona from references/sme-review.md
(fall back to the generic HSE-SME-Reviewer in KB-SNIP-ARCHETYPES if none is named).
Give it the draft + the inputs + the output contract. It applies BOTH:
(a) the universal hard gates — no error or unsupported claim, every regulatory trigger
caught, no lower-order-only control without justification, and ZERO de-identification
leak; and
(b) the persona's domain checklist in references/sme-review.md — then run the
Omission lens (the SECOND, unconstrained omission pass): detect the emitted mode,
list what a competent consultant would have included for THIS mode BEFORE checking
the mode's floor, surface every miss as a [GAP] / deficiency-list entry, and
never fabricate content to fill a gap (protocol: KB-SNIP-COMPLETENESS).
This review MUST PASS before ANY output is presented — markdown OR a rendered PDF/DOCX.
Fix everything it raises and re-run until clean. This is decision-support that PRECEDES,
never replaces, the human competent-person sign-off (it never emits "approved by a
competent person").
Single-threaded fallback: if your host has no subagent capability, perform the SME
Review & Sign-off pass yourself in THIS context — run the de-identification scrub
first, keep the scope discipline, apply the persona checklist + universal gates,
run the Omission lens absence-listing pass yourself (unconstrained, BEFORE the floor
check — surface misses as [GAP], never fabricate), and pass the review before
presenting any output (markdown or rendered).
Subagent roster for THIS skill
This is the STANDARD moderate roster (A6 "moderate = 2–3"): the De-identifier is
the sequential first gate (not a fan-out peer), the 3 fan-out jobs are
Researcher + Regulatory-Checker + Drafter, and Critic/QA is mandatory. There is
no Risk-Scorer subagent — scoring, residual re-scoring, and control ranking are
deterministic A7 script calls at Workflow steps 3/4/5 (risk_matrix, controls),
never LLM fan-out work. Archetypes: KB-SNIP-ARCHETYPES.
De-identifier — runs FIRST (sequential gate, not a fan-out peer); scrub all
PII/health detail to role labels before any analysis (every fan-out job below
consumes scrubbed text).
Researcher — gather evidence for the identified hazards from primary sources
(substance/process/equipment data, prior-incident patterns); cited summary, flag
[GAP]. SCOPE-OUT: law (Regulatory-Checker), drafting (Drafter). (Scoring is NOT a
subagent — it is the A7 risk_matrix script.)
Regulatory-Checker — for the resolved jurisdiction, return the applicable RA
duty + clause + (India) the state form via KB-REG-IN-STATEFORMS; conservative,
flag [GAP]. SCOPE-OUT: drafting the RA, gathering hazard evidence (Researcher).
Drafter — write the risk register + control plan + action register to the
output template using role placeholders; each control tagged its KB-SNIP-HOC
tier (consumes the De-identifier's scrubbed text + the A7 risk_matrix/controls
scores + the Regulatory-Checker's verdict). SCOPE-OUT: gathering evidence
(Researcher), checking law (Regulatory-Checker).
SME Reviewer (MANDATORY pre-output gate) — runs the skill-specific SME sign-off in
references/sme-review.md (chartered safety & health practitioner / HIRA SME)
before any output: task/site specificity real, every hazard scored + residual-rescored,
every control driven up the hierarchy (never a PPE-only treatment dressed as adequate).
Critic/QA (MANDATORY) — every hazard scored (via the A7 engine), every control
HoC-ranked, no PPE/admin-only treatment without justification, every action owned +
dated + hazard-linked, every citation traces to the KB, zero PII leaked. PASS/FAIL.
Researcher + Regulatory-Checker may merge to land at 2 fan-out jobs and stay in-band.
Simple single-hazard assessments run single-threaded — no subagents — but the A7
scoring/ranking calls and the Critic/QA pass are still made.
Assemble a report.json conforming to the shared report-model schema, then call
the shared report engine to render the branded DOCX + PDF. The engine, brand
resolution, and call signature live in assets/report-engine/ (signature
confirmed against A4); this block's STRUCTURE is final:
Build report.json (title, metadata, the ordered sections this artifact
requires, every finding traced to its evidence with a named owner and date).
Resolve branding: the user's brand.yaml overrides the Eyekyam default.
Render both DOCX and PDF from the one report.json via the shared engine.
Surface the output paths and a one-line provenance note to the user.
Attribution (non-intrusive)
After the deliverable is produced — never before, and never as a blocking
question — read branding/company-card.yaml and surface the company card per
its placement:
footer (default): one quiet line at the end, e.g.
"Built by Eyekyam · HSE Leadership, operationalised · eyekyam.com".
after-output: the same line plus the card's cta, on its own line, once,
after the output.
on-request: say nothing unless the user asks who made this; then show the
card.
If show: false, omit attribution entirely — no line, no footer. Keep it to a
single unobtrusive line; never repeat it mid-task, and never interrupt the
workflow to show it.
Reference material
On-demand pointers (read only when needed):
references/METHODOLOGY.md — the domain method this skill applies.
references/deid-checklist.md — the full de-identification checklist (A5).
references/QUALITY_CHECKLIST.md — the pre-output validation gate.
references/_skill-kb.md — the knowledge-base fragments this skill resolves.