一键导入
risk-management
Use when identifying project risks, creating risk registers, building mitigation plans, or assessing impact and likelihood of threats to delivery
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Use when identifying project risks, creating risk registers, building mitigation plans, or assessing impact and likelihood of threats to delivery
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Analyzes weight file diffs after benchmarks to flag significant regressions in ref_time, proof_size, and DB reads. Use when updating weights, running benchmarks, or reviewing weight changes.
Use when you have a written implementation plan to execute in a separate session with review checkpoints
Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup
Use when completing tasks, implementing major features, or before merging to verify work meets requirements
Use when executing implementation plans with independent tasks in the current session
Use when starting feature work that needs isolation from current workspace or before executing implementation plans - ensures an isolated workspace exists via native tools or git worktree fallback
| name | risk-management |
| description | Use when identifying project risks, creating risk registers, building mitigation plans, or assessing impact and likelihood of threats to delivery |
Structured risk assessment that produces a risk register with dual scoring (inherent and residual) and actionable mitigation plans. Uses a 5x5 likelihood-impact matrix aligned with ISO 31000:2018 principles.
The risk register template contains the full document structure with all scales, tables, diagrams, and guidance on what to adapt per project. This skill describes when and how to use it.
Announce at start: "I'm using the risk-management skill to create a risk register and mitigation plan."
Before identifying risks, establish:
Use the plan location discovery process to find the right directory. Default filename: risk-register-and-mitigation-plan.md.
Announce the chosen path and wait for user confirmation before writing.
Start from the risk register template. Adapt it to the project:
For each risk:
R-SEC-001)The gap between inherent and residual makes mitigation effectiveness visible and auditable.
For every risk with an inherent score of 12 or above (High/Critical), write a detailed mitigation plan using the template format in section 7. Organize controls by type:
Medium and lower risks are tracked in the register with mitigation strategies noted inline.
Present the completed register for review. Check that: