AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Ai Risk Governance

skill-daemon-blockint-tech-agentic-enteprises-skill-ai-risk-governance · by daemon-blockint-tech

|

No reviews yet
0 installs
46 views
0.0% view→install

Install

$ agentstack add skill-daemon-blockint-tech-agentic-enteprises-skill-ai-risk-governance

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-daemon-blockint-tech-agentic-enteprises-skill-ai-risk-governance)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Ai Risk Governance? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

AI Risk & Governance

When to Use

  • Classifying AI use cases by risk tier and impact
  • Drafting AI acceptable-use policies and governance frameworks
  • Building AI risk registers with likelihood/severity/mitigation tracking
  • Preparing model cards, system cards, or DPIAs for AI deployments
  • Reviewing third-party LLM vendors (data terms, fine-tuning, safety commitments)
  • Mapping AI products to frameworks (NIST AI RMF, ISO 42001, EU AI Act concepts)
  • Aligning product and engineering teams with compliance requirements
  • Designing human-in-the-loop oversight for consequential AI decisions

When NOT to Use

  • Implementing RAG pipelines, agents, or production features → ai-engineer
  • Running jailbreak tests or adversarial campaigns → ai-redteam
  • SOC 2/ISO evidence automation and technical control mapping → compliance-engineer
  • General SOC 2 IT controls without AI scope → cybersecurity
  • Commercial/enterprise AI solution architecture → applied-ai-architect-commercial-enterprise
  • Skills portfolio governance and publish gates → ai-skill-manager

Related skills

| Need | Skill | |---|---| | Building LLM products | ai-engineer | | Adversarial testing | ai-redteam | | Research and benchmarks | ai-researcher | | Enterprise security program | cybersecurity | | Pipeline and data security | devsecops | | SOC 2/ISO evidence and technical controls | compliance-engineer | | AI solution architecture (commercial/enterprise) | applied-ai-architect-commercial-enterprise | | Agent skills governance | ai-skill-manager | | Safeguard gateways, classifiers, rollout | ml-infrastructure-engineer-safeguards | | Safety classifier research and benchmarks | ml-research-engineer-safeguards | | Privacy research for safeguards | privacy-research-engineer-safeguards | | Enterprise security risk registers (non-AI scope) | security-risk-analyst | | M&A/investment cyber diligence and board packs | cyber-diligence-governance |

Core Workflows

1. Use-case intake and classification

Capture:

| Field | Purpose | |---|---| | Purpose and users | Scope and accountability | | Data types | PII, special categories, IP | | Automation level | Human-in-loop vs autonomous | | Impact if wrong | Safety, legal, financial, reputational | | External exposure | Customer-facing vs internal |

Risk tier (example):

| Tier | Criteria | Controls | |---|---|---| | Low | Internal, low impact, no sensitive data | Standard policy + logging | | Medium | Customer-facing or internal PII | Review + eval + monitoring | | High | Regulated domain, high impact, autonomous actions | Governance board + red-team + enhanced oversight |

See references/risk_classification.md for EU AI Act–oriented mapping (non-legal).

2. Risk assessment

Use structured worksheet:

  1. Identify hazards (bias, hallucination, leakage, misuse, dependency)
  2. Estimate likelihood and severity
  3. Define mitigations (technical, process, legal)
  4. Assign owner and review date
  5. Residual risk acceptance sign-off

See references/risk_assessment.md for worksheets and NIST AI RMF functions.

3. Documentation artifacts

| Artifact | When | |---|---| | Model card / system card | Every production model or vendor model | | Data sheet | Training/fine-tune data described | | Eval summary | Pre-deploy and periodic | | Incident log | AI-specific harms and near-misses |

See references/documentation.md for model card sections and change log.

4. Policy and oversight

  • Acceptable use policy (prohibited uses, approval paths)
  • Human oversight rules for consequential decisions
  • Escalation for policy violations and serious incidents
  • Training for builders and reviewers

See references/policy_oversight.md for governance committee cadence.

5. Vendor and third-party models

Review: data processing terms, subprocessors, retention, fine-tuning on customer data, safety commitments, breach notification, exit plan.

See references/vendor_review.md for vendor questionnaire topics.

When to load references

  • Tiering and regulation mappingreferences/risk_classification.md
  • Assessments and frameworksreferences/risk_assessment.md
  • Model cardsreferences/documentation.md
  • Policies and committeesreferences/policy_oversight.md
  • Vendorsreferences/vendor_review.md

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.