AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Risk Mitigation

skill-natan-mohart-24-strategy-skills-for-claude-risk-mitigation · by Natan-Mohart

Scores strategic and execution risks on likelihood, impact, AND velocity (how fast a risk could hit) via a bundled calculator — catching fast-moving risks a standard 2-factor heat map underranks — then forces a named owner and mitigation for every high-priority item. Use whenever the user wants a risk register, risk assessment, or mitigation plan for a strategy or initiative, or has a risk list w…

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-natan-mohart-24-strategy-skills-for-claude-risk-mitigation

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-natan-mohart-24-strategy-skills-for-claude-risk-mitigation)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Risk Mitigation? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Risk Mitigation

When to use

Use whenever a strategy, initiative, or business case needs a real risk assessment — especially replacing a risk list that's just a bulleted set of concerns with no scoring, no owners, and no distinction between a risk that's a slow background hum and one that could hit within weeks.

What it does

Scores every risk on likelihood, impact, AND velocity via a bundled calculator, producing a priority tier that a plain likelihood×impact heat map would get wrong for fast-moving risks — a moderate-score, high-velocity risk (like an active regulatory change) needs urgent attention even though its raw score looks unremarkable next to a high-score, low-velocity one. It also flags any critical risk with no documented mitigation, so nothing dangerous slips through unowned.

Method

  1. Inventory risks across categories: strategic (market/competitive), operational (execution/delivery), financial (funding/covenant), regulatory/compliance, and reputational — don't limit the list to whatever category the requester happens to be worried about today.
  2. Score each risk 1-5 on likelihood (probability it occurs in the relevant time horizon) and 1-5 on impact (severity if it does) — with a one-line justification for each score, not just a number.
  3. Score each risk 1-5 on velocity: how fast could it go from "not happening" to "fully materialized" — 1 for a risk that would take years to develop (giving time to react), 5 for one that could hit within weeks (leaving little reaction time even with good monitoring).
  4. Run the bundled calculator (scripts/risk_matrix.py) to get the likelihood×impact score, a priority tier, and two flags: any critical risk missing a documented mitigation, and any moderate-score risk with high velocity that a plain heat map would underrank.
  5. Assign a named owner and a specific mitigation action to every risk tiered HIGH or CRITICAL — "monitor closely" is not a mitigation; a mitigation names what specifically reduces likelihood or impact, and by when.
  6. For velocity-flagged risks, design a monitoring trigger, not just a mitigation plan — the point of high velocity is that mitigation alone may not be enough; you also need an early-warning signal because there's little time to react once it starts.
  7. Review the register on a cadence matched to its content: critical/high items reviewed monthly at minimum, moderate quarterly, low annually — a risk register that's built once and never revisited is closer to theater than to actual risk management.

Inputs

  • List of candidate risks across strategic/operational/financial/regulatory/reputational categories
  • Likelihood, impact, and velocity scores (1-5) with justification for each
  • Any existing mitigation already in place per risk
  • Config saved as JSON matching the format documented at the top of scripts/risk_matrix.py

Output format

Scored and tiered risk register (likelihood × impact × velocity); flagged critical risks with no mitigation; flagged high-velocity risks a static heat map would underrank; named owner and mitigation action per HIGH/CRITICAL risk; monitoring trigger per high-velocity risk; review cadence.

Example

A regulatory change risk scores only 10 on likelihood×impact (moderate) but carries a velocity of 5/5 — it could hit within weeks once triggered. A plain heat map would file it below several higher-scoring but slow-moving risks; the velocity flag surfaces it for urgent monitoring anyway, with a named early-warning signal (a specific legislative tracking service) rather than a quarterly check-in that would be too slow to matter.

Common pitfalls

  • Building a risk register once and never revisiting it, so it stops reflecting reality within a quarter.
  • Scoring only likelihood and impact, missing that a fast-moving moderate risk can be more dangerous than a slow-moving severe one because there's no time to react.
  • Listing risks with no owner or mitigation action, which produces a document that looks thorough but changes nothing.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.