
Risk Assessment
- 2.6k installs
- 23.3k repo stars
- Updated August 5, 2026
- anthropics/knowledge-work-plugins
risk-assessment is a knowledge-work skill for building operational risk registers with a standard matrix and mitigation fields.
About
The risk-assessment skill guides systematic identification, assessment, and mitigation planning for operational risks tied to projects, vendors, processes, or decisions. It opens with a likelihood-by-impact matrix that maps High, Medium, and Low combinations to Critical, High, Medium, or Low risk levels. Six risk categories cover operational, financial, compliance, strategic, reputational, and security concerns such as process failures, budget overruns, audit findings, market shifts, customer impact, and data breaches. For each risk the register captures description, likelihood, impact, derived risk level, mitigation actions, owner, and status values Open, Mitigated, Accepted, or Closed. Output is a prioritized risk register with specific, actionable mitigations focused on controllable and material risks. Triggers include phrases like risk assessment, risk register, what could go wrong, or when evaluating risks before a major decision. The workflow emphasizes structured documentation rather than ad hoc worry lists so teams can track ownership and mitigation progress over time.
- Likelihood-by-impact matrix maps combinations to Critical through Low levels.
- Six categories: operational, financial, compliance, strategic, reputational, security.
- Each risk documents description, likelihood, impact, level, mitigation, owner, status.
- Status values: Open, Mitigated, Accepted, or Closed.
- Output is a prioritized register focused on controllable, material risks.
Risk Assessment by the numbers
- 2,568 all-time installs (skills.sh)
- +104 installs in the week ending Aug 4, 2026 (Skillselion tracking)
- Ranked #206 of 3,282 Productivity & Planning skills by installs in the Skillselion catalog
- Security screen: MEDIUM risk (skills.sh audit)
- Data as of Aug 5, 2026 (Skillselion catalog sync)
risk-assessment capabilities & compatibility
- Capabilities
- likelihood impact matrix scoring · six category risk taxonomy · structured risk register fields · prioritized mitigation output
- Use cases
- planning · research
What risk-assessment says it does
Systematically identify, assess, and plan mitigations for operational risks.
Produce a prioritized risk register with specific, actionable mitigations.
Focus on risks that are controllable and material.
npx skills add https://github.com/anthropics/knowledge-work-plugins --skill risk-assessmentAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 2.6k |
|---|---|
| repo stars | ★ 23.3k |
| Security audit | 3 / 3 scanners passed |
| Last updated | August 5, 2026 |
| Repository | anthropics/knowledge-work-plugins ↗ |
What are the operational risks for this project, vendor, or decision and how should we mitigate them?
Build a prioritized operational risk register with likelihood, impact scoring, and actionable mitigations for projects or vendors.
Who is it for?
Teams evaluating operational, compliance, or security risks before major commitments.
Skip if: Skip for deep technical penetration testing or code-level security audits.
When should I use this skill?
User asks for risk assessment, risk register, what could go wrong, or vendor risk evaluation.
What you get
A prioritized risk register with likelihood, impact, owners, mitigations, and status tracking.
By the numbers
- Covers 6 risk categories: operational, financial, compliance, strategic, reputational, and security
Files
Risk Assessment
Systematically identify, assess, and plan mitigations for operational risks.
Risk Assessment Matrix
| Low Impact | Medium Impact | High Impact | |
|---|---|---|---|
| High Likelihood | Medium | High | Critical |
| Medium Likelihood | Low | Medium | High |
| Low Likelihood | Low | Low | Medium |
Risk Categories
- Operational: Process failures, staffing gaps, system outages
- Financial: Budget overruns, vendor cost increases, revenue impact
- Compliance: Regulatory violations, audit findings, policy breaches
- Strategic: Market changes, competitive threats, technology shifts
- Reputational: Customer impact, public perception, partner relationships
- Security: Data breaches, access control failures, third-party vulnerabilities
Risk Register Format
For each risk, document:
- Description: What could happen
- Likelihood: High / Medium / Low
- Impact: High / Medium / Low
- Risk Level: Critical / High / Medium / Low
- Mitigation: What we're doing to reduce likelihood or impact
- Owner: Who is responsible for managing this risk
- Status: Open / Mitigated / Accepted / Closed
Output
Produce a prioritized risk register with specific, actionable mitigations. Focus on risks that are controllable and material.
Related skills
How it compares
Pick risk-assessment over security audit skills when the need is cross-functional decision risk scoring, not code vulnerability scanning or penetration testing.
FAQ
What fields does each risk entry include?
Description, likelihood, impact, risk level, mitigation, owner, and status (Open, Mitigated, Accepted, Closed).
Which risk categories are covered?
Operational, financial, compliance, strategic, reputational, and security.
How is risk level determined?
Cross likelihood (High, Medium, Low) with impact (High, Medium, Low) using the provided matrix.
Is Risk Assessment safe to install?
skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.