Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
borghei avatar

Legal Risk Assessment

  • 47 installs
  • 451 repo stars
  • Updated July 21, 2026
  • borghei/claude-skills

legal-risk-assessment is a skill that scores legal risks on a 5x5 Severity x Likelihood matrix, maintains a risk register, and guides escalation decisions.

About

This skill runs structured legal risk assessment using a quantitative 5x5 Severity x Likelihood matrix. It scores individual risks, assigns color-coded levels with recommended actions, maintains a risk register, and generates assessment memos. Legal teams use it for risk scoring, register maintenance, and escalation decisions. It is explicitly experimental and not legal advice.

  • Scores legal risk with a quantitative 5x5 Severity x Likelihood matrix
  • Assigns color-coded risk levels (GREEN/YELLOW/ORANGE/RED) and recommended actions
  • Generates risk assessment memos and guides outside-counsel escalation decisions

Legal Risk Assessment by the numbers

  • 47 all-time installs (skills.sh)
  • Ranked #1,355 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

legal-risk-assessment capabilities & compatibility

Capabilities
risk assessment · risk scoring · escalation routing · compliance check
Use cases
security audit · planning
Pricing
Free
From the docs

What legal-risk-assessment says it does

Structured legal risk assessment using a quantitative 5x5 Severity x Likelihood matrix. Scores risks, maintains registers, generates assessment memos, and guides escalation decisions.
SKILL.md
Color-coded level (GREEN / YELLOW / ORANGE / RED)
SKILL.md
When to engage outside counsel:
SKILL.md
npx skills add https://github.com/borghei/claude-skills --skill legal-risk-assessment

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs47
repo stars451
Last updatedJuly 21, 2026
Repositoryborghei/claude-skills

What it does

Score legal risks on a 5x5 severity-likelihood matrix, maintain a risk register, and guide escalation decisions.

Who is it for?

Legal teams scoring risks, maintaining risk registers, and deciding when to escalate to outside counsel.

Skip if: Anyone needing actual legal advice; the skill is experimental and explicitly not legal advice.

When should I use this skill?

You need risk scoring, a risk register, escalation decisions, or a risk memo.

What you get

Produces a color-coded risk score, recommended action, register entry, and an assessment memo with escalation guidance.

  • Risk scores
  • Risk register
  • Risk assessment memo

By the numbers

  • 5x5 Severity x Likelihood matrix
  • Four color-coded risk levels: GREEN, YELLOW, ORANGE, RED
  • Two Python tools: risk scorer and risk report generator

Files

SKILL.mdMarkdownGitHub ↗
⚠️ EXPERIMENTAL — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output.

Legal Risk Assessment

Structured legal risk assessment using a quantitative 5x5 Severity x Likelihood matrix. Scores risks, maintains registers, generates assessment memos, and guides escalation decisions.

---

Table of Contents

---

Tools

Risk Scorer

Calculates risk scores from severity and likelihood inputs, assigns color-coded risk levels, and generates summary statistics.

# Score a single risk
python scripts/risk_scorer.py --severity 4 --likelihood 3 \
  --category "Contract" --description "Vendor SLA non-compliance"

# JSON output
python scripts/risk_scorer.py --severity 4 --likelihood 3 \
  --category "Contract" --description "Vendor SLA breach" --json

# Batch mode from risk register file
python scripts/risk_scorer.py --input risks.json --json

# Batch mode with human-readable output
python scripts/risk_scorer.py --input risks.json

Input JSON format (batch mode):

{
  "risks": [
    {"severity": 4, "likelihood": 3, "category": "Contract", "description": "Vendor SLA breach"},
    {"severity": 2, "likelihood": 2, "category": "Regulatory", "description": "Minor filing delay"}
  ]
}

Output includes:

  • Risk score (Severity x Likelihood)
  • Color-coded level (GREEN / YELLOW / ORANGE / RED)
  • Recommended action (Accept / Monitor / Mitigate / Escalate)
  • Batch summary statistics (count per level, average score)

---

Risk Report Generator

Generates a formatted risk assessment memo in markdown from a risk register JSON file.

# Generate memo from risk register
python scripts/risk_report_generator.py --input risk_register.json

# Save to file
python scripts/risk_report_generator.py --input risk_register.json --output memo.md

# JSON metadata output
python scripts/risk_report_generator.py --input risk_register.json --json

Report includes:

  • ASCII risk matrix visualization
  • Risk distribution summary (counts and percentages per level)
  • Top risks ranked by score
  • Recommended actions per risk with owner assignments
  • Monitoring plan suggestions
  • Escalation recommendations

---

Reference Guides

Risk Framework

references/risk_framework.md

Complete Severity x Likelihood matrix reference:

  • Severity levels 1-5 with financial exposure percentages
  • Likelihood levels 1-5 with probability ranges
  • Risk matrix visualization
  • Risk classification (GREEN/YELLOW/ORANGE/RED) with actions
  • Documentation standards for memos and register entries

Escalation Guide

references/escalation_guide.md

When to engage outside counsel:

  • Mandatory engagement triggers (litigation, investigation, criminal)
  • Strongly recommended scenarios (novel issues, material exposure)
  • Consider scenarios (complex disputes, employment, data incidents)
  • Risk category definitions and contributing/mitigating factors

---

Workflows

Workflow 1: New Risk Assessment

Step 1: Identify risk category and description
        → Use references/risk_framework.md category definitions

Step 2: Score severity (1-5) and likelihood (1-5)
        → python scripts/risk_scorer.py --severity N --likelihood N \
          --category "Category" --description "Description"

Step 3: Review risk level and recommended action
        → GREEN: Accept and document
        → YELLOW: Assign owner and monitor
        → ORANGE: Escalate to senior counsel
        → RED: Immediate escalation, crisis management

Step 4: Determine outside counsel need
        → Consult references/escalation_guide.md

Step 5: Document in risk register
        → Add entry to register JSON file

Workflow 2: Periodic Risk Register Review

Step 1: Load current risk register
        → python scripts/risk_scorer.py --input register.json

Step 2: Generate assessment memo
        → python scripts/risk_report_generator.py --input register.json --output memo.md

Step 3: Review top risks and distribution
        → Focus on ORANGE and RED risks first

Step 4: Update severity/likelihood for changed risks
        → Re-score and regenerate report

Step 5: Distribute memo to stakeholders

Workflow 3: Escalation Decision

Step 1: Score the risk
        → python scripts/risk_scorer.py --severity N --likelihood N \
          --category "Category" --description "Description"

Step 2: Check escalation triggers
        → Mandatory: active litigation, government investigation, criminal exposure
        → Strongly Recommended: novel issues, jurisdictional complexity, material exposure
        → Consider: complex disputes, employment matters, data incidents

Step 3: Document escalation rationale
        → Include risk score, level, and specific trigger in memo

Step 4: Select outside counsel if needed
        → See references/escalation_guide.md criteria

---

Troubleshooting

ProblemPossible CauseResolution
Risk score seems too low for a serious matterSeverity or likelihood underestimated; qualitative factors not capturedReview severity descriptions in risk_framework.md; consider worst-case financial exposure; add contributing factors to description
Multiple risks in same category but different scoresRisks have different severity/likelihood combinationsThis is expected; each risk is independent; review category-level trends in report
Batch mode fails on input fileMalformed JSON or missing required fieldsVerify JSON structure matches expected format; ensure each risk has severity, likelihood, category, description
Report generator produces empty matrixNo risks in input file or all risks have invalid scoresCheck that input JSON contains valid risks with severity 1-5 and likelihood 1-5
Escalation guide suggests outside counsel but budget is constrainedRisk score indicates material exposureDocument the budget constraint and residual risk acceptance; consider limited-scope engagement
Risk register grows unwieldyRisks not being closed or consolidatedArchive resolved risks; consolidate related risks; review register quarterly

---

Success Criteria

  • All identified legal risks scored and documented -- every risk has severity, likelihood, category, description, and recommended action in the register
  • Risk distribution reviewed quarterly -- memo generated and distributed to stakeholders with trend analysis
  • ORANGE and RED risks have assigned owners and mitigation plans -- no high-severity risk without accountability
  • Escalation decisions documented with rationale -- outside counsel engagement triggers clearly recorded
  • Risk register maintained as living document -- risks updated, resolved, or archived as status changes

---

Scope & Limitations

In Scope:

  • Quantitative risk scoring using 5x5 Severity x Likelihood matrix
  • Risk register management and batch processing
  • Risk assessment memo generation with matrix visualization
  • Escalation guidance for outside counsel engagement
  • Risk categorization (Contract, Regulatory, Litigation, IP, Data Privacy, Employment, Corporate)

Out of Scope:

  • Legal advice on specific risk mitigation strategies -- consult legal counsel
  • Insurance coverage analysis or actuarial calculations
  • Regulatory filing or submission preparation
  • Contract drafting or review
  • Litigation strategy or case management

---

Anti-Patterns

  • Scoring by committee consensus without criteria -- use the defined severity and likelihood scales consistently; do not negotiate scores to make stakeholders comfortable; a risk scored as 4 severity should match the framework definition
  • Treating the risk register as a one-time exercise -- risk registers are living documents; risks change as circumstances evolve; schedule quarterly reviews and update scores accordingly
  • Escalating everything to outside counsel -- the escalation guide defines specific triggers; not every YELLOW risk needs external counsel; over-escalation wastes budget and creates dependency
  • Ignoring GREEN risks entirely -- GREEN risks still require documentation and periodic monitoring; a GREEN risk can escalate to YELLOW or ORANGE if circumstances change
  • Using risk scores as the sole decision factor -- scores are inputs to judgment, not substitutes; qualitative factors like reputational impact or strategic importance may warrant action beyond what the score suggests

---

Tool Reference

risk_scorer.py

Calculates risk scores and assigns color-coded risk levels with recommended actions.

FlagRequiredDescription
--severity <1-5>Yes (single mode)Severity rating: 1=Negligible, 2=Minor, 3=Moderate, 4=Major, 5=Critical
--likelihood <1-5>Yes (single mode)Likelihood rating: 1=Remote, 2=Unlikely, 3=Possible, 4=Likely, 5=Almost Certain
--category <text>Yes (single mode)Risk category: Contract, Regulatory, Litigation, IP, Data Privacy, Employment, Corporate
--description <text>Yes (single mode)Risk description
--input <file>Yes (batch mode)Path to JSON file containing multiple risks
--jsonNoOutput results in JSON format

risk_report_generator.py

Generates formatted risk assessment memo from a risk register JSON file.

FlagRequiredDescription
--input <file>YesPath to risk register JSON file
--output <file>NoSave memo to specified file path (markdown format)
--jsonNoOutput report metadata in JSON format

Related skills

FAQ

What scoring model does it use?

A quantitative 5x5 Severity x Likelihood matrix that produces a color-coded level (GREEN/YELLOW/ORANGE/RED) and a recommended action.

Is this legal advice?

No. The skill is explicitly experimental, for educational purposes only, and not legal advice.

Securitycomplianceaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.