Agent skill

Risk Classification

by athola in athola/claude-night-market

Classifies agent tasks into 4 risk tiers (GREEN/YELLOW/RED/CRITICAL).

MITAuto-check passedLegal & Compliance

Install Risk Classification

skills CLI
$ npx skills add athola/claude-night-market --skill risk-classification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install athola/claude-night-market risk-classification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/leyline/skills/risk-classification .claude/skills/risk-classification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
risk-classification
GitHub stars
342
Token cost
~1.4k tokens
SKILL.md length
462 words
Files
6
Skills in repo
159
Repo updated
First seen
Licence
MIT

At a glance

Classifies agent tasks into 4 risk tiers (GREEN/YELLOW/RED/CRITICAL).

  • Assessing action reversibility before committing to an approach
  • SKILL.md covers Overview, When To Use, When NOT To Use and 4-Tier Risk Model, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Legal risk assessment

What it does

Risk Classification is an agent skill from athola/claude-night-market. Classifies agent tasks into 4 risk tiers (GREEN/YELLOW/RED/CRITICAL). Use when assessing action reversibility before committing to an approach.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files (for example `modules/automation-tiers.md`, `modules/heuristic-classifier.md` and `modules/readiness-levels.md`).

It sits in Legal & Compliance, covering Legal risk assessment. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.

When your agent uses it

  • Assessing action reversibility before committing to an approach
  • Tasks that involve Legal risk assessment

Example prompts

  • “Use the risk-classification skill to classify agent tasks into 4 risk tiers (GREEN/YELLOW/RED/CRITICAL)”
  • “/risk-classification”

What it can do on your machine

Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json, yaml and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Risk Classification loads about 1.4k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 462 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 462 words, ~1,435 tokens.

Download SKILL.mdSave it as .claude/skills/risk-classification/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
risk-classification
description
Classifies agent tasks into 4 risk tiers (GREEN/YELLOW/RED/CRITICAL). Use when assessing action reversibility before committing to an approach.
alwaysApply
false
category
infrastructure
tags
risk, classification, safety, verification, gates
dependencies
error-patterns
provides.infrastructure
risk-tier-classification, verification-gates, heuristic-classifier
provides.patterns
risk-aware-coordination, tier-based-verification
usage_patterns
task-risk-assessment, verification-gate-routing, parallel-safety-validation
complexity
intermediate
model_hint
standard
estimated_tokens
500

Risk Classification

Overview

Provides inline risk classification for agent tasks using a 4-tier model (GREEN/YELLOW/RED/CRITICAL). Uses fast heuristic file-pattern matching for low-risk tiers and delegates to Skill(attune:war-room-checkpoint) for high-risk tiers requiring full reversibility scoring.

When To Use

  • Assessing risk of tasks before agent assignment
  • Determining verification requirements for task completion
  • Deciding parallel execution safety between tasks
  • Adding risk markers to task checklists

When NOT To Use

  • Single-file trivial changes (assume GREEN)
  • Strategic architecture decisions (use full Skill(attune:war-room) instead)
  • Non-code tasks (documentation-only, configuration comments)

4-Tier Risk Model

TierColorScopeExampleVerification
GREENSafeSingle file, trivial revertTest files, docs, utilsNone required
YELLOWCautionModule-level, user-visibleComponents, routes, viewsConflict check and test pass
REDDangerCross-module, security/dataMigrations, auth, database schemaWar-room RS, full test, and review
CRITICALStopIrreversible, regulatedData deletion, production deployWar-room RS and human approval

Hybrid Routing

Task received
    |
    v
Heuristic classifier (file patterns)
    |
    ├── GREEN/YELLOW → Apply tier, continue
    |
    └── RED/CRITICAL → Invoke Skill(attune:war-room-checkpoint)
                        for reversibility scoring (RS)
                        |
                        └── RS confirms or adjusts tier

Why hybrid: GREEN/YELLOW classification is fast and deterministic (file pattern matching). RED/CRITICAL tasks warrant the overhead of full reversibility analysis because the cost of getting them wrong is high.

Task Metadata Extension

Add risk tier to task metadata for downstream consumption:

json
{
  "id": "5",
  "subject": "Add user authentication",
  "metadata": {
    "risk_tier": "YELLOW",
    "risk_reason": "Modifies src/components/LoginForm.tsx (user-visible component)",
    "classified_at": "2026-02-07T22:00:00Z"
  }
}

Tasks without risk_tier metadata default to GREEN (backward compatible).

Readiness Levels

The 4-tier Readiness Levels system provides clear risk classification with required controls per tier:

LevelNameWhenRequired Controls
0RoutineLow blast radius, easy rollbackBasic validation, rollback step
1WatchUser-visible changesReview, negative test, rollback note
2ElevatedSecurity/compliance/dataAdversarial review, risk checklist
3CriticalIrreversible, regulatedHuman confirmation, two-step verification

See modules/readiness-levels.md for full level definitions, selection decision tree, and integration guidance.

Show full SKILL.md (200 more words)Show less

Graduated Autonomy

Risk classification sets how carefully a change is verified. Automation tiers set how autonomously the agent acts and when it must hand control back. Each risk tier carries a default automation tier (GREEN to A3 autonomous, CRITICAL to A0 manual), and a pre-licensed downgrade trigger drops the agent one tier on repeated failure, confidence loss, a stakes spike, or repo-state mismatch rather than re-prompting at the same level. See modules/automation-tiers.md for the tier table and the downgrade trigger, and imbue:assisted-mastery for the explain/produce mode selection that reads from it.

Module Reference

  • tier-definitions.md: Detailed tier criteria, boundaries, and override mechanism
  • heuristic-classifier.md: File-pattern rules for automated classification
  • verification-gates.md: Per-tier verification requirements and parallel safety matrix
  • readiness-levels.md: 4-tier risk system with required controls per level
  • automation-tiers.md: Per-tier autonomy defaults and the downgrade trigger

Integration Pattern

yaml
# In your skill's frontmatter
dependencies: [leyline:risk-classification]
For Task Generators

Append [R:TIER] marker to task format:

markdown
- [ ] T012 [P] [US1] [R:YELLOW] Create LoginForm component in src/components/LoginForm.tsx
For Orchestrators

Check risk tier before task assignment:

if task.risk_tier in ["RED", "CRITICAL"]:
    invoke Skill(attune:war-room-checkpoint) for RS scoring
    if CRITICAL: require human approval before proceeding

Exit Criteria

  • Every task has a risk tier assigned (explicit or default GREEN)
  • RED/CRITICAL tasks have war-room-checkpoint RS scores
  • Verification gates passed for the assigned tier
  • No parallel execution of prohibited tier combinations
  • Each task carries an automation tier; downgrades are recorded with a reason when a trigger fires

© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files in plugins/leyline/skills/risk-classification of athola/claude-night-market.

  • SKILL.md
  • modules/automation-tiers.md
  • modules/heuristic-classifier.md
  • modules/readiness-levels.md
  • modules/tier-definitions.md
  • modules/verification-gates.md

Open the folder on GitHubat commit 9f3eb00

Compare with similar skills

Risk Classification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Risk Classification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Risk Classification this skillathola/claude-night-market342—~1.4kAutomated safety check: PassMIT
Product Launch Legal Reviewanthropics/claude-for-legal9.6k2 repos~5kAutomated safety check: PassApache-2.0
Legal Risk Visualizationzh-xx/legal-assistant-skills173—~2.4kAutomated safety check: PassApache-2.0
Contract Renewal Trackeranthropics/claude-for-legal9.6k2 repos~3.1kAutomated safety check: PassApache-2.0
Deep Risk Analysiszubair-trabzada/ai-legal-claude1.8k—~1.9kAutomated safety check: PassNone
Canghe Tianyanchafreestylefly/canghe-skills461—~2.4kAutomated safety check: PassNone

Similar skills

  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Legal & ComplianceAuto-check passed
  • Legal Risk Visualization

    zh-xx/legal-assistant-skills

    法律风险结构化分析与可视化。基于法律分析文本,执行五步风险抽取模型, 生成四层可视化输出(雷达图数据、风险矩阵、影响路径图、决策树)。

    173 GitHub stars~2.4k tokensUpdated 5 mo ago
    Legal & ComplianceAuto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Legal & ComplianceAuto-check passed
  • Deep Risk Analysis

    zubair-trabzada/ai-legal-claude

    Clause-by-clause contract risk analysis with severity scoring, financial exposure estimates, and prioritized remediation guidance

    1.8k GitHub stars~1.9k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Canghe Tianyancha

    freestylefly/canghe-skills

    Generates Tianyancha-style company and industry insight dashboards from researched enterprise data.

    461 GitHub stars~2.4k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check passed
  • EU AI Act System Inventory

    anthropics/claude-for-legal

    Official

    Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.

    9.6k GitHub starsUsed in 3 repos~2.8k tokens
    Legal & ComplianceAuto-check passed

More from athola/claude-night-market

All 159 skills in this repo
  • Night Market Diagnostics Toolkit

    athola/claude-night-market

    Run and interpret repo diagnostic scripts (ratchets, validators, token stats).

    342 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Skills Eval

    athola/claude-night-market

    Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.

    342 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Agent Teams

    athola/claude-night-market

    Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.

    342 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Delegation Core

    athola/claude-night-market

    Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).

    342 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Elegant Code

    athola/claude-night-market

    Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.

    342 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • Skill Library Mission

    athola/claude-night-market

    Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.

    342 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed

Questions about Risk Classification

What does Risk Classification do?

Classifies agent tasks into 4 risk tiers (GREEN/YELLOW/RED/CRITICAL). Risk Classification is an agent skill from athola/claude-night-market. Classifies agent tasks into 4 risk tiers (GREEN/YELLOW/RED/CRITICAL).

When should I use Risk Classification?

Risk Classification fits situations like: assessing action reversibility before committing to an approach; tasks that involve Legal risk assessment.

How do I install Risk Classification in Claude Code?

Run `npx skills add athola/claude-night-market --skill risk-classification -a claude-code`. Or copy the skill folder (plugins/leyline/skills/risk-classification in athola/claude-night-market) into .claude/skills/risk-classification in your project. Claude Code loads it when a task matches its description.

How do I install Risk Classification in Codex?

Run `npx skills add athola/claude-night-market --skill risk-classification -a codex`. Or copy the skill folder (plugins/leyline/skills/risk-classification in athola/claude-night-market) into .agents/skills/risk-classification in your project. Codex loads it when a task matches its description.

Can I use Risk Classification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill risk-classification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/risk-classification, .gemini/skills/risk-classification, .github/skills/risk-classification and .opencode/skills/risk-classification in your project.

What does Risk Classification need to run?

SKILL.md names no scripts, command-line tools or credentials: Risk Classification is instructions for the agent only.

Does Risk Classification access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Risk Classification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Risk Classification use?

Risk Classification is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Risk Classification use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Risk Classification?

Skills that share tags, products or a category with Risk Classification: Product Launch Legal Review (anthropics/claude-for-legal, 9.6k stars), Legal Risk Visualization (zh-xx/legal-assistant-skills, 173 stars), Contract Renewal Tracker (anthropics/claude-for-legal, 9.6k stars) and Deep Risk Analysis (zubair-trabzada/ai-legal-claude, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Risk Classification?

athola (a GitHub user) maintains it in athola/claude-night-market, which has 342 GitHub stars. The repository holds 159 skills in this directory. The repository was last updated on October 6, 2026.

Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.