Agent skill

Risk Management Specialist

by borghei in borghei/Claude-Skills

Medical device risk management specialist implementing ISO 14971 throughout product lifecycle.

MITAuto-check passedLegal & Compliance

Install Risk Management Specialist

skills CLI
$ npx skills add borghei/Claude-Skills --skill risk-management-specialist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills risk-management-specialist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/risk-management-specialist .claude/skills/risk-management-specialist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
risk-management-specialist
GitHub stars
891
Token cost
~1.9k tokens
SKILL.md length
708 words
Files
7 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

Medical device risk management specialist implementing ISO 14971 throughout product lifecycle.

  • Tasks that involve Legal risk assessment
  • SKILL.md covers Core Capabilities, When to Use, Clarify First and Quick Start, plus 3 more sections
  • Runs Python scripts from its folder; calls python

What it does

Risk Management Specialist is an agent skill from borghei/Claude-Skills. Medical device risk management specialist implementing ISO 14971 throughout product lifecycle. Provides risk analysis, risk evaluation, risk control, and post-production information analysis.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/extended-risk-domains.md`, `references/iso14971-implementation-guide.md` and `references/risk-analysis-methods.md`).

It sits in Legal & Compliance, covering Legal risk assessment. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Tasks that involve Legal risk assessment

Example prompts

  • “/risk-management-specialist”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Risk Management Specialist loads about 1.9k tokens when it runs, and up to ~18k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 708 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~18k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 708 words, ~1,869 tokens.

Download SKILL.mdSave it as .claude/skills/risk-management-specialist/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
risk-management-specialist
description
Medical device risk management specialist implementing ISO 14971 throughout product lifecycle. Provides risk analysis, risk evaluation, risk control, and post-production information analysis.
license
MIT + Commons Clause
metadata.version
1.1.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
risk-management
metadata.updated
2026-06-15
metadata.tags
iso-14971, risk-analysis, fmea, risk-register, medical-device

Risk Management Specialist

ISO 14971:2019 risk management implementation throughout the medical device lifecycle — planning, hazard analysis, risk evaluation, risk control, residual-risk assessment, and post-production monitoring — extended for AI/ML, cybersecurity (IEC 81001-5-1), supply chain, and cross-framework alignment (NIST CSF, DORA, NIS2).

Core Capabilities

  • Risk management planning — scope, 5x5 acceptability matrix, RACI, verification and post-production planning
  • Risk analysis & evaluation — hazard identification across 9 categories, P1-P5 / S1-S5 estimation, ALARP, benefit-risk triggers
  • Risk control — priority hierarchy (inherent safety → protective measures → information for safety), verification methods, residual-risk evaluation
  • Post-production monitoring — information sources, review triggers, RM-file update procedures, periodic review
  • Extended domains — AI/ML risk (bias, drift, adversarial inputs), health-software cybersecurity, supply chain risk, cross-framework mapping

When to Use

  • Implementing ISO 14971:2019 across the device lifecycle
  • Building a hazard analysis / risk register using FMEA, FTA, HAZOP, or Use Error Analysis
  • Evaluating residual risk and demonstrating ALARP or benefit-risk acceptability
  • Extending risk management to AI/ML devices, cybersecurity, or supply chain
  • Setting up post-production risk monitoring and Risk Management File update triggers

Clarify First

Before running the risk assessment, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Device and intended use — what it is and its use context (drives the hazard categories and benefit-risk analysis)
  • Lifecycle stage — planning, hazard analysis, risk control, or post-production (picks the workflow)
  • Acceptability criteria — the 5x5 matrix thresholds and ALARP definition (determines the risk-evaluation outcomes)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the risk register.

Quick Start

bash
# ISO 14971 risk level (probability × severity, 1-5 each)
python scripts/risk_matrix_calculator.py --probability 3 --severity 4

# FMEA Risk Priority Number (severity / occurrence / detection, 1-10 each)
python scripts/risk_matrix_calculator.py --fmea --severity 8 --occurrence 4 --detection 3

# Guided interactive assessment, or list the full criteria scales
python scripts/risk_matrix_calculator.py --interactive
python scripts/risk_matrix_calculator.py --list-criteria

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • references/risk-process.md — full ISO 14971 process: planning, analysis, evaluation, control, and post-production workflows; 5x5 acceptability matrix; probability/severity criteria; hazard checklist; and the decision frameworks. Read when executing any lifecycle stage.
  • references/risk-analysis-methods.md — FMEA, FTA, HAZOP, Use Error Analysis, and software hazard analysis methods. Read when choosing and applying a hazard-analysis technique.
  • references/iso14971-implementation-guide.md — complete ISO 14971:2019 implementation framework with templates. Read for clause-level implementation detail.
  • references/templates-and-tools.md — Hazard Analysis / FMEA worksheets, Risk Management Report template, full risk_matrix_calculator.py flag reference, troubleshooting table, and success criteria. Read when documenting assessments or diagnosing tool issues.
  • references/extended-risk-domains.md — AI/ML risk categories and methodology, IEC 81001-5-1 cybersecurity integration, supply chain risk, post-market monitoring automation, combined safety-security FMEA, and NIST CSF / DORA / NIS2 cross-framework mapping. Read for connected, software, or AI-enabled devices.
Show full SKILL.md (312 more words)Show less

Scope & Limitations

In Scope:

  • ISO 14971:2019 risk management process implementation (planning, analysis, evaluation, control, residual risk, production/post-production)
  • 5x5 risk matrix calculation and FMEA RPN scoring
  • Hazard analysis methodology guidance (FMEA, FTA, HAZOP, Use Error Analysis, PHA)
  • Risk control hierarchy application and verification planning
  • Benefit-risk analysis framework
  • Post-production risk monitoring and risk file update triggers
  • AI/ML-specific risk management extensions (model bias, drift, adversarial inputs)
  • Cybersecurity risk integration per IEC 81001-5-1
  • Supply chain risk assessment methodology
  • Cross-framework risk mapping (ISO 14971, NIST CSF, DORA, NIS2)

Out of Scope:

  • Clinical investigation design or execution (risk management informs clinical strategy but does not execute studies)
  • Software hazard analysis per IEC 62304 (the skill references software risk but detailed software lifecycle management requires IEC 62304 expertise)
  • Biocompatibility testing or ISO 10993 evaluation (the skill identifies biological hazards but does not execute biocompatibility testing)
  • Cybersecurity penetration testing or vulnerability scanning (use infrastructure-compliance-auditor for technical security testing)
  • CAPA root cause analysis execution (use capa-officer for 5-Why, Fishbone, FTA, FMEA-based root cause investigation)
  • Regulatory submission of risk management files (use regulatory-affairs-head for submission strategy and packaging)

Integration Points

SkillIntegration
quality-manager-qms-iso13485Risk management (Clause 7.1) integrates with QMS product realization planning; risk file is part of the Design History File
capa-officerPost-market risk signals may trigger CAPA; CAPA root cause analysis methods (FMEA, FTA) overlap with risk analysis techniques
regulatory-affairs-headRisk management file is required for FDA submissions and EU MDR Technical Documentation; benefit-risk analysis supports clinical evaluation
quality-documentation-managerRisk management file and records must be controlled per document control procedures (Clause 4.2)
fda-consultant-specialistFDA cybersecurity guidance (2025 update) requires integration of security risks into ISO 14971 processes for premarket submissions
infrastructure-compliance-auditorTechnical security controls validated by the infrastructure auditor serve as risk mitigations for cybersecurity threats in the risk assessment
nist-csf-specialistNIST CSF risk assessment (ID.RA) maps to ISO 14971 hazard identification and risk estimation; unified risk register possible

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in ra-qm-team/risk-management-specialist of borghei/Claude-Skills.

  • SKILL.md
  • references/extended-risk-domains.md
  • references/iso14971-implementation-guide.md
  • references/risk-analysis-methods.md
  • references/risk-process.md
  • references/templates-and-tools.md
  • scripts/risk_matrix_calculator.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Risk Management Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Risk Management Specialist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Risk Management Specialist this skillborghei/Claude-Skills891—~1.9kAutomated safety check: PassMIT
Product Launch Legal Reviewanthropics/claude-for-legal9.6k2 repos~5kAutomated safety check: PassApache-2.0
Legal Risk Visualizationzh-xx/legal-assistant-skills174—~2.4kAutomated safety check: PassApache-2.0
Contract Renewal Trackeranthropics/claude-for-legal9.6k2 repos~3.1kAutomated safety check: PassApache-2.0
Deep Risk Analysiszubair-trabzada/ai-legal-claude1.8k—~1.9kAutomated safety check: PassNone
Canghe Tianyanchafreestylefly/canghe-skills461—~2.4kAutomated safety check: PassNone

Similar skills

  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Legal & ComplianceAuto-check passed
  • Legal Risk Visualization

    zh-xx/legal-assistant-skills

    法律风险结构化分析与可视化。基于法律分析文本,执行五步风险抽取模型, 生成四层可视化输出(雷达图数据、风险矩阵、影响路径图、决策树)。

    174 GitHub stars~2.4k tokensUpdated 5 mo ago
    Legal & ComplianceAuto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Legal & ComplianceAuto-check passed
  • Deep Risk Analysis

    zubair-trabzada/ai-legal-claude

    Clause-by-clause contract risk analysis with severity scoring, financial exposure estimates, and prioritized remediation guidance

    1.8k GitHub stars~1.9k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Canghe Tianyancha

    freestylefly/canghe-skills

    Generates Tianyancha-style company and industry insight dashboards from researched enterprise data.

    461 GitHub stars~2.4k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check passed
  • EU AI Act System Inventory

    anthropics/claude-for-legal

    Official

    Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.

    9.6k GitHub starsUsed in 3 repos~2.8k tokens
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    891 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    891 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    891 GitHub stars~3.6k tokensUpdated 3 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    891 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    891 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed

Questions about Risk Management Specialist

What does Risk Management Specialist do?

Medical device risk management specialist implementing ISO 14971 throughout product lifecycle. Risk Management Specialist is an agent skill from borghei/Claude-Skills. Medical device risk management specialist implementing ISO 14971 throughout product lifecycle.

When should I use Risk Management Specialist?

Risk Management Specialist fits situations like: tasks that involve Legal risk assessment.

How do I install Risk Management Specialist in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill risk-management-specialist -a claude-code`. Or copy the skill folder (ra-qm-team/risk-management-specialist in borghei/Claude-Skills) into .claude/skills/risk-management-specialist in your project. Claude Code loads it when a task matches its description.

How do I install Risk Management Specialist in Codex?

Run `npx skills add borghei/Claude-Skills --skill risk-management-specialist -a codex`. Or copy the skill folder (ra-qm-team/risk-management-specialist in borghei/Claude-Skills) into .agents/skills/risk-management-specialist in your project. Codex loads it when a task matches its description.

Can I use Risk Management Specialist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill risk-management-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/risk-management-specialist, .gemini/skills/risk-management-specialist, .github/skills/risk-management-specialist and .opencode/skills/risk-management-specialist in your project.

What does Risk Management Specialist need to run?

Going by SKILL.md and its folder, Risk Management Specialist needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Risk Management Specialist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Risk Management Specialist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Risk Management Specialist use?

Risk Management Specialist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Risk Management Specialist use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.

What are the alternatives to Risk Management Specialist?

Skills that share tags, products or a category with Risk Management Specialist: Product Launch Legal Review (anthropics/claude-for-legal, 9.6k stars), Legal Risk Visualization (zh-xx/legal-assistant-skills, 174 stars), Contract Renewal Tracker (anthropics/claude-for-legal, 9.6k stars) and Deep Risk Analysis (zubair-trabzada/ai-legal-claude, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Risk Management Specialist?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.