Agent skill

Risky Changes

by davidondrej in davidondrej/skills

Verify assumptions before implementing large or risky changes to APIs, provider data, billing, pricing, quotas, or defaults.

MITAuto-check passed

Install Risky Changes

skills CLI
$ npx skills add davidondrej/skills --skill risky-changes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davidondrej/skills risky-changes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davidondrej/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ops-and-setup/risky-changes .claude/skills/risky-changes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
risky-changes
GitHub stars
4.1k
Token cost
~709 tokens
SKILL.md length
360 words
Files
1
Skills in repo
51
Repo updated
First seen
Licence
MIT

At a glance

Verify assumptions before implementing large or risky changes to APIs, provider data, billing, pricing, quotas, or defaults.

  • Works in 5 steps: Identify assumptions → Research before implementing → Measure real behavior → …
  • A mistake could affect customers
  • SKILL.md covers When this applies, 1. Identify assumptions, 2. Research before implementing and 3. Measure real behavior, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Risky Changes is an agent skill from davidondrej/skills. Verify assumptions before implementing large or risky changes to APIs, provider data, billing, pricing, quotas, or defaults. Use when a mistake could affect customers or the user asks if a change is safe to ship. Checks real-world impact beyond passing tests.

Its SKILL.md is about 710 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: access to david ondrej's personal agent skills. The licence is MIT.

When your agent uses it

  • A mistake could affect customers
  • The user asks if a change is safe to ship

Example prompts

  • “/risky-changes”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify assumptions
  2. Research before implementing
  3. Measure real behavior
  4. Confirm product-owner approval before shipping
  5. Verify after deployment

What it can do on your machine

Read from SKILL.md and the folder at commit 7874889. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Risky Changes loads about 709 tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 360 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~709

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davidondrej/skills at commit 7874889, republished under its MIT licence (© davidondrej). 360 words, ~709 tokens.

Download SKILL.mdSave it as .claude/skills/risky-changes/SKILL.md (or your agent's skills folder).
name
risky-changes
description
Verify assumptions before implementing large or risky changes to APIs, provider data, billing, pricing, quotas, or defaults. Use when a mistake could affect customers or the user asks if a change is safe to ship. Checks real-world impact beyond passing tests.

Risky Changes

A filter once passed every test but disabled ~99% of the feature on live data. Tests check code correctness; research and live measurement check whether a change is useful.

When this applies

Use for changes where being wrong is expensive or customer-visible:

  • Public API fields, filters, or response shaping
  • Dropping, transforming, or reordering upstream data
  • Billing, pricing, caps, or quotas
  • Defaults, thresholds, or provider request parameters
  • Unverified assumptions about external data or user behavior

If unsure whether a change qualifies, apply this process.

1. Identify assumptions

List the assumptions the change depends on. Mark which have evidence and which are still unverified.

2. Research before implementing

Use available research tools and reliable sources. Investigate each distinct question separately, covering at least:

  • How do leading products handle this design decision?
  • What does real-world data look like: frequencies, shapes, and edge cases?
  • What do users or agents actually need?

If evidence contradicts an assumption, reconsider the design before coding. If research is unavailable or inconclusive, state the gap; do not treat the assumption as verified. Do not ship while material assumptions remain unverified.

Show full SKILL.md (177 more words)Show less

3. Measure real behavior

Run 10–20+ realistic cases against the real endpoint or provider:

  • Base cases on real usage; vary topics, parameters, languages, and edge conditions.
  • Define benchmarks per case: speed, quality, accuracy, and how often the new behavior occurs.
  • Use hard numbers where possible. For subjective quality, use blind, criteria-based judging.
  • Compare before and after when both can be measured.
  • Read-only production analysis also counts as measurement.

Save the cases and results in the project's evals folder, e.g. docs/evals/YYYY-MM-DD-<endpoint>-<focus>.md. Create the folder if needed. Without this record, the change is not verified. Unit tests do not replace live measurement.

4. Confirm product-owner approval before shipping

Present decisions that affect what customers see or pay, with supporting research and measurements. Get the product owner's approval for those decisions; do not bury them in a plan or code default. Existing approval counts if it covers the actual behavior being shipped.

5. Verify after deployment

Within one day, measure the change on real traffic through read-only production analysis or a live sweep. Report results that differ from expectations immediately.

© davidondrej, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ops-and-setup/risky-changes of davidondrej/skills.

Open the folder on GitHubat commit 7874889

Compare with similar skills

Risky Changes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Risky Changes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Risky Changes this skilldavidondrej/skills4.1k—~709Automated safety check: PassMIT
Identify Assumptions Existingphuryn/pm-skills27k—~525Automated safety check: PassMIT
Identify Assumptions Newphuryn/pm-skills27k—~807Automated safety check: PassMIT
Prioritize Assumptionsphuryn/pm-skills27k—~571Automated safety check: PassMIT
Large Class Stylesgl-project/sglang37k2 repos~1.9kAutomated safety check: PassApache-2.0
Frontend Large Feature Architecturelangfuse/langfuse36k—~1.4kAutomated safety check: PassCustom licence

Similar skills

  • Identify risky assumptions for a feature idea in an existing product across Value, Usability, Viability, and Feasibility.

    27k GitHub stars~525 tokensUpdated 24 days ago
    Frontend & DesignAuto-check passed
  • Identify Assumptions New

    phuryn/pm-skills

    Identify risky assumptions for a new product idea across 8 risk categories including Go-to-Market, Strategy, and Team.

    27k GitHub stars~807 tokensUpdated 24 days ago
    Marketing & SEOAuto-check passed
  • Prioritize Assumptions

    phuryn/pm-skills

    Prioritize assumptions using an Impact × Risk matrix and suggest experiments for each.

    27k GitHub stars~571 tokensUpdated 24 days ago
    Product & Project ManagementAuto-check passed
  • Large Class Style

    sgl-project/sglang

    Code style for SGLang large classes Scheduler, TokenizerManager, and ModelRunner: frozen-code conventions and init orchestration style.

    37k GitHub starsUsed in 2 repos~1.9k tokens
    AI & LLM EngineeringAuto-check passed
  • Architect large or state-heavy Langfuse frontend features. An agent skill from langfuse/langfuse.

    36k GitHub stars~1.4k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Recipe Find Large Files

    googleworkspace/cli

    Identify large Google Drive files consuming storage quota. An agent skill from googleworkspace/cli.

    31k GitHub stars~175 tokensUpdated 2 days ago
    Auto-check passed

More from davidondrej/skills

All 51 skills in this repo
  • Nagent

    davidondrej/skills

    Launch a new bb worker thread with the right project, model, worktree, and task brief.

    4.1k GitHub stars~1.7k tokensUpdated today
    Auto-check: notes
  • Browser Harness

    davidondrej/skills

    Direct browser control via CDP. An agent skill from davidondrej/skills.

    4.1k GitHub starsUsed in 2 repos~3k tokens
    Auto-check passed
  • Persistent Localhost

    davidondrej/skills

    Manage persistent dev servers, APIs, and other local processes on a port using macOS LaunchAgents.

    4.1k GitHub stars~618 tokensUpdated today
    Auto-check passed
  • Reset Cursor Acp

    davidondrej/skills

    Reset a stuck Cursor ACP thread in <chat-system and reload its configuration.

    4.1k GitHub stars~728 tokensUpdated today
    Auto-check passed
  • Anti Sleep

    davidondrej/skills

    Keep a Mac awake for a set duration or while a process runs.

    4.1k GitHub stars~640 tokensUpdated today
    Auto-check: warnings
  • Bb CLI

    davidondrej/skills

    Use this when controlling bb. An agent skill from davidondrej/skills.

    4.1k GitHub stars~823 tokensUpdated today
    Auto-check passed

Questions about Risky Changes

What does Risky Changes do?

Verify assumptions before implementing large or risky changes to APIs, provider data, billing, pricing, quotas, or defaults. Risky Changes is an agent skill from davidondrej/skills. Verify assumptions before implementing large or risky changes to APIs, provider data, billing, pricing, quotas, or defaults.

When should I use Risky Changes?

Risky Changes fits situations like: A mistake could affect customers; the user asks if a change is safe to ship.

How do I install Risky Changes in Claude Code?

Run `npx skills add davidondrej/skills --skill risky-changes -a claude-code`. Or copy the skill folder (skills/ops-and-setup/risky-changes in davidondrej/skills) into .claude/skills/risky-changes in your project. Claude Code loads it when a task matches its description.

How do I install Risky Changes in Codex?

Run `npx skills add davidondrej/skills --skill risky-changes -a codex`. Or copy the skill folder (skills/ops-and-setup/risky-changes in davidondrej/skills) into .agents/skills/risky-changes in your project. Codex loads it when a task matches its description.

Can I use Risky Changes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davidondrej/skills --skill risky-changes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/risky-changes, .gemini/skills/risky-changes, .github/skills/risky-changes and .opencode/skills/risky-changes in your project.

What does Risky Changes need to run?

SKILL.md names no scripts, command-line tools or credentials: Risky Changes is instructions for the agent only.

Does Risky Changes access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Risky Changes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Risky Changes use?

Risky Changes is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Risky Changes use?

About 709 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Risky Changes?

Skills that share tags, products or a category with Risky Changes: Identify Assumptions Existing (phuryn/pm-skills, 27k stars), Identify Assumptions New (phuryn/pm-skills, 27k stars), Prioritize Assumptions (phuryn/pm-skills, 27k stars) and Large Class Style (sgl-project/sglang, 37k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Risky Changes?

davidondrej (a GitHub user) maintains it in davidondrej/skills, which has 4,112 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.

Source: davidondrej/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.