Agent skill

Risk Assessment Methodology

by Hack23 in Hack23/cia

Systematic risk identification, analysis, evaluation, and treatment aligned with ISO 27005, NIST RMF, and Hack23 ISMS risk register

Apache-2.0Auto-check passedLegal & Compliance

Install Risk Assessment Methodology

skills CLI
$ npx skills add Hack23/cia --skill risk-assessment-methodology -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia risk-assessment-methodology --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/risk-assessment-methodology .claude/skills/risk-assessment-methodology && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
risk-assessment-methodology
GitHub stars
239
Token cost
~5.2k tokens
SKILL.md length
920 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Systematic risk identification, analysis, evaluation, and treatment aligned with ISO 27005, NIST RMF, and Hack23 ISMS risk register

  • Tasks that involve Legal risk assessment
  • SKILL.md covers Purpose, When to Use This Skill, Risk Assessment Process Flow and Likelihood Assessment Framework, plus 10 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Risk Assessment Methodology is an agent skill from Hack23/cia. Systematic risk identification, analysis, evaluation, and treatment aligned with ISO 27005, NIST RMF, and Hack23 ISMS risk register

Its SKILL.md is about 5.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Legal risk assessment. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Legal risk assessment

Example prompts

  • “/risk-assessment-methodology”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python, mermaid, yaml and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • img.shields.io
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Risk Assessment Methodology loads about 5.2k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 920 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 920 words, ~5,202 tokens.

Download SKILL.mdSave it as .claude/skills/risk-assessment-methodology/SKILL.md (or your agent's skills folder).
name
risk-assessment-methodology
description
Systematic risk identification, analysis, evaluation, and treatment aligned with ISO 27005, NIST RMF, and Hack23 ISMS risk register
license
Apache-2.0

Risk Assessment Methodology Skill

Purpose

This skill provides quantitative risk assessment methodology aligned with Hack23 AB's enterprise risk management framework. It enables security professionals and business leaders to systematically identify, analyze, evaluate, and treat risks using defensible statistical methods that demonstrate cybersecurity consulting expertise through measurable, data-driven risk quantification.

When to Use This Skill

Apply this skill when:

  • ✅ Conducting quarterly risk assessments
  • ✅ Evaluating risks for new products or services
  • ✅ Calculating Annual Loss Expectancy (ALE) for control investments
  • ✅ Prioritizing risk treatment based on quantitative impact
  • ✅ Documenting risk acceptance decisions
  • ✅ Creating risk registers for compliance frameworks
  • ✅ Performing threat modeling with financial impact
  • ✅ Supporting business case for security controls
  • ✅ Responding to client risk assessment inquiries

Do NOT use for:

  • ❌ Real-time incident response (use incident-response skill)
  • ❌ Vulnerability scoring (use vulnerability-management skill)
  • ❌ Code security reviews (use secure-code-review skill)

Risk Assessment Process Flow

mermaid
flowchart TD
    START["🎯 Risk Assessment<br/>Initiation"] --> IDENTIFY["📋 Risk Identification<br/>Assets • Threats • Vulnerabilities"]
    
    IDENTIFY --> ANALYZE["🔍 Risk Analysis"]
    
    ANALYZE --> LIKELIHOOD["📊 Likelihood Assessment<br/>Historical + Industry + Expert"]
    ANALYZE --> IMPACT["💰 Impact Assessment<br/>Financial • Operational • Reputational"]
    
    LIKELIHOOD --> CALC["🔢 Risk Score Calculation<br/>Probability × Impact × 100"]
    IMPACT --> CALC
    
    CALC --> CATEGORY{Risk Level?}
    
    CATEGORY -->|400-600| CRITICAL["🔴 Critical Risk<br/>Immediate action required"]
    CATEGORY -->|200-399| HIGH["🟠 High Risk<br/>Priority mitigation needed"]
    CATEGORY -->|100-199| MEDIUM["🟡 Medium Risk<br/>Planned controls required"]
    CATEGORY -->|50-99| LOW["🟢 Low Risk<br/>Monitor and accept"]
    CATEGORY -->|1-49| MINIMAL["⚪ Minimal Risk<br/>Accept risk"]
    
    CRITICAL --> TREAT{Treatment<br/>Decision}
    HIGH --> TREAT
    MEDIUM --> TREAT
    LOW --> ACCEPT["✅ Accept Risk<br/>Document in Risk Register"]
    MINIMAL --> ACCEPT
    
    TREAT -->|Reduce| MITIGATE["🛡️ Implement Controls<br/>Reduce likelihood or impact"]
    TREAT -->|Transfer| TRANSFER["🤝 Insurance/Outsource<br/>Share financial burden"]
    TREAT -->|Avoid| AVOID["🚫 Eliminate Activity<br/>Remove risk source"]
    TREAT -->|Accept| ACCEPT_HIGH["📋 Document Acceptance<br/>CEO approval required"]
    
    MITIGATE --> RESIDUAL["📉 Residual Risk<br/>Reassessment"]
    TRANSFER --> RESIDUAL
    AVOID --> RESIDUAL
    ACCEPT_HIGH --> RESIDUAL
    ACCEPT --> REGISTER["📊 Risk Register<br/>Tracking & Monitoring"]
    
    RESIDUAL --> REGISTER
    
    REGISTER --> REVIEW["🔄 Periodic Review<br/>Quarterly/Annual"]
    REVIEW --> START
    
    style START fill:#1565C0,stroke:#0D47A1,stroke-width:3px,color:#fff
    style CRITICAL fill:#D32F2F,stroke:#B71C1C,stroke-width:3px,color:#fff
    style HIGH fill:#FF9800,stroke:#F57C00,stroke-width:2px
    style MEDIUM fill:#FFC107,stroke:#FFA000,stroke-width:2px
    style LOW fill:#4CAF50,stroke:#2E7D32,stroke-width:2px,color:#fff
    style MINIMAL fill:#9E9E9E,stroke:#616161,stroke-width:1px
    style REGISTER fill:#9C27B0,stroke:#7B1FA2,stroke-width:2px,color:#fff

Likelihood Assessment Framework

Evaluate probability using descriptive categories with quantitative ranges:

LikelihoodBadgeProbabilityAnnual FrequencyARODefinitionExamples
Almost CertainImage: Almost Certain80-99%292-361 events/year0.8-0.99Expected to occur in most circumstancesDaily operational issues, routine maintenance
LikelyImage: Likely60-79%219-291 events/year0.6-0.79Will probably occurWeekly service disruptions, staff availability issues
PossibleImage: Possible40-59%146-218 events/year0.4-0.59Might occur at some timeMonthly supplier issues, seasonal variations
UnlikelyImage: Unlikely20-39%73-145 events/year0.2-0.39Could occur but not expectedQuarterly security incidents, annual contract changes
RareImage: Rare5-19%18-72 events/year0.05-0.19May occur only in exceptional circumstancesMulti-year events, rare external factors
ExceptionalImage: Exceptional<5%<18 events/year<0.05Rare, once-in-decade eventBlack swan events, extreme scenarios
Likelihood Assessment Methods

Quantitative Data (Preferred):

python
# Historical frequency analysis
def calculate_aro(events_last_3_years, trend_factor=1.0):
    """Calculate Annual Rate of Occurrence from historical data"""
    base_aro = sum(events_last_3_years) / 3
    adjusted_aro = base_aro * trend_factor
    return min(adjusted_aro, 0.99)  # Cap at 99%

# Example: 8 incidents in 3 years, increasing trend
aro = calculate_aro([2, 3, 3], trend_factor=1.2)  # = 0.32 (Unlikely)

Qualitative Assessment (When Data Limited):

  • Industry benchmarks (DBIR, ENISA Threat Landscape)
  • Expert judgment from security team
  • Peer comparison with similar organizations
  • Threat intelligence feeds

Impact Assessment Framework

Evaluate business impact across multiple dimensions:

ImpactBadgeFinancialOperationalReputationalRegulatory
CatastrophicImage: Catastrophic>€50KComplete shutdownInternational mediaCriminal charges
CriticalImage: Critical€10K-50KMajor disruptionNational mediaSignificant fines
HighImage: High€1K-10KSignificant degradationIndustry attentionModerate penalties
ModerateImage: Moderate€500-1KPartial service impactRegional visibilityMinor warnings
LowImage: Low€100-500Minor inconvenienceLimited local impactVerbal guidance
MinimalImage: Minimal<€100No significant impactNo external visibilityNo implications
Impact Score Mapping
  • Catastrophic = 6
  • Critical = 5
  • High = 4
  • Moderate = 3
  • Low = 2
  • Minimal = 1

Risk Score Calculation

Formula: Risk Score = Likelihood (midpoint %) × Impact Score (1-6) × 100

Calculation Examples

Example 1: Data Breach Risk

  • Likelihood: Unlikely (30% midpoint)
  • Impact: Critical (5)
  • Risk Score: 0.30 × 5 × 100 = 150 → 🟡 Medium Risk

Example 2: DDoS Attack Risk

  • Likelihood: Possible (50% midpoint)
  • Impact: High (4)
  • Risk Score: 0.50 × 4 × 100 = 200 → 🟠 High Risk

Example 3: Ransomware Risk

  • Likelihood: Likely (70% midpoint)
  • Impact: Catastrophic (6)
  • Risk Score: 0.70 × 6 × 100 = 420 → 🔴 Critical Risk

Risk Level Categories

Risk LevelScore RangeBadgeManagement ResponseReview Frequency
Critical400-600Image: CriticalCEO immediate action, daily monitoringDaily
High200-399Image: HighWeekly executive reviewWeekly
Medium100-199Image: MediumMonthly assessmentMonthly
Low50-99Image: LowQuarterly monitoringQuarterly
Minimal1-49Image: MinimalAcceptance, periodic reviewAnnual

Financial Risk Analysis

Single Loss Expectancy (SLE)

Formula: SLE = Asset Value × Exposure Factor

Asset Value Categories:

CategoryValue RangeExamples
Mission Critical€100K-500KCore infrastructure, customer data
High Value€50K-100KBusiness applications, intellectual property
Standard€10K-50KSupporting systems, processes
Low Value€1K-10KDocumentation, utilities

Exposure Factor Guidelines:

ExposureFactorDescription
Complete Loss0.8-1.0Total destruction (ransomware, theft)
Major Loss0.5-0.8Significant damage (data corruption)
Moderate Loss0.2-0.5Partial damage (service disruption)
Minor Loss0.1-0.2Limited impact (performance degradation)
Show full SKILL.md (350 more words)Show less
Annual Loss Expectancy (ALE)

Formula: ALE = SLE × ARO

Example Calculation:

python
# Ransomware attack on CIA Platform
asset_value = 200000  # €200K (Mission Critical)
exposure_factor = 0.9  # 90% loss (Complete Loss)
aro = 0.7  # 70% (Likely based on industry data)

sle = asset_value * exposure_factor  # €180K
ale = sle * aro  # €126K annually
Value at Risk (VaR) Framework

Formula: VaR = Impact (€) × Probability × Confidence Factor × Time Horizon

VaR Risk Categories:

CategoryVaR Range (€)Management Action
Critical>€200KBoard escalation, immediate mitigation
High€50K-200KExecutive committee, quarterly review
Medium€10K-50KRisk committee, semi-annual review
Low€1K-10KManagement monitoring, annual review
Minimal<€1KAcceptance, periodic review

Risk Treatment Decision Matrix

mermaid
graph TB
    RISK["📊 Risk Identified<br/>with Score"] --> EVAL{Risk Level?}
    
    EVAL -->|Critical/High<br/>400-600, 200-399| HIGH_TREAT["🎯 Treatment Required"]
    EVAL -->|Medium<br/>100-199| MED_TREAT["⚖️ Treatment Evaluation"]
    EVAL -->|Low/Minimal<br/>1-99| LOW_TREAT["✅ Consider Acceptance"]
    
    HIGH_TREAT --> OPTIONS1[Treatment Options]
    MED_TREAT --> OPTIONS2[Treatment Options]
    LOW_TREAT --> ACCEPT_DIRECT[Accept Risk<br/>Document in Risk Register]
    
    OPTIONS1 --> MITIGATE1["🛡️ Mitigate<br/>Implement controls"]
    OPTIONS1 --> TRANSFER1["🤝 Transfer<br/>Insurance/Outsource"]
    OPTIONS1 --> AVOID1["🚫 Avoid<br/>Eliminate activity"]
    
    OPTIONS2 --> MITIGATE2["🛡️ Mitigate<br/>Cost-benefit analysis"]
    OPTIONS2 --> ACCEPT2["📋 Accept<br/>Document rationale"]
    
    MITIGATE1 --> COST_BENEFIT{Control Cost<br/>vs ALE?}
    TRANSFER1 --> COST_BENEFIT
    MITIGATE2 --> COST_BENEFIT
    
    COST_BENEFIT -->|Control < ALE| IMPLEMENT["✅ Implement Control"]
    COST_BENEFIT -->|Control > ALE| ACCEPT_COST["📋 Accept Risk<br/>Document decision"]
    
    AVOID1 --> BUSINESS{Business<br/>Impact?}
    BUSINESS -->|Acceptable| ELIMINATE["🚫 Eliminate Risk"]
    BUSINESS -->|Unacceptable| FIND_ALT["🔄 Find Alternative"]
    
    IMPLEMENT --> RESIDUAL["📉 Residual Risk<br/>Assessment"]
    ACCEPT2 --> REGISTER["📊 Risk Register"]
    ACCEPT_COST --> REGISTER
    ACCEPT_DIRECT --> REGISTER
    ELIMINATE --> REGISTER
    
    RESIDUAL --> REEVAL{Still<br/>High/Critical?}
    REEVAL -->|Yes| ADDITIONAL[Additional Controls<br/>Required]
    REEVAL -->|No| REGISTER
    
    ADDITIONAL --> COST_BENEFIT
    
    style RISK fill:#1565C0,stroke:#0D47A1,stroke-width:3px,color:#fff
    style HIGH_TREAT fill:#D32F2F,stroke:#B71C1C,stroke-width:3px,color:#fff
    style MED_TREAT fill:#FF9800,stroke:#F57C00,stroke-width:2px
    style IMPLEMENT fill:#4CAF50,stroke:#2E7D32,stroke-width:2px,color:#fff
    style REGISTER fill:#9C27B0,stroke:#7B1FA2,stroke-width:2px,color:#fff
Cost-Benefit Analysis Formula

Control Value = ALE (Before) - ALE (After) - Control Cost

python
def control_roi(ale_before, ale_after, control_cost_annual):
    """Calculate return on investment for security control"""
    annual_benefit = ale_before - ale_after
    net_benefit = annual_benefit - control_cost_annual
    roi_percentage = (net_benefit / control_cost_annual) * 100
    return {
        'annual_benefit': annual_benefit,
        'net_benefit': net_benefit,
        'roi_percentage': roi_percentage,
        'recommendation': 'Implement' if net_benefit > 0 else 'Reject'
    }

# Example: MFA implementation
result = control_roi(
    ale_before=126000,  # €126K ransomware risk
    ale_after=12600,    # 90% reduction
    control_cost_annual=5000  # €5K/year for MFA
)
# Result: €108.4K net benefit, 2068% ROI → Implement

Risk Assessment Templates

Template 1: Comprehensive Risk Assessment
markdown
# Risk Assessment: [Risk Name]

**Risk ID:** RSK-2025-XXX
**Assessment Date:** 2025-01-XX
**Assessor:** [Name/Role]
**Status:** Open/Mitigated/Accepted/Closed

## Risk Description
Brief description of the risk scenario.

## Asset Information
- **Primary Asset:** [Asset name]
- **Asset Value:** €X
- **Classification:** [Confidentiality/Integrity/Availability levels]

## Threat & Vulnerability
- **Threat Actor:** [Who/what causes the risk]
- **Threat Motivation:** [Why would they exploit this]
- **Vulnerability:** [What weakness enables exploitation]
- **Attack Vector:** [How the attack occurs]

## Likelihood Assessment
- **Category:** [Exceptional/Rare/Unlikely/Possible/Likely/Almost Certain]
- **Probability:** X%
- **ARO:** X.XX
- **Evidence:** [Historical data, industry benchmarks, expert judgment]

## Impact Assessment
- **Financial:** €X (Category: [Minimal/Low/Moderate/High/Critical/Catastrophic])
- **Operational:** [Description]
- **Reputational:** [Description]
- **Regulatory:** [Description]
- **Impact Score:** X (1-6)

## Risk Calculation
- **Risk Score:** [Probability × Impact × 100] = XXX
- **Risk Level:** 🔴/🟠/🟡/🟢/⚪ [Critical/High/Medium/Low/Minimal]

## Financial Analysis
- **Asset Value:** €X
- **Exposure Factor:** X.X
- **SLE:** €X
- **ALE:** €X

## Current Controls
- [Existing control 1]
- [Existing control 2]

## Recommended Treatment
- **Strategy:** Mitigate/Transfer/Avoid/Accept
- **Proposed Controls:** [List controls]
- **Control Cost:** €X annually
- **Residual Risk Score:** XXX → [Risk Level]
- **Cost-Benefit:** Net benefit €X, ROI X%
- **Recommendation:** Implement/Reject

## Approval
- **Risk Owner:** [Name/Role]
- **Approval Date:** 2025-XX-XX
- **Review Date:** 2025-XX-XX
Template 2: Quick Risk Matrix
Risk IDDescriptionLikelihoodImpactScoreLevelTreatmentOwner
RSK-001Data breachUnlikely (30%)Critical (5)150🟡 MediumMFA implementationCTO
RSK-002DDoS attackPossible (50%)High (4)200🟠 HighCDN + WAFCTO
RSK-003RansomwareLikely (70%)Catastrophic (6)420🔴 CriticalBackup + EDRCEO

Integration with Classification Framework

Align risk assessments with Classification Framework:

CIA Triad Mapping

Confidentiality Impact:

  • Very High (C5) → Catastrophic financial impact
  • High (C4) → Critical financial impact
  • Moderate (C3) → High financial impact
  • Low (C2) → Moderate financial impact
  • Minimal (C1) → Low financial impact

Integrity Impact:

  • Critical (I5) → Catastrophic operational impact
  • High (I4) → Critical operational impact
  • Moderate (I3) → High operational impact
  • Low (I2) → Moderate operational impact
  • Minimal (I1) → Low operational impact

Availability Impact:

  • Mission Critical (A5) → Catastrophic business impact
  • High (A4) → Critical business impact
  • Moderate (A3) → High business impact
  • Low (A2) → Moderate business impact
  • Minimal (A1) → Low business impact

Practical Examples

Example 1: CIA Platform Ransomware Risk

Risk Assessment:

yaml
risk_id: "RSK-2025-001"
risk_name: "Ransomware attack on CIA Platform"
asset: "CIA Platform (Production)"
asset_value: 200000  # €200K

likelihood:
  category: "Likely"
  probability: 0.70
  aro: 0.70
  evidence: "Industry data (DBIR 2024), phishing susceptibility"

impact:
  financial: 180000  # €180K recovery costs
  operational: "72-hour downtime"
  reputational: "National media coverage"
  regulatory: "GDPR breach notification required"
  category: "Catastrophic"
  score: 6

risk_score: 420  # 0.70 × 6 × 100
risk_level: "Critical"

financial_analysis:
  sle: 180000  # €200K × 0.9
  ale: 126000  # €180K × 0.70

current_controls:
  - "Firewall"
  - "Antivirus"
  - "User awareness training"

proposed_treatment:
  strategy: "Mitigate"
  controls:
    - "Multi-factor authentication (MFA)"
    - "Endpoint detection and response (EDR)"
    - "Immutable backups (3-2-1 rule)"
    - "Email security gateway"
  control_cost_annual: 15000  # €15K
  residual_likelihood: 0.07  # 90% reduction
  residual_risk_score: 42  # 0.07 × 6 × 100
  residual_risk_level: "Minimal"
  
cost_benefit:
  ale_reduction: 113400  # €126K - €12.6K
  net_benefit: 98400  # €113.4K - €15K
  roi: 656  # 656% ROI
  recommendation: "IMPLEMENT IMMEDIATELY"

approval:
  risk_owner: "CEO"
  approval_date: "2025-01-25"
  next_review: "2025-04-25"
Example 2: Black Trigram No Authentication Risk

Risk Assessment:

yaml
risk_id: "RSK-2025-015"
risk_name: "No authentication system risk"
asset: "Black Trigram Gaming Platform"
asset_value: 10000  # €10K

likelihood:
  category: "Rare"
  probability: 0.12
  aro: 0.12
  evidence: "No user accounts, public content only"

impact:
  financial: 500  # €500 reputation recovery
  operational: "Minimal—frontend only"
  reputational: "Limited local impact"
  regulatory: "None—no personal data"
  category: "Low"
  score: 2

risk_score: 24  # 0.12 × 2 × 100
risk_level: "Minimal"

financial_analysis:
  sle: 5000  # €10K × 0.5 (moderate exposure)
  ale: 600  # €5K × 0.12

treatment:
  strategy: "Accept"
  rationale: "Low confidentiality classification. All content is public educational material. No user-specific operations."
  controls_considered:
    - "Authentication system: €8K/year"
    - "Cost-benefit: Negative ROI (€7.4K loss)"
  residual_risk: "Same as inherent risk"
  
risk_acceptance:
  documented_in: "Risk_Register.md"
  approved_by: "CEO"
  review_frequency: "Annual"
  trigger_conditions:
    - "Introduction of user accounts"
    - "Processing of personal data"
    - "User-generated content features"

Compliance Mapping

Risk Assessment ComponentISO 27005NIST RMFCIS Controls v8
Risk identificationClause 8.2Categorize4.1 Asset Management
Likelihood assessmentAnnex CAssess4.1 Risk Assessment
Impact assessmentAnnex CAssess4.2 Risk Analysis
Risk calculationClause 8.3Assess4.2 Risk Analysis
Risk treatmentClause 8.4Select + Implement4.3 Risk Response
Risk acceptanceClause 8.4.4Authorize4.4 Risk Approval
Monitoring & reviewClause 9Monitor4.5 Risk Monitoring

Standards & Policy References

Core Hack23 ISMS Policies:

All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/risk-assessment-methodology of Hack23/cia.

Open the folder on GitHubat commit bbed538

Compare with similar skills

Risk Assessment Methodology next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Risk Assessment Methodology compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Risk Assessment Methodology this skillHack23/cia239—~5.2kAutomated safety check: PassApache-2.0
Product Launch Legal Reviewanthropics/claude-for-legal9.6k2 repos~5kAutomated safety check: PassApache-2.0
Legal Risk Visualizationzh-xx/legal-assistant-skills173—~2.4kAutomated safety check: PassApache-2.0
Contract Renewal Trackeranthropics/claude-for-legal9.6k2 repos~3.1kAutomated safety check: PassApache-2.0
Deep Risk Analysiszubair-trabzada/ai-legal-claude1.8k—~1.9kAutomated safety check: PassNone
Canghe Tianyanchafreestylefly/canghe-skills461—~2.4kAutomated safety check: PassNone

Similar skills

  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Legal & ComplianceAuto-check passed
  • Legal Risk Visualization

    zh-xx/legal-assistant-skills

    法律风险结构化分析与可视化。基于法律分析文本,执行五步风险抽取模型, 生成四层可视化输出(雷达图数据、风险矩阵、影响路径图、决策树)。

    173 GitHub stars~2.4k tokensUpdated 5 mo ago
    Legal & ComplianceAuto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Legal & ComplianceAuto-check passed
  • Deep Risk Analysis

    zubair-trabzada/ai-legal-claude

    Clause-by-clause contract risk analysis with severity scoring, financial exposure estimates, and prioritized remediation guidance

    1.8k GitHub stars~1.9k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Canghe Tianyancha

    freestylefly/canghe-skills

    Generates Tianyancha-style company and industry insight dashboards from researched enterprise data.

    461 GitHub stars~2.4k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check passed
  • EU AI Act System Inventory

    anthropics/claude-for-legal

    Official

    Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.

    9.6k GitHub starsUsed in 3 repos~2.8k tokens
    Legal & ComplianceAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about Risk Assessment Methodology

What does Risk Assessment Methodology do?

Systematic risk identification, analysis, evaluation, and treatment aligned with ISO 27005, NIST RMF, and Hack23 ISMS risk register. Risk Assessment Methodology is an agent skill from Hack23/cia.

When should I use Risk Assessment Methodology?

Risk Assessment Methodology fits situations like: tasks that involve Legal risk assessment.

How do I install Risk Assessment Methodology in Claude Code?

Run `npx skills add Hack23/cia --skill risk-assessment-methodology -a claude-code`. Or copy the skill folder (.github/skills/risk-assessment-methodology in Hack23/cia) into .claude/skills/risk-assessment-methodology in your project. Claude Code loads it when a task matches its description.

How do I install Risk Assessment Methodology in Codex?

Run `npx skills add Hack23/cia --skill risk-assessment-methodology -a codex`. Or copy the skill folder (.github/skills/risk-assessment-methodology in Hack23/cia) into .agents/skills/risk-assessment-methodology in your project. Codex loads it when a task matches its description.

Can I use Risk Assessment Methodology in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill risk-assessment-methodology -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/risk-assessment-methodology, .gemini/skills/risk-assessment-methodology, .github/skills/risk-assessment-methodology and .opencode/skills/risk-assessment-methodology in your project.

What does Risk Assessment Methodology need to run?

SKILL.md names no scripts, command-line tools or credentials: Risk Assessment Methodology is instructions for the agent only. Our summary lists: Python 3.

Does Risk Assessment Methodology access the network?

SKILL.md names 2 domains. As links in the text: img.shields.io and github.com. This is read from the text; nothing was executed.

Is Risk Assessment Methodology safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Risk Assessment Methodology use?

Risk Assessment Methodology is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Risk Assessment Methodology use?

About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Risk Assessment Methodology?

Skills that share tags, products or a category with Risk Assessment Methodology: Product Launch Legal Review (anthropics/claude-for-legal, 9.6k stars), Legal Risk Visualization (zh-xx/legal-assistant-skills, 173 stars), Contract Renewal Tracker (anthropics/claude-for-legal, 9.6k stars) and Deep Risk Analysis (zubair-trabzada/ai-legal-claude, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Risk Assessment Methodology?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.