Agent skill

Risk Register

by mohitagw15856 in mohitagw15856/pm-claude-skills

Build and maintain a project or product risk register. An agent skill from mohitagw15856/pm-claude-skills.

MITAuto-check passedLegal & Compliance

Install Risk Register

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill risk-register -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills risk-register --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/risk-register .claude/skills/risk-register && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
risk-register
GitHub stars
1.4k
Token cost
~2.3k tokens
SKILL.md length
1,063 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Build and maintain a project or product risk register. An agent skill from mohitagw15856/pm-claude-skills.

  • Works in 7 steps: Risk Scoring Framework → Risk Register → Risk Categories — Common Risks by Type → …
  • Asked to create a risk register
  • SKILL.md covers Required Inputs, Output Structure, 1. Risk Scoring Framework and 2. Risk Register, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Risk Register is an agent skill from mohitagw15856/pm-claude-skills. Build and maintain a project or product risk register. Use when asked to create a risk register, identify project risks, build a risk matrix, or document risks and mitigations for a programme. Produces a complete risk register with likelihood/impact scoring, RAG status, ownership, and prioritised mitigations.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Legal risk assessment. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked to create a risk register
  • Identify project risks
  • Build a risk matrix
  • Document risks and mitigations for a programme

Example prompts

  • “/risk-register”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Risk Scoring Framework
  2. Risk Register
  3. Risk Categories — Common Risks by Type
  4. Risk Heat Map
  5. Top Risks — Executive Summary
  6. Risk Changes Since Last Review
  7. Risk Closure Criteria

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Risk Register loads about 2.3k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 1,063 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 1,063 words, ~2,299 tokens.

Download SKILL.mdSave it as .claude/skills/risk-register/SKILL.md (or your agent's skills folder).
name
risk-register
description
Build and maintain a project or product risk register. Use when asked to create a risk register, identify project risks, build a risk matrix, or document risks and mitigations for a programme. Produces a complete risk register with likelihood/impact scoring, RAG status, ownership, and prioritised mitigations.

Risk Register Skill

This skill produces a complete risk register for a project, programme, or product. Output follows standard risk management practice with likelihood × impact scoring, RAG status, a risk heat map, and specific mitigation and contingency plans. Ready to share with a project board, steering committee, or programme office.

Required Inputs

Ask the user for these if not provided:

  • Project or product name
  • Project stage (discovery / delivery / launch / live / programme-level)
  • Key objectives — what is the project trying to achieve?
  • Known risks — anything already on the team's radar (even informal concerns count)
  • Key dependencies — external vendors, teams, systems, or regulatory approvals
  • Deadline or milestone sensitivity — are there hard dates that cannot move?
  • Audience — who will read this? (internal team / executive steering / external board / regulator)

Output Structure


Risk Register: [Project / Product Name]

Project stage: [Discovery / Delivery / Launch / Live / Programme] Version: [1.0] Owner: [PM / Programme Manager / Risk Lead] Last reviewed: [Date] Next review: [Date — recommend weekly during delivery, monthly during discovery] Status: [Active / Archived]


1. Risk Scoring Framework

Likelihood (L)

ScoreLabelDefinition
5Almost certain>80% probability of occurring
4Likely60–80% probability
3Possible40–60% probability
2Unlikely20–40% probability
1Rare<20% probability

Impact (I)

ScoreLabelDefinition
5CriticalProgramme failure, regulatory breach, major financial loss, safety event
4HighSignificant schedule delay (>4 weeks), scope reduction, reputational damage
3MediumModerate delay (1–4 weeks), cost overrun, reduced quality
2LowMinor delay (<1 week), manageable cost increase
1NegligibleMinimal impact, easily absorbed

Risk Score = L × I

ScoreRAGAction
20–25🔴 CriticalImmediate escalation; active management required
12–19🔴 HighOwner-assigned mitigation; weekly review
8–11🟡 MediumMitigation planned; fortnightly review
4–7🟡 LowMonitor; monthly review
1–3🟢 NegligibleAccept; review if context changes

2. Risk Register

IDRiskCategoryLIScoreRAGOwnerStatusMitigationContingencyReview date
R01[Risk description — be specific: "Third-party API may not support required volume, causing X to fail"][Schedule / Technical / Resource / Commercial / Compliance / External][1–5][1–5][L×I]🔴/🟡/🟢[Name][Open / Mitigating / Closed][What are we doing to reduce likelihood or impact?][What do we do if it happens?][Date]
R02[...][...][...][...][...][...][...][...][...][...][...]

3. Risk Categories — Common Risks by Type

Use these to prompt risk identification. Add, remove, or customise for your project.

Schedule & Delivery
  • Key milestone depends on a dependency that has not confirmed availability
  • Team capacity reduced by planned or unplanned absence during critical period
  • Technical complexity is underestimated — story points consistently overrun
  • External approval (regulator, legal, procurement) takes longer than planned
Technical
  • Integration with a third-party system not yet prototyped or agreed
  • Existing technical debt makes the change harder or riskier than estimated
  • Security or compliance review required before launch has not been scoped
  • Performance under production load untested
  • Key technical knowledge held by one person (single point of failure)
Resource & People
  • Key SME or engineer leaving or unavailable during critical phase
  • Budget not confirmed for Phase 2 of the project
  • Stakeholder sponsor changes role or leaves the organisation
  • Team not yet at full capacity (hiring lag, access issues, onboarding time)
Commercial & Financial
  • Vendor or partner contract not yet signed
  • Cost estimate based on assumptions that have not been validated
  • Revenue or savings case depends on assumptions outside the team's control
  • Currency exposure or exchange rate risk for international projects
Compliance & Regulatory
  • Data privacy impact assessment (DPIA) not yet complete
  • Regulatory approval required and timeline is uncertain
  • GDPR, HIPAA, SOC 2, or sector-specific compliance requirement not yet mapped
  • Legal review of terms of service or contracts pending
Stakeholder & Adoption
  • Key user group has low awareness or motivation to adopt the change
  • Internal resistance from a team that will be affected by the change
  • Executive sponsor not consistently engaged — decisions are slow
  • Communications plan not yet agreed with change management team
External
  • Market or competitive change could undermine the business case
  • Macroeconomic conditions affect budget or priority
  • Supplier or infrastructure provider risk (e.g. cloud provider, hardware)
  • Geopolitical or regulatory environment change

Show full SKILL.md (416 more words)Show less

4. Risk Heat Map

Plot risks by likelihood (Y axis) and impact (X axis):

         │  Low     Medium    High    Critical
         │  (1)      (2-3)    (4)      (5)
─────────┼────────────────────────────────────
Almost   │  🟡        🟡       🔴       🔴
certain  │
(5)      │
─────────┼────────────────────────────────────
Likely   │  🟡        🟡       🔴       🔴
(4)      │
─────────┼────────────────────────────────────
Possible │  🟢        🟡       🟡       🔴
(3)      │
─────────┼────────────────────────────────────
Unlikely │  🟢        🟢       🟡       🟡
(2)      │
─────────┼────────────────────────────────────
Rare     │  🟢        🟢       🟢       🟡
(1)      │

[Plot each risk ID on this grid — e.g. R01 lands at L4/I5 = 🔴 Critical]


5. Top Risks — Executive Summary

For steering committee or board-level reporting:

RankRiskScoreRAGOwnerMitigation status
1[Most critical risk — plain English description][X]🔴[Owner][Active / Planned / Not started]
2[...][...]🔴[...][...]
3[...][...]🟡[...][...]
4[...][...]🟡[...][...]
5[...][...]🟡[...][...]

Decisions required from steering:

  • [Any risk that requires budget, scope, or timeline decision to mitigate]

6. Risk Changes Since Last Review

Risk IDChangeDetail
[R03]Score increased[L moved from 2 → 4 — vendor confirmed delay in API availability]
[R07]Risk closed[Legal sign-off received on 12 May]
[NEW]New risk identified[R09 — budget freeze announcement affects Phase 2 funding]

7. Risk Closure Criteria

A risk is closed when:

  • The risk event can no longer occur (e.g. milestone passed, contract signed), OR
  • The residual risk score drops to Negligible (1–3) AND the team formally accepts it, OR
  • The risk has materialised and transitioned to an issue (tracked separately)

Issues log: [Link to issues log — risks that have materialised and are now active problems being managed]


Quality Checks

  • Every risk has a specific owner — not "the team" or "TBD"
  • Mitigations describe what is actively being done — not "monitor and review"
  • Contingency plans exist for all Critical and High risks
  • Risk descriptions are specific — "vendor may be late" is not specific enough; name the vendor and the dependency
  • Register has been reviewed in the last [X] days
  • Closed risks are archived, not deleted — they provide audit trail
  • Risks are distinguished from issues — a risk is something that might happen; an issue is something that has happened

Example Trigger Phrases

  • "Build a risk register for our product launch"
  • "Create a risk matrix for [project name]"
  • "What risks should I document for a data migration project?"
  • "Generate a risk register for our steering committee"
  • "Help me identify and score risks for our Q3 delivery plan"

Anti-Patterns

  • Do not assign risks to "the team" or "TBD" — every risk must have a named individual owner
  • Do not write mitigations as "monitor and review" — mitigations must describe what is actively being done to reduce likelihood or impact
  • Do not delete closed risks — they provide an audit trail; archive them instead
  • Do not confuse risks with issues — a risk is something that might happen; an issue is something that has already happened
  • Do not leave Critical or High risks without a contingency plan — what happens if the mitigation fails must be documented

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/risk-register of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Risk Register next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Risk Register compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Risk Register this skillmohitagw15856/pm-claude-skills1.4k—~2.3kAutomated safety check: PassMIT
Product Launch Legal Reviewanthropics/claude-for-legal9.6k2 repos~5kAutomated safety check: PassApache-2.0
Legal Risk Visualizationzh-xx/legal-assistant-skills174—~2.4kAutomated safety check: PassApache-2.0
Contract Renewal Trackeranthropics/claude-for-legal9.6k2 repos~3.1kAutomated safety check: PassApache-2.0
Deep Risk Analysiszubair-trabzada/ai-legal-claude1.8k—~1.9kAutomated safety check: PassNone
Canghe Tianyanchafreestylefly/canghe-skills461—~2.4kAutomated safety check: PassNone

Similar skills

  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Legal & ComplianceAuto-check passed
  • Legal Risk Visualization

    zh-xx/legal-assistant-skills

    法律风险结构化分析与可视化。基于法律分析文本,执行五步风险抽取模型, 生成四层可视化输出(雷达图数据、风险矩阵、影响路径图、决策树)。

    174 GitHub stars~2.4k tokensUpdated 5 mo ago
    Legal & ComplianceAuto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Legal & ComplianceAuto-check passed
  • Deep Risk Analysis

    zubair-trabzada/ai-legal-claude

    Clause-by-clause contract risk analysis with severity scoring, financial exposure estimates, and prioritized remediation guidance

    1.8k GitHub stars~1.9k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Canghe Tianyancha

    freestylefly/canghe-skills

    Generates Tianyancha-style company and industry insight dashboards from researched enterprise data.

    461 GitHub stars~2.4k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check passed
  • EU AI Act System Inventory

    anthropics/claude-for-legal

    Official

    Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.

    9.6k GitHub starsUsed in 3 repos~2.8k tokens
    Legal & ComplianceAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Risk Register

What does Risk Register do?

Build and maintain a project or product risk register. An agent skill from mohitagw15856/pm-claude-skills. Risk Register is an agent skill from mohitagw15856/pm-claude-skills. Build and maintain a project or product risk register.

When should I use Risk Register?

Risk Register fits situations like: asked to create a risk register; identify project risks; build a risk matrix; document risks and mitigations for a programme.

How do I install Risk Register in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill risk-register -a claude-code`. Or copy the skill folder (skills/risk-register in mohitagw15856/pm-claude-skills) into .claude/skills/risk-register in your project. Claude Code loads it when a task matches its description.

How do I install Risk Register in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill risk-register -a codex`. Or copy the skill folder (skills/risk-register in mohitagw15856/pm-claude-skills) into .agents/skills/risk-register in your project. Codex loads it when a task matches its description.

Can I use Risk Register in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill risk-register -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/risk-register, .gemini/skills/risk-register, .github/skills/risk-register and .opencode/skills/risk-register in your project.

What does Risk Register need to run?

SKILL.md names no scripts, command-line tools or credentials: Risk Register is instructions for the agent only.

Does Risk Register access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Risk Register safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Risk Register use?

Risk Register is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Risk Register use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Risk Register?

Skills that share tags, products or a category with Risk Register: Product Launch Legal Review (anthropics/claude-for-legal, 9.6k stars), Legal Risk Visualization (zh-xx/legal-assistant-skills, 174 stars), Contract Renewal Tracker (anthropics/claude-for-legal, 9.6k stars) and Deep Risk Analysis (zubair-trabzada/ai-legal-claude, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Risk Register?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.