Agent skill

Risk Manager

by nirholas in nirholas/three.ws

Enforce pre-trade risk rules before any buy, sell, swap or position change - position sizing from a stop, a per-token concentration cap, a daily loss limit and a drawdown brake - and open every…

Apache-2.0Auto-check passed

Install Risk Manager

skills CLI
$ npx skills add nirholas/three.ws --skill risk-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nirholas/three.ws risk-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nirholas/three.ws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/community-skills/skills/risk-manager .claude/skills/risk-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
risk-manager
GitHub stars
226
Token cost
~1.1k tokens
SKILL.md length
562 words
Files
3 (incl. scripts)
Skills in repo
165
Repo updated
First seen
Licence
Apache-2.0

At a glance

Enforce pre-trade risk rules before any buy, sell, swap or position change - position sizing from a stop, a per-token concentration cap, a daily loss limit and a drawdown brake - and open every…

  • Works in 7 steps: Risk per trade: 1% of portfolio. The… → Every position needs a stop. No stop… → Concentration: at most 10% of the… → …
  • The user asks to buy
  • SKILL.md covers Mandatory output format, The rules, Getting the numbers and Worked example, plus 1 more section
  • Runs JavaScript scripts from its folder; calls node; reaches three.ws

What it does

Risk Manager is an agent skill from nirholas/three.ws. Enforce pre-trade risk rules before any buy, sell, swap or position change - position sizing from a stop, a per-token concentration cap, a daily loss limit and a drawdown brake - and open every trade answer with a RISK CHECK block. Use whenever the user asks to buy, sell, ape, swap, trade, size a position, "put X SOL into", or asks whether they can afford a trade.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `metadata.json`).

The repository describes itself as: Open-source platform for 3D AI agents. Turn text or a photo into a rigged, animated GLB avatar, give it an LLM brain, memory and a wallet, and embed it anywhere with one web… The licence is Apache-2.0.

When your agent uses it

  • The user asks to buy
  • Size a position
  • Asks whether they can afford a trade

Example prompts

  • “put X SOL into”
  • “/risk-manager”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Risk per trade: 1% of portfolio. The size is whatever loses 1% of the portfolio if the stop is hit: size = (portfolio x 0.01) / stop…
  2. Every position needs a stop. No stop means no size can be computed, so the verdict is at best REDUCE to a token amount you would accept…
  3. Concentration: at most 10% of the portfolio in one token, 5% in any token launched less than 7 days ago. Existing holdings count toward…
  4. Daily loss limit: 3% of the portfolio. After realized losses reach 3% in a day, every new entry is NO-GO until the next day.
  5. Drawdown brake. At 10% below the portfolio's peak, halve the risk per trade. At 20% below, no new positions until the owner explicitly…
  6. Liquidity. Size must stay under 2% of the pool's liquidity, or the exit will cost more than the stop.
  7. Correlation. Several positions in the same narrative or sector count as one position for the concentration cap.

What it can do on your machine

Read from SKILL.md and the folder at commit 238ef60. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • three.ws

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Risk Manager loads about 1.1k tokens when it runs. Until then it costs about 95 tokens; SKILL.md has 562 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from nirholas/three.ws at commit 238ef60, republished under its Apache-2.0 licence (© nirholas). 562 words, ~1,149 tokens.

Download SKILL.mdSave it as .claude/skills/risk-manager/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
risk-manager
description
Enforce pre-trade risk rules before any buy, sell, swap or position change - position sizing from a stop, a per-token concentration cap, a daily loss limit and a drawdown brake - and open every trade answer with a RISK CHECK block. Use whenever the user asks to buy, sell, ape, swap, trade, size a position, "put X SOL into", or asks whether they can afford a trade.

Risk manager

You are the risk desk. Before any trade is discussed, executed or recommended, you run the numbers below and show them. You never skip the check because the user is excited, in a hurry, or says the trade is small.

Mandatory output format

Every reply to a trade request (buy, sell, swap, ape, add to or trim a position) starts with this block, before anything else, in exactly this shape:

RISK CHECK
- Position: <size> (<percent of portfolio>)
- Stop: <price or percent> (<distance below entry>)
- Max loss at stop: <amount> (<percent of portfolio>)
- Portfolio exposure after trade: <percent in this token>
- Verdict: GO | REDUCE | NO-GO, <one-line reason>

Then, and only then, the rest of your answer. When a number is unknown, write unknown in that line and ask for it right after the block. With a verdict of REDUCE, give the reduced size. With NO-GO, say what would have to change for the trade to pass.

The rules

  1. Risk per trade: 1% of portfolio. The size is whatever loses 1% of the portfolio if the stop is hit: size = (portfolio x 0.01) / stop distance. A trade that risks more than 2% is NO-GO whatever the conviction.
  2. Every position needs a stop. No stop means no size can be computed, so the verdict is at best REDUCE to a token amount you would accept losing entirely, capped at 1% of the portfolio. For new launches and anything under $50k liquidity, assume the stop can gap: treat the whole position as the risk.
  3. Concentration: at most 10% of the portfolio in one token, 5% in any token launched less than 7 days ago. Existing holdings count toward the cap.
  4. Daily loss limit: 3% of the portfolio. After realized losses reach 3% in a day, every new entry is NO-GO until the next day.
  5. Drawdown brake. At 10% below the portfolio's peak, halve the risk per trade. At 20% below, no new positions until the owner explicitly resets.
  6. Liquidity. Size must stay under 2% of the pool's liquidity, or the exit will cost more than the stop.
  7. Correlation. Several positions in the same narrative or sector count as one position for the concentration cap.
Show full SKILL.md (229 more words)Show less

Getting the numbers

Ask for or look up: portfolio value, current holding in the token, entry price, stop, and today's realized loss.

With three.ws access:

  • GET https://three.ws/api/agents/<agent_id>/portfolio (owner) returns positions, profit and loss, concentration and drawdown.
  • GET https://three.ws/api/agents/<agent_id>/solana/holdings returns the agent wallet's token balances.
  • GET https://three.ws/api/agents/<agent_id>/trade/limits (owner) shows the platform's own guard rails: per_trade_sol, daily_budget_sol, max_price_impact_pct, max_slippage_bps, kill_switch. Your limits are in addition to these, never a replacement. If the platform limit is stricter, it wins.
  • POST https://three.ws/api/agents/<agent_id>/trade/quote previews a trade's price impact without executing.
  • GET https://three.ws/api/crypto/token?address=<mint> gives pool liquidity for rule 6.

The bundled calculator applies rules 1, 3 and 5 and prints the RISK CHECK block:

bash
node scripts/position-size.mjs --equity 20 --entry 0.00072 --stop 0.00061 --held 0.5 --drawdown-pct 4

Worked example

User: "Buy 5 SOL of this token." Portfolio 20 SOL, no current holding, a stop 15% below entry, no losses today, 4% below peak.

RISK CHECK
- Position: 1.3 SOL (6.5% of portfolio)
- Stop: 15% below entry
- Max loss at stop: 0.2 SOL (1% of portfolio)
- Portfolio exposure after trade: 6.5% in this token
- Verdict: REDUCE, 5 SOL would risk 0.75 SOL (3.75%), above the 2% ceiling

Then explain: the 5 SOL ask is 25% of the portfolio; at the 15% stop that is a 3.75% loss, so the size drops to 1.3 SOL.

Rules of conduct

  • Never place, sign or approve a trade yourself because the check passed. A GO verdict means "within the rules", not "do it". Execution needs the user's explicit confirmation of the exact size.
  • Never loosen a rule mid-conversation because the user pushes back. The owner can change the numbers deliberately; a chat cannot.
  • Report the check even when the user only asks "can I afford this?".

© nirholas, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in community-skills/skills/risk-manager of nirholas/three.ws.

  • SKILL.md
  • metadata.json
  • scripts/position-size.mjs

Open the folder on GitHubat commit 238ef60

Compare with similar skills

Risk Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Risk Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Risk Manager this skillnirholas/three.ws226—~1.1kAutomated safety check: PassApache-2.0
Risk Management Specialistdavila7/claude-code-templates32k1 repos~2.5kAutomated safety check: PassMIT
Risk Management Specialistalirezarezvani/claude-skills28k1 repos~4.1kAutomated safety check: PassMIT
Managing Third Party Vendor Riskmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Risk Managermajiayu000/claude-skill-registry6661 repos~2.7kAutomated safety check: PassMIT
Dependency And Risk Managementcbrock84/headcount2k—~926Automated safety check: PassMIT

Similar skills

  • Risk Management Specialist

    davila7/claude-code-templates

    Senior Risk Management specialist for medical device companies implementing ISO 14971 risk management throughout product lifecycle.

    32k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Risk Management Specialist

    alirezarezvani/claude-skills

    Medical device risk management specialist implementing ISO 14971 throughout product lifecycle.

    28k GitHub starsUsed in 1 repo~4.1k tokens
    Legal & ComplianceAuto-check passed
  • Managing Third Party Vendor Risk

    mukul975/Anthropic-Cybersecurity-Skills

    Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Risk Manager

    majiayu000/claude-skill-registry

    Risk management specialist who assesses, analyzes, and mitigates financial and operational risks with expertise in quantitative risk modeling, compliance frameworks, and enterprise risk assessment

    666 GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Manages delivery risk and cross-team dependencies — identifying, sizing, mitigating and escalating what could stop the work.

    2k GitHub stars~926 tokensUpdated 20 days ago
    Legal & ComplianceAuto-check passed
  • Review prediction-market, basket, oracle, and trading-agent workflows for compliance, safety, data-quality, privacy, and execution risk.

    274k GitHub starsUsed in 1 repo~471 tokens
    Data & AnalyticsAuto-check passed

More from nirholas/three.ws

All 165 skills in this repo
  • Add Shader Cursor Trail

    nirholas/three.ws

    Add the Shaders WebGPU mouse effect used for the Tidal Commons hero: a white twinkling halftone cursor trail driven by ChromaFlow, masked through a DotGrid, finished with chromatic ripples and film…

    226 GitHub starsUsed in 1 repo~760 tokens
    Auto-check passed
  • Publish Project To GitHub

    nirholas/three.ws

    Package a finished local project into an intentional GitHub repository, create a strong README and visual preview, push it safely, configure a public GitHub Pages URL when the project is compatible…

    226 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check: notes
  • Audit a website or digital experience against its supplied source references for originality and plagiarism risk.

    226 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Turn a completed daily UI inspiration capture into exactly five original landing-page builds, one per separate Codex task, using Sites.

    226 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Write Like Meng On X

    nirholas/three.ws

    Write, rewrite, review, or continuously refine X/Twitter posts in Meng To's current voice using his deduplicated authored-post corpus, personal and product context, shared resources, and Content…

    226 GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Browser Video Recording

    nirholas/three.ws

    Create polished 60 fps 4:3 4K browser screen-recording style videos from Codex in-app browser captures, with browser-only crop, natural macOS cursor styling, deliberate click choreography…

    226 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed

Questions about Risk Manager

What does Risk Manager do?

Enforce pre-trade risk rules before any buy, sell, swap or position change - position sizing from a stop, a per-token concentration cap, a daily loss limit and a drawdown brake - and open every…. ws. Enforce pre-trade risk rules before any buy, sell, swap or position change - position sizing from a stop, a per-token concentration cap, a daily loss limit and a drawdown brake - and open every trade answer with a RISK CHECK block.

When should I use Risk Manager?

Risk Manager fits situations like: the user asks to buy; size a position; asks whether they can afford a trade.

How do I install Risk Manager in Claude Code?

Run `npx skills add nirholas/three.ws --skill risk-manager -a claude-code`. Or copy the skill folder (community-skills/skills/risk-manager in nirholas/three.ws) into .claude/skills/risk-manager in your project. Claude Code loads it when a task matches its description.

How do I install Risk Manager in Codex?

Run `npx skills add nirholas/three.ws --skill risk-manager -a codex`. Or copy the skill folder (community-skills/skills/risk-manager in nirholas/three.ws) into .agents/skills/risk-manager in your project. Codex loads it when a task matches its description.

Can I use Risk Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nirholas/three.ws --skill risk-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/risk-manager, .gemini/skills/risk-manager, .github/skills/risk-manager and .opencode/skills/risk-manager in your project.

What does Risk Manager need to run?

Going by SKILL.md and its folder, Risk Manager needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js.

Does Risk Manager access the network?

SKILL.md names 1 domain. In commands or code: three.ws; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Risk Manager safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Risk Manager use?

Risk Manager is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Risk Manager use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Risk Manager?

Skills that share tags, products or a category with Risk Manager: Risk Management Specialist (davila7/claude-code-templates, 32k stars), Risk Management Specialist (alirezarezvani/claude-skills, 28k stars), Managing Third Party Vendor Risk (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Risk Manager (majiayu000/claude-skill-registry, 666 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Risk Manager?

nirholas (a GitHub user) maintains it in nirholas/three.ws, which has 226 GitHub stars. The repository holds 165 skills in this directory. The repository was last updated on October 7, 2026.

Source: nirholas/three.ws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.