Agent skill

Legal Risk Assessment

by rongxinzy in rongxinzy/RongxinAI

Assess and classify legal risks using a severity-by-likelihood framework with escalation criteria.

Apache-2.0Auto-check passedLegal & Compliance

Install Legal Risk Assessment

skills CLI
$ npx skills add rongxinzy/RongxinAI --skill legal-risk-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rongxinzy/RongxinAI legal-risk-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rongxinzy/RongxinAI.git skills-src && mkdir -p .claude/skills && cp -r skills-src/SKILLs/legal-risk-assessment .claude/skills/legal-risk-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
legal-risk-assessment
GitHub stars
154
Used in
2 other repos
Token cost
~3.1k tokens
SKILL.md length
1,232 words
Files
4
Skills in repo
94
Repo updated
First seen
Licence
Apache-2.0

At a glance

Assess and classify legal risks using a severity-by-likelihood framework with escalation criteria.

  • Evaluating contract risk
  • SKILL.md covers Risk Assessment Framework, Risk Classification Levels…, Documentation Standards for… and When to Escalate to Outside…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Assessing deal exposure

What it does

Legal Risk Assessment is an agent skill from rongxinzy/RongxinAI. Assess and classify legal risks using a severity-by-likelihood framework with escalation criteria. Use when evaluating contract risk, assessing deal exposure, classifying issues by severity, or determining whether a matter needs senior counsel or outside legal review.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `zhiyuan/metadata.yaml`).

It sits in Legal & Compliance, covering Legal risk assessment. The repository describes itself as: An all-in-one local AI Agent workspace with a fully self-developed stack. The licence is Apache-2.0.

When your agent uses it

  • Evaluating contract risk
  • Assessing deal exposure
  • Classifying issues by severity
  • Determining whether a matter needs senior counsel

Example prompts

  • “/legal-risk-assessment”

What it can do on your machine

Read from SKILL.md and the folder at commit 9c64865. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Legal Risk Assessment loads about 3.1k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 1,232 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rongxinzy/RongxinAI at commit 9c64865, republished under its Apache-2.0 licence (© rongxinzy). 1,232 words, ~3,146 tokens.

Download SKILL.mdSave it as .claude/skills/legal-risk-assessment/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
legal-risk-assessment
description
Assess and classify legal risks using a severity-by-likelihood framework with escalation criteria. Use when evaluating contract risk, assessing deal exposure, classifying issues by severity, or determining whether a matter needs senior counsel or outside legal review.

You are a legal risk assessment assistant for an in-house legal team. You help evaluate, classify, and document legal risks using a structured framework based on severity and likelihood.

Important: You assist with legal workflows but do not provide legal advice. Risk assessments should be reviewed by qualified legal professionals. The framework provided is a starting point that organizations should customize to their specific risk appetite and industry context.

Risk Assessment Framework

Severity x Likelihood Matrix

Legal risks are assessed on two dimensions:

Severity (impact if the risk materializes):

LevelLabelDescription
1NegligibleMinor inconvenience; no material financial, operational, or reputational impact. Can be handled within normal operations.
2LowLimited impact; minor financial exposure (< 1% of relevant contract/deal value); minor operational disruption; no public attention.
3ModerateMeaningful impact; material financial exposure (1-5% of relevant value); noticeable operational disruption; potential for limited public attention.
4HighSignificant impact; substantial financial exposure (5-25% of relevant value); significant operational disruption; likely public attention; potential regulatory scrutiny.
5CriticalSevere impact; major financial exposure (> 25% of relevant value); fundamental business disruption; significant reputational damage; regulatory action likely; potential personal liability for officers/directors.

Likelihood (probability the risk materializes):

LevelLabelDescription
1RemoteHighly unlikely to occur; no known precedent in similar situations; would require exceptional circumstances.
2UnlikelyCould occur but not expected; limited precedent; would require specific triggering events.
3PossibleMay occur; some precedent exists; triggering events are foreseeable.
4LikelyProbably will occur; clear precedent; triggering events are common in similar situations.
5Almost CertainExpected to occur; strong precedent or pattern; triggering events are present or imminent.
Risk Score Calculation

Risk Score = Severity x Likelihood

Score RangeRisk LevelColor
1-4Low RiskGREEN
5-9Medium RiskYELLOW
10-15High RiskORANGE
16-25Critical RiskRED
Risk Matrix Visualization
                    LIKELIHOOD
                Remote  Unlikely  Possible  Likely  Almost Certain
                  (1)     (2)       (3)      (4)        (5)
SEVERITY
Critical (5)  |   5    |   10   |   15   |   20   |     25     |
High     (4)  |   4    |    8   |   12   |   16   |     20     |
Moderate (3)  |   3    |    6   |    9   |   12   |     15     |
Low      (2)  |   2    |    4   |    6   |    8   |     10     |
Negligible(1) |   1    |    2   |    3   |    4   |      5     |
GREEN -- Low Risk (Score 1-4)

Characteristics:

  • Minor issues that are unlikely to materialize
  • Standard business risks within normal operating parameters
  • Well-understood risks with established mitigations in place

Recommended Actions:

  • Accept: Acknowledge the risk and proceed with standard controls
  • Document: Record in the risk register for tracking
  • Monitor: Include in periodic reviews (quarterly or annually)
  • No escalation required: Can be managed by the responsible team member

Examples:

  • Vendor contract with minor deviation from standard terms in a non-critical area
  • Routine NDA with a well-known counterparty in a standard jurisdiction
  • Minor administrative compliance task with clear deadline and owner
YELLOW -- Medium Risk (Score 5-9)

Characteristics:

  • Moderate issues that could materialize under foreseeable circumstances
  • Risks that warrant attention but do not require immediate action
  • Issues with established precedent for management

Recommended Actions:

  • Mitigate: Implement specific controls or negotiate to reduce exposure
  • Monitor actively: Review at regular intervals (monthly or as triggers occur)
  • Document thoroughly: Record risk, mitigations, and rationale in risk register
  • Assign owner: Ensure a specific person is responsible for monitoring and mitigation
  • Brief stakeholders: Inform relevant business stakeholders of the risk and mitigation plan
  • Escalate if conditions change: Define trigger events that would elevate the risk level

Examples:

  • Contract with liability cap below standard but within negotiable range
  • Vendor processing personal data in a jurisdiction without clear adequacy determination
  • Regulatory development that may affect a business activity in the medium term
  • IP provision that is broader than preferred but common in the market
ORANGE -- High Risk (Score 10-15)

Characteristics:

  • Significant issues with meaningful probability of materializing
  • Risks that could result in substantial financial, operational, or reputational impact
  • Issues that require senior attention and dedicated mitigation efforts

Recommended Actions:

  • Escalate to senior counsel: Brief the head of legal or designated senior counsel
  • Develop mitigation plan: Create a specific, actionable plan to reduce the risk
  • Brief leadership: Inform relevant business leaders of the risk and recommended approach
  • Set review cadence: Review weekly or at defined milestones
  • Consider outside counsel: Engage outside counsel for specialized advice if needed
  • Document in detail: Full risk memo with analysis, options, and recommendations
  • Define contingency plan: What will the organization do if the risk materializes?

Examples:

  • Contract with uncapped indemnification in a material area
  • Data processing activity that may violate a regulatory requirement if not restructured
  • Threatened litigation from a significant counterparty
  • IP infringement allegation with colorable basis
  • Regulatory inquiry or audit request
Show full SKILL.md (525 more words)Show less
RED -- Critical Risk (Score 16-25)

Characteristics:

  • Severe issues that are likely or certain to materialize
  • Risks that could fundamentally impact the business, its officers, or its stakeholders
  • Issues requiring immediate executive attention and rapid response

Recommended Actions:

  • Immediate escalation: Brief General Counsel, C-suite, and/or Board as appropriate
  • Engage outside counsel: Retain specialized outside counsel immediately
  • Establish response team: Dedicated team to manage the risk with clear roles
  • Consider insurance notification: Notify insurers if applicable
  • Crisis management: Activate crisis management protocols if reputational risk is involved
  • Preserve evidence: Implement litigation hold if legal proceedings are possible
  • Daily or more frequent review: Active management until the risk is resolved or reduced
  • Board reporting: Include in board risk reporting as appropriate
  • Regulatory notifications: Make any required regulatory notifications

Examples:

  • Active litigation with significant exposure
  • Data breach affecting regulated personal data
  • Regulatory enforcement action
  • Material contract breach by or against the organization
  • Government investigation
  • Credible IP infringement claim against a core product or service

Documentation Standards for Risk Assessments

Risk Assessment Memo Format

Every formal risk assessment should be documented using the following structure:

## Legal Risk Assessment

**Date**: [assessment date]
**Assessor**: [person conducting assessment]
**Matter**: [description of the matter being assessed]
**Privileged**: [Yes/No - mark as attorney-client privileged if applicable]

### 1. Risk Description
[Clear, concise description of the legal risk]

### 2. Background and Context
[Relevant facts, history, and business context]

### 3. Risk Analysis

#### Severity Assessment: [1-5] - [Label]
[Rationale for severity rating, including potential financial exposure, operational impact, and reputational considerations]

#### Likelihood Assessment: [1-5] - [Label]
[Rationale for likelihood rating, including precedent, triggering events, and current conditions]

#### Risk Score: [Score] - [GREEN/YELLOW/ORANGE/RED]

### 4. Contributing Factors
[What factors increase the risk]

### 5. Mitigating Factors
[What factors decrease the risk or limit exposure]

### 6. Mitigation Options

| Option | Effectiveness | Cost/Effort | Recommended? |
|---|---|---|---|
| [Option 1] | [High/Med/Low] | [High/Med/Low] | [Yes/No] |
| [Option 2] | [High/Med/Low] | [High/Med/Low] | [Yes/No] |

### 7. Recommended Approach
[Specific recommended course of action with rationale]

### 8. Residual Risk
[Expected risk level after implementing recommended mitigations]

### 9. Monitoring Plan
[How and how often the risk will be monitored; trigger events for re-assessment]

### 10. Next Steps
1. [Action item 1 - Owner - Deadline]
2. [Action item 2 - Owner - Deadline]
Risk Register Entry

For tracking in the team's risk register:

FieldContent
Risk IDUnique identifier
Date IdentifiedWhen the risk was first identified
DescriptionBrief description
CategoryContract, Regulatory, Litigation, IP, Data Privacy, Employment, Corporate, Other
Severity1-5 with label
Likelihood1-5 with label
Risk ScoreCalculated score
Risk LevelGREEN / YELLOW / ORANGE / RED
OwnerPerson responsible for monitoring
MitigationsCurrent controls in place
StatusOpen / Mitigated / Accepted / Closed
Review DateNext scheduled review
NotesAdditional context

When to Escalate to Outside Counsel

Engage outside counsel when:

Mandatory Engagement
  • Active litigation: Any lawsuit filed against or by the organization
  • Government investigation: Any inquiry from a government agency, regulator, or law enforcement
  • Criminal exposure: Any matter with potential criminal liability for the organization or its personnel
  • Securities issues: Any matter that could affect securities disclosures or filings
  • Board-level matters: Any matter requiring board notification or approval
  • Novel legal issues: Questions of first impression or unsettled law where the organization's position could set precedent
  • Jurisdictional complexity: Matters involving unfamiliar jurisdictions or conflicting legal requirements across jurisdictions
  • Material financial exposure: Risks with potential exposure exceeding the organization's risk tolerance thresholds
  • Specialized expertise needed: Matters requiring deep domain expertise not available in-house (antitrust, FCPA, patent prosecution, etc.)
  • Regulatory changes: New regulations that materially affect the business and require compliance program development
  • M&A transactions: Due diligence, deal structuring, and regulatory approvals for significant transactions
Consider Engagement
  • Complex contract disputes: Significant disagreements over contract interpretation with material counterparties
  • Employment matters: Claims or potential claims involving discrimination, harassment, wrongful termination, or whistleblower protections
  • Data incidents: Potential data breaches that may trigger notification obligations
  • IP disputes: Infringement allegations (received or contemplated) involving material products or services
  • Insurance coverage disputes: Disagreements with insurers over coverage for material claims
Selecting Outside Counsel

When recommending outside counsel engagement, suggest the user consider:

  • Relevant subject matter expertise
  • Experience in the applicable jurisdiction
  • Understanding of the organization's industry
  • Conflict of interest clearance
  • Budget expectations and fee arrangements (hourly, fixed fee, blended rates, success fees)
  • Diversity and inclusion considerations
  • Existing relationships (panel firms, prior engagements)

© rongxinzy, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in SKILLs/legal-risk-assessment of rongxinzy/RongxinAI.

  • SKILL.md
  • LICENSE.txt
  • zhiyuan/icon.png
  • zhiyuan/metadata.yaml

Open the folder on GitHubat commit 9c64865

Used in 2 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in rongxinzy/RongxinAI, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Legal Risk Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Legal Risk Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Legal Risk Assessment this skillrongxinzy/RongxinAI1542 repos~3.1kAutomated safety check: PassApache-2.0
Product Launch Legal Reviewanthropics/claude-for-legal9.6k2 repos~5kAutomated safety check: PassApache-2.0
Legal Risk Visualizationzh-xx/legal-assistant-skills174—~2.4kAutomated safety check: PassApache-2.0
Contract Renewal Trackeranthropics/claude-for-legal9.6k2 repos~3.1kAutomated safety check: PassApache-2.0
Deep Risk Analysiszubair-trabzada/ai-legal-claude1.8k—~1.9kAutomated safety check: PassNone
Canghe Tianyanchafreestylefly/canghe-skills461—~2.4kAutomated safety check: PassNone

Similar skills

  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Legal & ComplianceAuto-check passed
  • Legal Risk Visualization

    zh-xx/legal-assistant-skills

    法律风险结构化分析与可视化。基于法律分析文本,执行五步风险抽取模型, 生成四层可视化输出(雷达图数据、风险矩阵、影响路径图、决策树)。

    174 GitHub stars~2.4k tokensUpdated 5 mo ago
    Legal & ComplianceAuto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Legal & ComplianceAuto-check passed
  • Deep Risk Analysis

    zubair-trabzada/ai-legal-claude

    Clause-by-clause contract risk analysis with severity scoring, financial exposure estimates, and prioritized remediation guidance

    1.8k GitHub stars~1.9k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Canghe Tianyancha

    freestylefly/canghe-skills

    Generates Tianyancha-style company and industry insight dashboards from researched enterprise data.

    461 GitHub stars~2.4k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check passed
  • EU AI Act System Inventory

    anthropics/claude-for-legal

    Official

    Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.

    9.6k GitHub starsUsed in 3 repos~2.8k tokens
    Legal & ComplianceAuto-check passed

More from rongxinzy/RongxinAI

All 94 skills in this repo
  • SaaS Metrics Coach

    rongxinzy/RongxinAI

    SaaS financial health advisor. An agent skill from rongxinzy/RongxinAI.

    154 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Churn Prevention

    rongxinzy/RongxinAI

    Reduce voluntary and involuntary churn through cancel flow design, save offers, exit surveys, and dunning sequences.

    154 GitHub starsUsed in 3 repos~2.6k tokens
    Auto-check passed
  • Presentation Studio

    rongxinzy/RongxinAI

    The only skill for creating a new PowerPoint deck. An agent skill from rongxinzy/RongxinAI.

    154 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Zhiyuan Expert Manager

    rongxinzy/RongxinAI

    ZhiYuan Agent expert package lifecycle manager for the pi engine.

    154 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Ziwei Doushu

    rongxinzy/RongxinAI

    Professional Ziwei Doushu consultation skill with an offline calculation engine.

    154 GitHub stars~746 tokensUpdated yesterday
    Auto-check passed
  • Lark Mail

    rongxinzy/RongxinAI

    飞书邮箱:Use when user mentions 起草邮件、写邮件、草稿、发送/回复/转发邮件、查阅邮件、看邮件、搜索邮件、邮件文件夹、邮件标签、邮件联系人、监听新邮件、邮件收信规则等;use for mail/email intent only.

    154 GitHub starsUsed in 3 repos~4.1k tokens
    Auto-check: warnings

Questions about Legal Risk Assessment

What does Legal Risk Assessment do?

Assess and classify legal risks using a severity-by-likelihood framework with escalation criteria. Legal Risk Assessment is an agent skill from rongxinzy/RongxinAI. Assess and classify legal risks using a severity-by-likelihood framework with escalation criteria.

When should I use Legal Risk Assessment?

Legal Risk Assessment fits situations like: evaluating contract risk; assessing deal exposure; classifying issues by severity; determining whether a matter needs senior counsel.

How do I install Legal Risk Assessment in Claude Code?

Run `npx skills add rongxinzy/RongxinAI --skill legal-risk-assessment -a claude-code`. Or copy the skill folder (SKILLs/legal-risk-assessment in rongxinzy/RongxinAI) into .claude/skills/legal-risk-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Legal Risk Assessment in Codex?

Run `npx skills add rongxinzy/RongxinAI --skill legal-risk-assessment -a codex`. Or copy the skill folder (SKILLs/legal-risk-assessment in rongxinzy/RongxinAI) into .agents/skills/legal-risk-assessment in your project. Codex loads it when a task matches its description.

Can I use Legal Risk Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rongxinzy/RongxinAI --skill legal-risk-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/legal-risk-assessment, .gemini/skills/legal-risk-assessment, .github/skills/legal-risk-assessment and .opencode/skills/legal-risk-assessment in your project.

What does Legal Risk Assessment need to run?

SKILL.md names no scripts, command-line tools or credentials: Legal Risk Assessment is instructions for the agent only.

Does Legal Risk Assessment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Legal Risk Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Legal Risk Assessment use?

Legal Risk Assessment is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Legal Risk Assessment use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Legal Risk Assessment?

Skills that share tags, products or a category with Legal Risk Assessment: Product Launch Legal Review (anthropics/claude-for-legal, 9.6k stars), Legal Risk Visualization (zh-xx/legal-assistant-skills, 174 stars), Contract Renewal Tracker (anthropics/claude-for-legal, 9.6k stars) and Deep Risk Analysis (zubair-trabzada/ai-legal-claude, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Legal Risk Assessment?

rongxinzy (a GitHub organization) maintains it in rongxinzy/RongxinAI, which has 154 GitHub stars. The repository holds 94 skills in this directory. The repository was last updated on October 10, 2026.

Source: rongxinzy/RongxinAI on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.