Agent skill

Risk Assess

by sd0xdev in sd0xdev/sd0x-harness

Uncommitted code risk assessment with breaking change detection, blast radius analysis, and scope metrics.

MITAuto-check passedDevelopment

Install Risk Assess

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill risk-assess -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness risk-assess --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/risk-assess .claude/skills/risk-assess && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
risk-assess
GitHub stars
192
Token cost
~834 tokens
SKILL.md length
285 words
Files
4 (incl. scripts, references)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Uncommitted code risk assessment with breaking change detection, blast radius analysis, and scope metrics.

  • Works in 7 steps: Run bash scripts/run-skill.sh… → Parse the JSON output — overall_score,… → If risk_level = Critical (score 75-100)… → …
  • : evaluating PR risk
  • SKILL.md covers When NOT to Use, Procedure, Script Integration and Output Format, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls bash

What it does

Risk Assess is an agent skill from sd0xdev/sd0x-harness. Uncommitted code risk assessment with breaking change detection, blast radius analysis, and scope metrics. Use when: evaluating PR risk, pre-commit risk check, large refactoring review. Not for: security vulnerabilities (use /codex-security), code correctness (use /codex-review-fast). Output: 3-dimension weighted score + risk level + gate.

Its SKILL.md is about 830 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/output-template.md`, `references/risk-dimensions.md` and `scripts/risk-analyze.js`).

It sits in Development, covering Anomaly detection and Refactoring. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • : evaluating PR risk
  • Pre-commit risk check
  • Large refactoring review

Example prompts

  • “/risk-assess”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Run bash scripts/run-skill.sh risk-assess risk-analyze.js --json to collect deterministic scores
  2. Parse the JSON output — overall_score, risk_level, dimensions, flags, gate, next_actions
  3. If risk_level = Critical (score 75-100) — highlight all breaking signals, recommend splitting PRs
  4. If risk_level = High (score 50-74) — auto-escalate to --mode deep, detail blast radius
  5. If risk_level = Medium (score 30-49) — summarize dimensions, note areas of concern
  6. If risk_level = Low (score 0-29) — brief summary, confirm safe to proceed
  7. Add qualitative interpretation beyond the scores (e.g., "high blast radius but all dependents are test files")

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Risk Assess loads about 834 tokens when it runs, and up to ~2k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 285 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~834
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 285 words, ~834 tokens.

Download SKILL.mdSave it as .claude/skills/risk-assess/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
risk-assess
description
Uncommitted code risk assessment with breaking change detection, blast radius analysis, and scope metrics. Use when: evaluating PR risk, pre-commit risk check, large refactoring review. Not for: security vulnerabilities (use /codex-security), code correctness (use /codex-review-fast). Output: 3-dimension weighted score + risk level + gate.

Risk Assessment

When NOT to Use

  • Security vulnerability detection (use /codex-security)
  • Code correctness / lint / test review (use /codex-review-fast)
  • Project-level health audit (use /project-audit)

Procedure

  1. Run bash scripts/run-skill.sh risk-assess risk-analyze.js --json to collect deterministic scores
  2. Parse the JSON output — overall_score, risk_level, dimensions, flags, gate, next_actions
  3. If risk_level = Critical (score 75-100) — highlight all breaking signals, recommend splitting PRs
  4. If risk_level = High (score 50-74) — auto-escalate to --mode deep, detail blast radius
  5. If risk_level = Medium (score 30-49) — summarize dimensions, note areas of concern
  6. If risk_level = Low (score 0-29) — brief summary, confirm safe to proceed
  7. Add qualitative interpretation beyond the scores (e.g., "high blast radius but all dependents are test files")

Script Integration

The script analyzes 3 dimensions + 2 conditional flags:

DimensionWeightWhat It Measures
breaking_surface45%Removed exports, renamed APIs, changed signatures, deleted modules
blast_radius35%Number of files importing changed modules (grep-based)
change_scope20%File count, LOC delta, directory span, rename ratio
FlagTriggerWhat It Checks
migration_safetyMigration/schema files in diffRollback/down file exists
regression_hint(v2 stub)Future: git history analysis
Scoring Model
  • Overall: breaking_surface * 0.45 + blast_radius * 0.35 + change_scope * 0.20
  • Each dimension: 0-100 scale
  • Overall: 0-100 scale
Risk Levels
ScoreLevelGateExit Code
0-29LowPASS0
30-49MediumPASS0
50-74HighREVIEW1
75-100CriticalBLOCK2
Script Failure Fallback

If the script fails, report the error and suggest running manually:

bash
bash scripts/run-skill.sh risk-assess risk-analyze.js --json

Output Format

## Risk Assessment Report

| Field | Value |
|-------|-------|
| Score | **[N]/100** |
| Risk Level | [icon] [level] |
| Gate | [PASS/REVIEW/BLOCK] |

### Dimensions
[table of dimension scores + weights]

### Breaking Change Signals
[list of detected signals — only if any]

### Next Actions
[prioritized action items]

## Gate: [sentinel]

References

  • references/risk-dimensions.md — Signal catalog, import patterns, scoring bands (read when investigating a specific dimension)
  • references/output-template.md — JSON schema, report templates per risk level (read when customizing output)

Verification

  • Script ran successfully
  • All 3 dimensions scored
  • Qualitative interpretation added beyond raw scores
  • Next actions are actionable (include commands where applicable)
  • Gate sentinel present in output

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/risk-assess of sd0xdev/sd0x-harness.

  • SKILL.md
  • references/output-template.md
  • references/risk-dimensions.md
  • scripts/risk-analyze.js

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Risk Assess next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Risk Assess compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Risk Assess this skillsd0xdev/sd0x-harness192—~834Automated safety check: PassMIT
Angularkid-sid/claude-spellbook189—~5kAutomated safety check: PassMIT
Angularericrisco/rsc-harness156—~3.4kAutomated safety check: PassMIT
Angular Componentaiskillstore/marketplace4301 repos~1.7kAutomated safety check: PassNone
Guidelinesakash-network/node1.1k22 repos~577Automated safety check: PassMIT
Component Refactoringlangflow-ai/langflow156k—~3.5kAutomated safety check: PassMIT

Similar skills

  • Angular

    kid-sid/claude-spellbook

    A skill your agent uses when building or refactoring Angular applications — choosing between signals, RxJS, and NgRx for state, configuring routing with guards and lazy loading, optimizing change…

    189 GitHub stars~5k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Angular

    ericrisco/rsc-harness

    A skill your agent uses when building, refactoring, or debugging Angular (v20/21+): standalone components, signals, zoneless change detection, @if/@for/@defer control flow, inject() DI…

    156 GitHub stars~3.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Angular Component

    aiskillstore/marketplace

    Create modern Angular standalone components following v20+ best practices.

    430 GitHub starsUsed in 1 repo~1.7k tokens
    Frontend & DesignAuto-check passed
  • Guidelines

    akash-network/node

    Behavioral guidelines to reduce common LLM coding mistakes. An agent skill from akash-network/node.

    1.1k GitHub starsUsed in 22 repos~577 tokens
    DevelopmentAuto-check passed
  • Component Refactoring

    langflow-ai/langflow

    Refactor high-complexity React components in Langflow frontend.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    41k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Risk Assess

What does Risk Assess do?

Uncommitted code risk assessment with breaking change detection, blast radius analysis, and scope metrics. Risk Assess is an agent skill from sd0xdev/sd0x-harness. Uncommitted code risk assessment with breaking change detection, blast radius analysis, and scope metrics.

When should I use Risk Assess?

Risk Assess fits situations like: : evaluating PR risk; pre-commit risk check; large refactoring review.

How do I install Risk Assess in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill risk-assess -a claude-code`. Or copy the skill folder (skills/risk-assess in sd0xdev/sd0x-harness) into .claude/skills/risk-assess in your project. Claude Code loads it when a task matches its description.

How do I install Risk Assess in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill risk-assess -a codex`. Or copy the skill folder (skills/risk-assess in sd0xdev/sd0x-harness) into .agents/skills/risk-assess in your project. Codex loads it when a task matches its description.

Can I use Risk Assess in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill risk-assess -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/risk-assess, .gemini/skills/risk-assess, .github/skills/risk-assess and .opencode/skills/risk-assess in your project.

What does Risk Assess need to run?

Going by SKILL.md and its folder, Risk Assess needs JavaScript for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: Node.js.

Does Risk Assess access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Risk Assess safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Risk Assess use?

Risk Assess is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Risk Assess use?

About 834 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Risk Assess?

Skills that share tags, products or a category with Risk Assess: Angular (kid-sid/claude-spellbook, 189 stars), Angular (ericrisco/rsc-harness, 156 stars), Angular Component (aiskillstore/marketplace, 430 stars) and Guidelines (akash-network/node, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Risk Assess?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.