Agent skill

Risk Prioritiser

by transilienceai in transilienceai/communitytools

Risk-based prioritisation of confirmed attack paths. An agent skill from transilienceai/communitytools.

MITAuto-check passedSecurity

Install Risk Prioritiser

skills CLI
$ npx skills add transilienceai/communitytools --skill risk-prioritiser -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install transilienceai/communitytools risk-prioritiser --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/transilienceai/communitytools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/risk-prioritiser .claude/skills/risk-prioritiser && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
risk-prioritiser
GitHub stars
563
Token cost
~1.5k tokens
SKILL.md length
579 words
Files
2
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Risk-based prioritisation of confirmed attack paths. An agent skill from transilienceai/communitytools.

  • Works in 7 steps: Load inputs. → Score each confirmed_paths entry. → Score each single-asset validated… → …
  • Tasks that involve Prioritization frameworks
  • SKILL.md covers Trigger, Workflow, Tier weights and Output, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Risk Prioritiser is an agent skill from transilienceai/communitytools. Risk-based prioritisation of confirmed attack paths. Combines exploit feasibility, technical CVSS severity, and asset business impact into a single ranked list driving remediation roadmaps.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `reference/scoring-formula.md`).

It sits in Security, covering Prioritization frameworks. The repository describes itself as: Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research. The licence is MIT.

When your agent uses it

  • Tasks that involve Prioritization frameworks

Example prompts

  • “/risk-prioritiser”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Load inputs.
  2. Score each confirmed_paths entry.
  3. Score each single-asset validated finding that does not sit on a confirmed path. Same formula; feasibility = 1.0, business_impact =…
  4. Score each inferred_paths entry, but cap their bucket placement at theoretical regardless of numeric score. Inferred paths NEVER reach…
  5. Sort descending. Stable tie-break order: max CVSS desc → hop count asc → finding age desc (newer first).
  6. Bucket into roadmap tiers.
  7. Write outputs to artifacts/attack-paths-ranked.json + attack-paths-ranked.md. Each row carries path_class so downstream consumers can…

What it can do on your machine

Read from SKILL.md and the folder at commit 95fdc12. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Risk Prioritiser loads about 1.5k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 579 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from transilienceai/communitytools at commit 95fdc12, republished under its MIT licence (© transilienceai). 579 words, ~1,526 tokens.

Download SKILL.mdSave it as .claude/skills/risk-prioritiser/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
risk-prioritiser
description
Risk-based prioritisation of confirmed attack paths. Combines exploit feasibility, technical CVSS severity, and asset business impact into a single ranked list driving remediation roadmaps.

Risk Prioritiser

Consume the attack-path graph + the client-supplied business-tier map and emit a single ranked list of paths the org should remediate first. Mounted onto cloud-agent task #7.

Trigger

Cron daily after attack-path-stitcher (task #6) completes. Also event-fires when a new validated/*.json is written with nvd.score >= 9.0.

Workflow

  1. Load inputs.
    • artifacts/attack-paths.json — graph from task #6. Split into confirmed_paths (RFP-grade) and inferred_paths (topology/supply-chain).
    • business-tier-map.csv — client-supplied asset → tier. Search order: {OUTPUT_DIR}/business-tier-map.csv → projects/rfp-3.3/schemas/business-tier-map.csv.
  2. Score each confirmed_paths entry.
    • feasibility = product of every edge's feasibility along the path. For confirmed paths this is always 1.0.
    • technical_severity = max_cvss_along_path / 10.
    • business_impact = tier weight of the destination (crown_jewel = 1.0 by definition).
    • entry_exposure = 1.0 if entry node is external: true, else 0.5.
    • Final score = feasibility × technical_severity × business_impact × entry_exposure.
  3. Score each single-asset validated finding that does not sit on a confirmed path. Same formula; feasibility = 1.0, business_impact = asset's own tier weight, hop count = 1.
  4. Score each inferred_paths entry, but cap their bucket placement at theoretical regardless of numeric score. Inferred paths NEVER reach immediate / short_term / medium_term — RFP §3.3 requires "confirmed", and inferred paths are evidence-deficient by construction.
  5. Sort descending. Stable tie-break order: max CVSS desc → hop count asc → finding age desc (newer first).
  6. Bucket into roadmap tiers.
    • immediate (0-7 days): confirmed AND score ≥ 0.6
    • short_term (7-30 days): confirmed AND 0.3 ≤ score < 0.6
    • medium_term (30-90 days): confirmed AND 0.1 ≤ score < 0.3
    • monitor: confirmed AND score < 0.1
    • theoretical (track-only): any path with path_class != "confirmed". Surfaced in board reports but excluded from the remediation SLA roadmap.
  7. Write outputs to artifacts/attack-paths-ranked.json + attack-paths-ranked.md. Each row carries path_class so downstream consumers can filter.

Tier weights

TierWeight
crown_jewel1.00
revenue0.70
support0.40
dev0.20
unknown0.30

The unknown weight is deliberately above support to bias toward investigating un-mapped assets — they often turn out to be high-tier once discovered.

Output

{OUTPUT_DIR}/
  artifacts/
    attack-paths-ranked.json
    attack-paths-ranked.md

attack-paths-ranked.json schema:

json
{
  "generated_at": "2026-05-13T03:30:00Z",
  "tier_weights_used": {"crown_jewel": 1.0, "revenue": 0.7, "support": 0.4, "dev": 0.2, "unknown": 0.3},
  "ranked": [
    {
      "rank": 1,
      "kind": "path",
      "path_class": "confirmed",
      "path_id": "asset05->asset42->asset99",
      "hops": ["asset05", "asset42", "asset99"],
      "feasibility": 1.0,
      "max_cvss": 9.8,
      "business_impact": 1.0,
      "entry_exposure": 1.0,
      "score": 0.98,
      "bucket": "immediate",
      "remediation_focus": "asset05"
    },
    {
      "rank": 2,
      "kind": "finding",
      "path_class": "confirmed",
      "finding_id": "finding-018",
      "asset": "asset42",
      "feasibility": 1.0,
      "max_cvss": 9.1,
      "business_impact": 0.7,
      "entry_exposure": 1.0,
      "score": 0.637,
      "bucket": "immediate"
    }
  ],
  "buckets": {"immediate": 4, "short_term": 11, "medium_term": 22, "monitor": 8, "theoretical": 14}
}
Show full SKILL.md (276 more words)Show less

Remediation focus

For each ranked path, pick a single remediation_focus asset — the one whose patch breaks the chain at the lowest cost:

  • If any edge has feasibility < 1.0 → focus on that edge's source asset. The weakest pivot is the attacker's cheapest hop; hardening it eliminates the easiest entry.
  • If every edge is feasibility 1.0 (fully confirmed chain) → focus on the path's entry asset (hops[0]). Patching the externally-reachable foothold breaks every downstream hop and is the cheapest patch surface operationally.

This rule yields a single deterministic asset id per path. The previous "edge contribution formula" was deprecated — on uniformly-confirmed chains every edge has identical contribution, which gives no useful signal.

Rules

  1. Always derive from attack-paths.json. Do not re-derive feasibility / CVSS — those are already validated by upstream tasks.
  2. business-tier-map.csv is authoritative. If an asset is missing from the map, use unknown tier weight + flag unmapped_assets[] at the top of the JSON output.
  3. Stable rank for stable input. Re-running on identical input must produce byte-identical output.
  4. No new findings. Prioritisation never creates findings; it only re-orders.
  5. Bucket thresholds are config. The 0.6/0.3/0.1 cuts can be overridden via --thresholds argument when running on a client with different remediation cadences. Default values match the Transilience report's "Immediate / Short-term / Medium-term" labels.

Implementation

The scoring is implemented deterministically by tools/risk-prioritise.py (not delegated to an LLM agent), to satisfy Rule 3 (stable rank for stable input). The tool reads artifacts/attack-paths.json and writes the two output files. Override the tier weights or bucket thresholds with --tier-weights / --thresholds JSON arguments — recorded in the output for audit.

References

  • reference/scoring-formula.md — worked example + edge-case behaviour.
  • projects/rfp-3.3/schemas/business-tier-map.csv — input schema and example rows.
  • tools/risk-prioritise.py — deterministic implementation.

© transilienceai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/risk-prioritiser of transilienceai/communitytools.

  • SKILL.md
  • reference/scoring-formula.md

Open the folder on GitHubat commit 95fdc12

Compare with similar skills

Risk Prioritiser next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Risk Prioritiser compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Risk Prioritiser this skilltransilienceai/communitytools563—~1.5kAutomated safety check: PassMIT
Performing Cve Prioritization With Kev Catalogmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.0
Mapping Mitre Attack Techniquesmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
Threat Detectionalirezarezvani/claude-skills28k—~3.5kAutomated safety check: PassMIT
Building Ioc Enrichment Pipeline With Openctimukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Managing Vulnerabilitiesancoleman/ai-design-components525—~3.8kAutomated safety check: PassMIT

Similar skills

  • Performing Cve Prioritization With Kev Catalog

    mukul975/Anthropic-Cybersecurity-Skills

    Fetch and parse the CISA Known Exploited Vulnerabilities (KEV) catalog, enrich it with EPSS scores and CVSS metrics, and build a multi-factor prioritization engine and report that ranks CVE…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Mapping Mitre Attack Techniques

    mukul975/Anthropic-Cybersecurity-Skills

    Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization.

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Threat Detection

    alirezarezvani/claude-skills

    A skill your agent uses when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.

    28k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Ioc Enrichment Pipeline With Opencti

    mukul975/Anthropic-Cybersecurity-Skills

    Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native threat intel platform) using its internal enrichment connectors to pull context from VirusTotal, Shodan, AbuseIPDB, and…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    Product & Project ManagementAuto-check passed
  • Managing Vulnerabilities

    ancoleman/ai-design-components

    Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.

    525 GitHub stars~3.8k tokensUpdated 10 mo ago
    SecurityAuto-check passed
  • Vulnerability Management

    cbrock84/headcount

    Runs the loop from discovering a weakness to confirming it is fixed — scanning, triage, prioritization by real exploitability, remediation tracking, and patch policy.

    2k GitHub stars~1.1k tokensUpdated 23 days ago
    Product & Project ManagementAuto-check passed

More from transilienceai/communitytools

All 35 skills in this repo
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    563 GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Workflow

    transilienceai/communitytools

    GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.

    563 GitHub stars~812 tokensUpdated 2 mo ago
    Auto-check: notes
  • Pci Secure Software

    transilienceai/communitytools

    Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.

    563 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Protect With Password

    transilienceai/communitytools

    Generate ONE strong password and apply it to each referenced file (PDF, Word, Excel, PowerPoint, or any type).

    563 GitHub stars~583 tokensUpdated 2 mo ago
    Auto-check passed
  • Skill Update

    transilienceai/communitytools

    Skill creation, update and management — generates skill directory structure, validates against best practices, enforces line count limits.

    563 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Source Code Scanning

    transilienceai/communitytools

    Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

    563 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check: notes

Questions about Risk Prioritiser

What does Risk Prioritiser do?

Risk-based prioritisation of confirmed attack paths. An agent skill from transilienceai/communitytools. Risk Prioritiser is an agent skill from transilienceai/communitytools. Risk-based prioritisation of confirmed attack paths.

When should I use Risk Prioritiser?

Risk Prioritiser fits situations like: tasks that involve Prioritization frameworks.

How do I install Risk Prioritiser in Claude Code?

Run `npx skills add transilienceai/communitytools --skill risk-prioritiser -a claude-code`. Or copy the skill folder (skills/risk-prioritiser in transilienceai/communitytools) into .claude/skills/risk-prioritiser in your project. Claude Code loads it when a task matches its description.

How do I install Risk Prioritiser in Codex?

Run `npx skills add transilienceai/communitytools --skill risk-prioritiser -a codex`. Or copy the skill folder (skills/risk-prioritiser in transilienceai/communitytools) into .agents/skills/risk-prioritiser in your project. Codex loads it when a task matches its description.

Can I use Risk Prioritiser in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add transilienceai/communitytools --skill risk-prioritiser -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/risk-prioritiser, .gemini/skills/risk-prioritiser, .github/skills/risk-prioritiser and .opencode/skills/risk-prioritiser in your project.

What does Risk Prioritiser need to run?

SKILL.md names no scripts, command-line tools or credentials: Risk Prioritiser is instructions for the agent only.

Does Risk Prioritiser access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Risk Prioritiser safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Risk Prioritiser use?

Risk Prioritiser is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Risk Prioritiser use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Risk Prioritiser?

Skills that share tags, products or a category with Risk Prioritiser: Performing Cve Prioritization With Kev Catalog (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Mapping Mitre Attack Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Threat Detection (alirezarezvani/claude-skills, 28k stars) and Building Ioc Enrichment Pipeline With Opencti (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Risk Prioritiser?

transilienceai (a GitHub organization) maintains it in transilienceai/communitytools, which has 563 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on July 29, 2026.

Source: transilienceai/communitytools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.