Agent skill

Feature Risk Assessment

by zhou210712 in zhou210712/claude-for-legal-ZH

对单个功能或产品领域进行更深入的风险评估,当上线审查发现某个议题需要 超出单行条目的深度分析时使用。结构化分析:可能出什么问题、可能性多大、 后果多严重、如何缓解。当用户说"深入分析这个风险""[功能]风险评估" "可能出什么问题"或上线审查标记了全新议题时使用。

Apache-2.0Auto-check passedLegal & Compliance

Install Feature Risk Assessment

skills CLI
$ npx skills add zhou210712/claude-for-legal-ZH --skill feature-risk-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zhou210712/claude-for-legal-ZH feature-risk-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/product-legal/skills/feature-risk-assessment .claude/skills/feature-risk-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
feature-risk-assessment
GitHub stars
225
Token cost
~915 tokens
SKILL.md length
118 words
Files
1
Skills in repo
122
Repo updated
First seen
Licence
Apache-2.0

At a glance

对单个功能或产品领域进行更深入的风险评估,当上线审查发现某个议题需要 超出单行条目的深度分析时使用。结构化分析:可能出什么问题、可能性多大、 后果多严重、如何缓解。当用户说"深入分析这个风险""[功能]风险评估" "可能出什么问题"或上线审查标记了全新议题时使用。

  • Works in 6 steps: 我们评估什么 → 风险 → 监管环境(如相关) → …
  • Legal & Compliance work in your project
  • SKILL.md covers 事项上下文, 目的, 何时运行 and 结构, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Feature Risk Assessment is an agent skill from zhou210712/claude-for-legal-ZH. 对单个功能或产品领域进行更深入的风险评估,当上线审查发现某个议题需要 超出单行条目的深度分析时使用。结构化分析:可能出什么问题、可能性多大、 后果多严重、如何缓解。当用户说"深入分析这个风险""[功能]风险评估" "可能出什么问题"或上线审查标记了全新议题时使用。

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance. The licence is Apache-2.0.

When your agent uses it

  • Legal & Compliance work in your project

Example prompts

  • “深入分析这个风险”
  • “[功能]风险评估”
  • “可能出什么问题”
  • “/feature-risk-assessment”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. 我们评估什么
  2. 风险
  3. 监管环境(如相关)
  4. 先例(如有)
  5. 选项
  6. 建议

What it can do on your machine

Read from SKILL.md and the folder at commit 2f01c92. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Feature Risk Assessment loads about 915 tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 118 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~915

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zhou210712/claude-for-legal-ZH at commit 2f01c92, republished under its Apache-2.0 licence (© zhou210712). 118 words, ~915 tokens.

Download SKILL.mdSave it as .claude/skills/feature-risk-assessment/SKILL.md (or your agent's skills folder).
name
feature-risk-assessment
description
对单个功能或产品领域进行更深入的风险评估,当上线审查发现某个议题需要 超出单行条目的深度分析时使用。结构化分析:可能出什么问题、可能性多大、 后果多严重、如何缓解。当用户说"深入分析这个风险""[功能]风险评估" "可能出什么问题"或上线审查标记了全新议题时使用。

功能风险评估

事项上下文

事项上下文。 检查实务级 CLAUDE.md 中的 ## 事项工作空间。如果 Enabled 为 ✗(企业法务用户的默认值),跳过本段其余内容——技能使用实务级上下文,事项机制不可见。如果已启用且无活跃事项,询问:"这是哪个事项?运行 /product-legal:matter-workspace switch <事项简称> 或说 实务级。"加载活跃事项的 matter.md 获取事项特定上下文和覆盖规则。输出写入事项文件夹 ~/.claude/plugins/config/claude-for-legal/product-legal/matters/<事项简称>/。除非 跨事项上下文 为 开,否则绝不读取其他事项的文件。


目的

上线审查是广度。这是深度。当单个议题需要超出表格行的分析——一个新型AI功能、一个儿童产品、一个监管机构正在积极关注的事项——本技能产出一份独立的评估。

不是每次上线都需要。大多数不需要。这是给那10%的,其中"做完个人信息保护影响评估,上线"的审查深度不够。

何时运行

  • 上线审查发现一个不在校准表中的模式(全新)
  • 上线审查发现**"通常阻断"**类别中的某项
  • 法务负责人或领导层问"这里有什么风险"且需要的不是一句话
  • 功能处于监管积极关注的领域(AI、儿童、生物特征、健康、金融)
  • 法律团队外部有人担心,结构化的回答会有所帮助

如果以上都不满足,上线审查就足够了。不要为自身目的生成文书工作。

结构

1. 我们评估什么

一段话。功能做什么、新在哪里、为什么被升级到完整评估。

2. 风险

对每个独立风险(目标是2-5个,不是15个):

markdown
### 风险[N]:[简短名称]

**场景:**[需要发生什么才会导致出问题。要具体——不是"数据泄露"
而是"推荐算法因X将用户的敏感类别兴趣展示给了不该看到的人。"]

**谁受伤害:**[用户?公司?第三方?要具体。]

**可能性多大:**[低/中/高——附理由。"低——需要X和Y同时失效。"
不只是感觉评分。]

**如果发生有多严重:**[低/中/高——附理由。"高——
行政处罚+集团诉讼暴露+媒体报道"vs."低——一条愤怒的微博,无实际损害。"]

**现有缓解措施:**[已经降低可能性或影响的措施]

**缺口:**[还缺什么,如果有]

**剩余风险:**[在现有缓解措施之后——这是可接受还是需要更多?]
3. 监管环境(如相关)

仅当有监管机构对此领域有积极关注时才包含。如有:

  • 哪个监管机构,他们最近说了什么/做了什么
  • 此功能在他们看来如何
  • 我们是希望他们从我们这里听到还是从一篇头条新闻中听到

在中国法语境下,关注市场监管总局、国家互联网信息办公室、工业和信息化部、公安部门及其他行业监管机构最近的执法动态和指引。

4. 先例(如有)

其他公司做过类似的事吗?发生了什么?

  • 如果没出什么问题 → 有用,但不具有决定性
  • 如果出了问题 → 他们的情况有什么不同,这里是否适用

不要高估先例。监管机构会变换优先级;一家公司侥幸过关不意味着下一家也会。

5. 选项

呈现2-3条现实路径:

markdown
| 选项 | 描述 | 风险降低 | 成本 |
|---|---|---|---|
| A:按设计上线 | [当前计划] | 无 | 无 |
| B:上线并增加[缓解措施] | [改动] | [多少] | [开发工作量、时间、用户体验] |
| C:不上线[组件] | [砍范围] | [多少] | [产品影响] |
6. 建议

选一个。解释理由。承认您正在做何种权衡。

markdown
**建议:选项[X]**

[理由。剩余什么风险。为什么可接受。谁接受。]

**如果答案是"非我能定":**[谁决定,他们需要知道什么]

校准检查

定稿前,对照 ~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md → 风险校准检查:

  • 这份风险评估是针对这家公司校准的,还是泛泛的?
  • 对处于承诺整改协议下的公司可能是"高"风险,对不在该情况下的公司可能是"中"
  • 评估应反映实务画像中记载的实际监管环境、诉讼历史和风险偏好

交接

  • 转AI治理: 如果深度评估由AI功能触发——这很常见——同时或紧接着运行 /ai-governance-legal:aia-generation [功能]。功能风险评估搭建决策框架;算法安全评估以AI治理所需的格式具体记录AI系统。两者不重复:FRA是产品法务决策文件;算法安全评估是治理记录。
  • 转个人信息保护: 如果功能涉及新的数据采集或处理,运行 /privacy-legal:pia-generation [功能]。FRA的风险节可能与个人信息保护影响评估重叠——标记该重叠以避免重复工作,但两份文件都需要存在。
  • 转AI治理供应商审查: 如果功能使用新的AI供应商,运行 /ai-governance-legal:vendor-ai-review [供应商协议],如在上线审查时尚未完成。

输出格式

独立文件,2-4页。冠以 ~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md ## 输出规范 中的工作成果页眉(因用户角色而异——参见 ## 使用者)。

不是PPT演示稿,不是备忘录——是一份供阅读后决策的决策文件。

保存到 ~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md → 上线审查流程规定的审查文件存放位置。如果文件将被分享给保密范围外的任何人(例如发布到广泛共享的工单上),仅为该对外版本去除工作成果页眉,在事项文件中保留保密原始版本。

引用检查

如果评估引用了案例、法律、法规或执法行动——尤其是在监管环境或先例节中——这些引用由AI模型生成且未经原始来源验证。在决策文件交给决策者之前,对照法律研究工具(北大法宝、威科先行、法信或您的律所研究平台)核实每个引用的准确性、有效性和当前的执法态势。建立在虚构执法行动上的风险评估比没有评估更糟糕。

禁止静默补充。 如果对已配置的法律研究工具的检索查询返回的结果很少或无结果,报告检索到的情况并停止。不要未经询问从联网搜索或模型知识中填补。说:"[工具]搜索返回[N]条结果。关于[制度/先例]的覆盖似乎有限。选项:(1) 扩大检索查询,(2) 尝试不同的研究工具,(3) 搜索网络——结果将标记 [联网检索 — 需复核],依赖前应比照发布机关核实,或 (4) 标记为未核实并停止。您选哪个?"由律师决定是否接受较低置信度的来源。

来源归属。 将监管环境和先例节中的每个引用标记其来源:[北大法宝]、[威科先行]、[监管机构网站],或对于从法律研究对接获取的引用使用MCP工具名称;[联网检索 — 需复核] 用于联网搜索引用;[模型知识 — 需验证] 用于训练数据中回忆的引用;[用户提供] 用于功能团队提供的引用。标记 需验证 的引用具有较高的编造风险,应首先检查。绝不剥离或折叠标签——决策者需要看到哪些引用需要首先核实。

以下一步决策树收尾

以 CLAUDE.md ## 输出规范 中的下一步决策树收尾。将选项定制为本技能刚刚产出的内容——五个默认分支(起草X、上报、补充事实、监控等待、其他)是起点,不是锁死。决策树是输出;律师做选择。

本技能不做什么

  • 它不评估每个功能。大多数功能只需上线审查。
  • 它不做决策。它搭建决策框架。有权的人选选项。
  • 它不做定量风险建模。如果公司有带数字的正式风险框架,使用该框架——这是定性评估。

© zhou210712, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in product-legal/skills/feature-risk-assessment of zhou210712/claude-for-legal-ZH.

Open the folder on GitHubat commit 2f01c92

Compare with similar skills

Feature Risk Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Feature Risk Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Feature Risk Assessment this skillzhou210712/claude-for-legal-ZH225—~915Automated safety check: PassApache-2.0
Paper to Chinese Patent DrafterYuan1z0825/nature-skills47k1 repos~1.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Legal Clinic Client Intakeanthropics/claude-for-legal9.6k3 repos~3.2kAutomated safety check: PassApache-2.0
Paper To Cn Patentsnipp-zha/Paper-to-patent-Skill1071 repos~959Automated safety check: PassNone

Similar skills

  • Paper to Chinese Patent Drafter

    Yuan1z0825/nature-skills

    Drafts Chinese invention patent applications and technical disclosures from research papers or inventor materials, tying each claim feature to source evidence.

    47k GitHub starsUsed in 1 repo~1.1k tokens
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Legal & ComplianceAuto-check passed
  • Paper To Cn Patent

    snipp-zha/Paper-to-patent-Skill

    Convert scientific papers, theses, technical reports, source code, figures, or research manuscripts into evidence-grounded Chinese invention patent drafts.

    107 GitHub starsUsed in 1 repo~959 tokens
    Legal & ComplianceAuto-check passed
  • Employment Contract Templates

    ynulihao/AgentSkillOS

    Create employment contracts, offer letters, and HR policy documents following legal best practices.

    618 GitHub starsUsed in 12 repos~4.1k tokens
    Legal & ComplianceAuto-check passed

More from zhou210712/claude-for-legal-ZH

All 122 skills in this repo
  • Claim Chart

    zhou210712/claude-for-legal-ZH

    构建或审查要件分析表——专利权利要求对照表(侵权、无效或审查)或 民事构成要件分析表(任何诉讼请求或抗辩),每个单元格附精确引用, 缺口检测为优先输出。当用户要求要件分析表、权利要求对照表、 证据对照表、侵权或无效主张、逐要件映射,或问"我们证明[主张]还缺什么"时使用。

    225 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Client Intake

    zhou210712/claude-for-legal-ZH

    结构化接待——实践领域模板、跨领域考点识别、利益冲突标记、分流分类. An agent skill from zhou210712/claude-for-legal-ZH.

    225 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Gap Surfacer

    zhou210712/claude-for-legal-ZH

    参考资料:支持 /regulatory-legal:gaps 和 /regulatory-legal:comments 的共享差距和意见征集跟踪框架。跟踪未关闭的政策差距及其整改状态, 从 policy-diff 中获取差距,呈现开放和即将到期的事项,路由给负责人, 并通过企业通讯工具通知差距负责人,每次发送前需确认。

    225 GitHub stars~757 tokensUpdated 4 mo ago
    Auto-check passed
  • Launch Review

    zhou210712/claude-for-legal-ZH

    对照您的框架和风险校准进行全面产品上线审查。当用户说"审查这个上线" "[功能]法务审查""我们能上线吗""[产品]有什么法律问题"或引用了需要 逐类审查备忘录的产品需求文档或上线追踪工单时使用。

    225 GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check passed
  • Reg Feed Watcher

    zhou210712/claude-for-legal-ZH

    检查法规动态源,报告自上次检查以来的新事项,按重要度阈值过滤。适用于用户说"检查法规动态"、"有什么新规定"、"法规更新"、从定时任务触发执行,或手动粘贴法规动态进行分类和差异分析时。

    225 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Renewal Tracker

    zhou210712/claude-for-legal-ZH

    展示具有即将到来的取消截止日期的合同,在通知窗口关闭前发出预警, 基于维护的续约登记册运行。当用户询问"什么即将续约""哪些续约即将到期" "我们是否错过了取消窗口""将此添加到续约追踪器"时使用,或按计划运行。

    225 GitHub stars~681 tokensUpdated 4 mo ago
    Auto-check passed

Questions about Feature Risk Assessment

What does Feature Risk Assessment do?

对单个功能或产品领域进行更深入的风险评估,当上线审查发现某个议题需要 超出单行条目的深度分析时使用。结构化分析:可能出什么问题、可能性多大、 后果多严重、如何缓解。当用户说"深入分析这个风险""[功能]风险评估" "可能出什么问题"或上线审查标记了全新议题时使用。. Feature Risk Assessment is an agent skill from zhou210712/claude-for-legal-ZH.

When should I use Feature Risk Assessment?

Feature Risk Assessment fits situations like: legal & Compliance work in your project.

How do I install Feature Risk Assessment in Claude Code?

Run `npx skills add zhou210712/claude-for-legal-ZH --skill feature-risk-assessment -a claude-code`. Or copy the skill folder (product-legal/skills/feature-risk-assessment in zhou210712/claude-for-legal-ZH) into .claude/skills/feature-risk-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Feature Risk Assessment in Codex?

Run `npx skills add zhou210712/claude-for-legal-ZH --skill feature-risk-assessment -a codex`. Or copy the skill folder (product-legal/skills/feature-risk-assessment in zhou210712/claude-for-legal-ZH) into .agents/skills/feature-risk-assessment in your project. Codex loads it when a task matches its description.

Can I use Feature Risk Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhou210712/claude-for-legal-ZH --skill feature-risk-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/feature-risk-assessment, .gemini/skills/feature-risk-assessment, .github/skills/feature-risk-assessment and .opencode/skills/feature-risk-assessment in your project.

What does Feature Risk Assessment need to run?

SKILL.md names no scripts, command-line tools or credentials: Feature Risk Assessment is instructions for the agent only.

Does Feature Risk Assessment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Feature Risk Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Feature Risk Assessment use?

Feature Risk Assessment is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Feature Risk Assessment use?

About 915 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Feature Risk Assessment?

Skills that share tags, products or a category with Feature Risk Assessment: Paper to Chinese Patent Drafter (Yuan1z0825/nature-skills, 47k stars), C15t (c15t/c15t, 1.9k stars), Contract Review (evolsb/claude-legal-skill, 464 stars) and Legal Clinic Client Intake (anthropics/claude-for-legal, 9.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Feature Risk Assessment?

zhou210712 (a GitHub user) maintains it in zhou210712/claude-for-legal-ZH, which has 225 GitHub stars. The repository holds 122 skills in this directory. The repository was last updated on May 15, 2026.

Source: zhou210712/claude-for-legal-ZH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.