risk

Record, resolve, and renew risk acceptances with expiry and remediation plans.

54|3|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/arcasilesgroup/ai-engineering --skill risk-arcasilesgroup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: risk
Source: https://github.com/arcasilesgroup/ai-engineering/tree/main/.agents/skills/risk
Command: npx skills add https://github.com/arcasilesgroup/ai-engineering --skill risk-arcasilesgroup

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill streamlines the process of managing risk acceptances, ensuring that all risks are properly documented, tracked, and have clear remediation plans.

Core Features & Use Cases

  • Accept Risk: Record new risks with severity, expiry, and follow-up actions.
  • Resolve Risk: Close accepted risks once remediation is complete.
  • Renew Risk: Extend the expiry of an accepted risk, with a limit of two renewals.
  • Use Case: When a security scan flags a low-severity issue that cannot be immediately fixed, use this Skill to formally accept the risk, document the remediation plan, and set an expiry date, allowing development to continue while the risk is tracked.

Quick Start

Use the risk skill to accept a new risk with critical severity and a clear follow-up action.

Frequently Asked Questions about risk

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I document and track risk acceptances for security issues that cannot be immediately fixed?

To manage risk acceptances, record the identified risk with its severity level, set an expiry date, and define follow-up remediation actions. This creates an auditable entry that allows development to proceed while tracking the risk lifecycle.

What is the process for resolving an accepted risk once remediation is complete?

Resolving an accepted risk involves closing the risk entry within the management workflow once the remediation plan has been fully executed. This finalizes the lifecycle and ensures compliance records reflect the completed action.

Can I extend the expiry date of an accepted risk if remediation is delayed?

Yes, you can extend the expiry date of an accepted risk through a renewal process. The system enforces time-bound risk management by limiting each risk to a maximum of two renewals.

When should I use a formal risk acceptance process in a development workflow?

Use a formal risk acceptance process when a security scan flags a low-severity issue that cannot be immediately fixed. It allows you to formally accept the risk, document a remediation plan, and set an expiry date for auditable governance.

Are there limits on how many times I can renew a risk acceptance?

Yes, the risk management system enforces a strict limit of two renewals per accepted risk. This ensures time-bound remediation planning and prevents indefinite risk acceptance without resolution.