risk-assessment

Identify and manage risks across technical, project, and business dimensions.

Updated Mar 6, 2026
One-click install
npx skills add https://github.com/oyjs1989/marketplace --skill risk-assessment-oyjs1989
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: risk-assessment
Source: https://github.com/oyjs1989/marketplace/tree/main/skills/risk-assessment/skills/risk-assessment
Command: npx skills add https://github.com/oyjs1989/marketplace --skill risk-assessment-oyjs1989

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

系统化地识别、分析并量化技术、项目及业务风险,帮助团队在早期阶段发现潜在问题并制定可执行的缓解策略。

Core Features & Use Cases

  • 风险识别、根因分析、影响评估、风险量化、优先级排序和缓解计划等完整流程
  • 适用于技术项目、产品开发、运维和业务场景的系统性风险管理
  • 提供基于 COSO ERM 与 ISO 31000 的方法论与模板,帮助组织建立持续改进的风险体系
  • Use Case: 在软件项目中识别关键风险、计算风险值并制定应对措施以保障进度与质量

Quick Start

描述一个软件项目场景并生成一个带有可执行缓解措施的优先级风险评估。

Frequently Asked Questions about risk-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a risk assessment for a software project using ISO 31000?

Risk assessment using ISO 31000 involves systematically identifying threats, analyzing root causes, quantifying impact, and prioritizing risks. This Skill applies structured techniques to evaluate technical and project dimensions, delivering clear risk matrices and remediation strategies.

What is the best way to identify and mitigate technical risks in product development?

Identifying and mitigating technical risks requires evaluating potential threats across technical, project, and business dimensions. You can quantify risk values, prioritize issues, and generate executable mitigation plans aligned with COSO ERM and ISO 31000 methodologies.

Can I use FMEA to perform root cause analysis and risk quantification for operations?

Yes, FMEA supports root cause analysis and risk quantification for operations. This Skill systematically evaluates operational threats, calculates risk values, and produces prioritized matrices to guide your mitigation planning effectively.

How do I create a risk matrix and prioritize mitigation plans for business risks?

Creating a risk matrix involves quantifying potential business threats and sorting them by priority. This Skill evaluates business dimensions, calculates clear risk values, and outputs structured remediation strategies to mitigate prioritized risks.

Does risk mitigation planning based on COSO ERM work for early stage product projects?

Yes, COSO ERM-based risk mitigation works for early stage product projects. It helps teams systematically discover potential problems early, evaluate threats across product dimensions, and establish executable mitigation strategies to safeguard schedules.

When should I not use systematic risk identification for my project?

Systematic risk identification may be unnecessary for trivial tasks lacking technical or business complexity. This Skill is designed for software, operations, and product projects requiring structured COSO ERM or ISO 31000 methodologies to manage significant threats.