vantage-risk-register-curator

Create and normalize cyber risk register items from findings and assessments.

Updated Feb 20, 2026
One-click install
npx skills add https://github.com/johngutierrez31/VantageAI --skill vantage-risk-register-curator
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vantage-risk-register-curator
Source: https://github.com/johngutierrez31/VantageAI/tree/main/.agents/skills/vantage-risk-register-curator
Command: npx skills add https://github.com/johngutierrez31/VantageAI --skill vantage-risk-register-curator

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill streamlines the management of cyber risks by creating, normalizing, and prioritizing items in a living risk register, ensuring clear ownership and actionable due dates.

Core Features & Use Cases

  • Automated Risk Creation: Generates risk register items from various sources like findings, evidence gaps, and assessment results.
  • Risk Normalization: Consolidates duplicate risks, maintaining source references and essential details.
  • Prioritization & Tracking: Assigns severity, likelihood, and impact, and tracks ownership and due dates for board briefs and roadmaps.

Quick Start

Use the vantage-risk-register-curator skill to create a normalized risk register item from the provided TrustOps finding.

Frequently Asked Questions about vantage-risk-register-curator

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a cyber risk register from security findings and assessments?

You can create a cyber risk register from security findings by automatically generating, normalizing, and prioritizing risk items from diverse inputs like evidence gaps, overdue tasks, and assessment results. The skill ensures each risk is tenant-scoped and clearly linked to its original source.

What is the best way to normalize and de-duplicate duplicate entries in a risk register?

Normalizing and de-duplicating a risk register involves consolidating overlapping risk entries while maintaining source references and essential details. This ensures risks are tenant-scoped and clearly linked to their sources, preventing redundant tracking and reporting.

How do I prioritize cybersecurity risks with severity, likelihood, and impact metrics?

Prioritizing cybersecurity risks requires assigning explicit severity, likelihood, and impact metrics to each normalized risk register item. This process tracks ownership and actionable due dates, enabling effective roadmap planning and board brief generation.

Can I generate board briefs and roadmap plans from an existing compliance risk register?

Yes, you can generate board briefs and roadmap plans by surfacing top open risks from your compliance risk register. The skill assigns severity, likelihood, and impact metrics while tracking ownership and due dates to support executive reporting.

Does the risk register curator work with TrustOps findings and evidence gaps?

Yes, the risk register curator works directly with TrustOps findings and evidence gaps to automatically generate normalized risk register items. It processes these diverse inputs to ensure risks are tenant-scoped, de-duplicated, and linked to their sources.

What are the limitations of using automated risk normalization for cybersecurity assessments?

Automated risk normalization requires diverse inputs like findings and assessment results to be structured clearly to avoid misclassification. It relies on explicit severity, likelihood, and impact metrics, meaning unstructured or incomplete assessment data may limit risk prioritization accuracy.