wr-risk-scorer:update-policy

Draft or update RISK-POLICY.md to ISO 31000 standards.

4|1|Updated Apr 7, 2026
One-click install
npx skills add https://github.com/windyroad/agent-plugins --skill wr-risk-scorer-update-policy
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: wr-risk-scorer:update-policy
Source: https://github.com/windyroad/agent-plugins/tree/main/packages/risk-scorer/skills/update-policy
Command: npx skills add https://github.com/windyroad/agent-plugins --skill wr-risk-scorer-update-policy

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Drafts or updates the project's RISK-POLICY.md to ISO 31000 standards for consistent risk scoring.

Core Features & Use Cases

  • Policy drafting and updating: derives risk appetites, impact, and likelihood levels from project context.
  • Policy maintenance: last reviewed date tracking and auditability.
  • Validation and governance: informs risk scoring and gate decisions for commits, pushes, and releases.
  • Policy guidance: provides a repeatable framework that the risk-scorer agent and problem management process reference.

Quick Start

Run this skill to generate or update RISK-POLICY.md tailored to your project.

Frequently Asked Questions about wr-risk-scorer:update-policy

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an ISO 31000 compliant risk policy for my project?

To generate an ISO 31000 compliant risk policy, this skill drafts a RISK-POLICY.md file by assessing your project context to derive tailored risk appetites, impact levels, and likelihood levels for consistent scoring.

What is the best way to maintain governance and auditability for risk scoring policies?

Maintaining risk scoring governance and auditability is achieved by tracking the last reviewed date within the RISK-POLICY.md, ensuring your project retains a repeatable framework for ongoing policy maintenance and gate decisions.

How do I structure impact and likelihood levels for pipeline actions like commit and release?

Structuring impact and likelihood levels for pipeline actions involves drafting thresholds within the risk policy that inform gate decisions for commits, pushes, and releases based on derived project context.

Can I validate drafted risk levels against the risk-scorer agent contract before finalizing?

Yes, you can validate drafted risk levels against the risk-scorer agent contract. The skill implements a specific validation step to ensure your drafted policy aligns with the agent's scoring requirements.

When do I need a structured risk policy for problem management processes?

You need a structured risk policy for problem management when your project requires consistent risk scoring and governance guidance to inform automated pipeline actions and ongoing policy maintenance.

Does the risk policy generation process require existing project context to function?

Risk policy generation requires existing project context to derive appropriate risk appetites, impact levels, and likelihood levels, ensuring the drafted RISK-POLICY.md is tailored to your specific governance needs.