cosmicstack-labs/risk-management
Risk identification, assessment matrices, mitigation strategies, BCP, and risk reporting
npx skills add https://github.com/cosmicstack-labs/mercury-agent-skills --skill risk-management
Identify, assess, and mitigate business and operational risks.
| Category | Examples |
|----------|----------|
| Strategic | Competition, market shifts, M&A integration |
| Operational | System failures, process gaps, human error |
| Financial | Currency, credit, liquidity, fraud |
| Compliance | Regulatory changes, data privacy, licensing |
| Reputational | Social media, PR crises, customer satisfaction |
| Security | Data breaches, cyber attacks, insider threats |
Likelihood × Impact = Risk Score (1-25)
Impact
Low Med High
Likely 3 6 9
Possible 2 4 6
Rare 1 2 3
Score 1-3: Accept | 4-6: Mitigate | 7-9: Avoid/Transfer
| Strategy | When | Example |
|----------|------|---------|
| Avoid | High risk, low reward | Don't enter unstable market |
| Reduce | Manageable risk | Add security controls, backups |
| Transfer | Financial risk but can't eliminate | Insurance, vendor contracts |
| Accept | Low impact or expensive to fix | Minor process inefficiencies |
| ID | Risk | Category | Likelihood | Impact | Score | Owner | Mitigation | Status |
|----|------|----------|-----------|--------|-------|-------|------------|--------|
| R01 | ... | ... | 3 | 4 | 12 | ... | ... | Active |
Take cosmicstack-labs/risk-management from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.