Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/brainbytes-dev/everything-claude-finance/risk-assessmentgit clone --depth 1 https://github.com/brainbytes-dev/everything-claude-financeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/brainbytes-dev/everything-claude-finance/risk-assessment)<a href="https://agentmods.dev/commands/brainbytes-dev/everything-claude-finance/risk-assessment"><img src="https://agentmods.dev/badge/commands/brainbytes-dev/everything-claude-finance/risk-assessment.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00007 | $0.01610 |
| Opus 5 | $0.00003 | $0.00805 |
| Sonnet 5 | $0.00001 | $0.00322 |
| Haiku 4.5 | $0.00001 | $0.00161 |
Grade A, and why
risk-assessment scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 160 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/risk-assessment — Financial Risk Assessment
What This Command Does
Conducts a structured financial risk assessment covering market risk, credit risk, operational risk, liquidity risk, and strategic risk. Produces a risk register with heat map, quantified exposure estimates, and a prioritized mitigation plan. Aligned with COSO ERM, ISO 31000, or Basel frameworks.
When to Use
- Annual enterprise risk assessment
- Board risk committee reporting
- Pre-transaction risk evaluation
- Regulatory risk assessment requirements
- Insurance coverage review
- Business continuity planning
How It Works
- Risk Identification: Systematic identification of financial risks across categories
- Risk Assessment: Evaluates likelihood and impact on a 5x5 matrix
- Quantification: Estimates financial exposure (VaR, stress loss, expected loss)
- Control Evaluation: Assesses effectiveness of existing controls and mitigants
- Residual Risk: Maps residual risk after controls
- Mitigation Planning: Proposes additional mitigants for unacceptable residual risks
- Monitoring: Defines KRIs (Key Risk Indicators) and escalation triggers
Example Usage
Input:
/risk-assessment entity:"GlobalParts Manufacturing" scope:enterprise framework:coso
Output:
# Enterprise Risk Assessment — GlobalParts Manufacturing
## Framework: COSO ERM | Scope: Enterprise | Date: 2026-03-14
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
## Risk Heat Map Summary
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Impact → Negligible Minor Moderate Major Severe
Likelihood ↓
Almost Certain [R7]
Likely [R3] [R1]
Possible [R5] [R4] [R2]
Unlikely [R6] [R8]
Rare [R9]
Critical risks (red zone): R1, R2, R7
High risks (orange zone): R3, R4
Moderate risks (yellow zone): R5, R8
Low risks (green zone): R6, R9
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
## Risk Register — Top Risks
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
### R1: Supply Chain Disruption (CRITICAL)
| Dimension | Assessment |
|-----------------|---------------------------------------------|
| Category | Operational Risk |
| Likelihood | Likely (4/5) |
| Impact | Major (4/5) — EUR 8M–15M revenue at risk |
| Inherent score | 16/25 |
| Current controls| Dual sourcing for 40% of components |
| Control effectiveness | Partial |
| Residual score | 12/25 |
| Exposure (1yr) | EUR 5M–10M (probability-weighted) |
Mitigation plan:
1. Expand dual sourcing to 80% of critical components (Q3 2026)
2. Increase safety stock for single-source items to 45 days (Q2 2026)
3. Qualify alternative suppliers in different geographies
Estimated cost: EUR 800K | Residual risk after: 6/25
### R2: FX Exposure — EUR/CNY (CRITICAL)
| Dimension | Assessment |
|-----------------|---------------------------------------------|
| Category | Market Risk |
| Likelihood | Possible (3/5) |
| Impact | Major (4/5) — EUR 3M–6M margin impact |
| Inherent score | 12/25 |
| Current controls| Natural hedge (30% of exposure) |
| Residual score | 9/25 |
| VaR (95%, 1yr) | EUR 4.2M |
Mitigation plan:
1. Implement rolling 12-month FX hedge program (60% of exposure)
2. Negotiate CNY-denominated supplier contracts where possible
3. Quarterly hedge ratio review linked to order book visibility
Estimated cost: EUR 120K (hedge premium) | Residual risk after: 4/25
### R7: Cybersecurity / Ransomware (CRITICAL)
| Dimension | Assessment |
|-----------------|---------------------------------------------|
| Category | Operational Risk |
| Likelihood | Almost Certain (5/5) |
| Impact | Severe (5/5) — EUR 10M+ (production stop) |
| Inherent score | 25/25 |
| Current controls| Basic firewall, antivirus, weekly backups |
| Control effectiveness | Weak |
| Residual score | 20/25 |
Mitigation plan:
1. IMMEDIATE: Implement EDR solution and 24/7 SOC monitoring
2. Daily encrypted offsite backups with tested restore procedures
3. Cyber insurance (EUR 10M coverage)
4. Employee security awareness training program
Estimated cost: EUR 350K/yr | Residual risk after: 8/25
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
## Aggregate Risk Exposure
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
| Risk Category | Gross Exposure | Controls | Net Exposure | % Revenue |
|------------------|---------------|----------|-------------|-----------|
| Market risk | EUR 8.5M | 35% | EUR 5.5M | 2.2% |
| Operational risk | EUR 22.0M | 25% | EUR 16.5M | 6.6% |
| Credit risk | EUR 3.2M | 60% | EUR 1.3M | 0.5% |
| Liquidity risk | EUR 5.0M | 50% | EUR 2.5M | 1.0% |
| **Total** |**EUR 38.7M** | |**EUR 25.8M**| **10.3%** |
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
## Key Risk Indicators (KRIs)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
| KRI | Current | Amber | Red |
|------------------------------|---------|---------|---------|
| Single-source component % | 60% | > 50% | > 70% |
| FX hedge ratio | 30% | < 40% | < 20% |
| Customer concentration (top 5)| 38% | > 40% | > 50% |
| Days cash on hand | 45 | < 30 | < 15 |
| Cybersecurity incidents/month| 12 | > 10 | > 25 |
### Next Review: Q3 2026 | Board Risk Committee: Q2 2026
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 160 lines · 7 tokens per session scan A 8d7dd627db7b
risk-assessment is a command published in the GitHub repository brainbytes-dev/everything-claude-finance (5 stars, last pushed 5mo ago), licensed MIT. It adds 7 tokens to every session and 1,610 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
merit-reconcile
Preview or check the status of Stripe → Merit payout reconciliation (read-only).
audit-checklist
Perform an internal audit, review controls, or prepare for an external financial audit.
valuation-methods
Valuation methods analysis — multiples, DCF inputs, PEG integration, valuation assumption extraction.
scan
Scan AWS account for cost optimization.
finops-status
Orientation — say where an opportunity or assignment sits in the five-step FinOps lifecycle and what unlocks next. Useful when a record has no active stage: an opportunity while its assignments do the work, an assignment whose plan has not been approved yet, or a rejected or archived assignment. Read-only; mutates…
archive-ledger
../../../shared/commands/archive-ledger.md.