Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add jeffreytse/grimoire-core --skill apply-iso-31000-risk-frameworkgit clone --depth 1 https://github.com/jeffreytse/grimoire-coreWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jeffreytse/grimoire-core/apply-iso-31000-risk-framework)<a href="https://agentmods.dev/skills/jeffreytse/grimoire-core/apply-iso-31000-risk-framework"><img src="https://agentmods.dev/badge/skills/jeffreytse/grimoire-core/apply-iso-31000-risk-framework/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/jeffreytse/grimoire-core/apply-iso-31000-risk-framework"><img src="https://agentmods.dev/badge/skills/jeffreytse/grimoire-core/apply-iso-31000-risk-framework.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00072 | $0.01430 |
| Opus 5 | $0.00036 | $0.00715 |
| Sonnet 5 | $0.00014 | $0.00286 |
| Haiku 4.5 | $0.00007 | $0.00143 |
Grade A, and why
apply-iso-31000-risk-framework scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 68 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Apply ISO 31000 Risk Framework
Apply a systematic, repeatable process for managing risk across an organization broadly — establishing context, identifying risks, analyzing and evaluating them, treating the significant ones, and monitoring the whole process over time — rather than handling risk ad hoc through isolated, disconnected efforts that don't add up to a coherent, organization-wide risk-management discipline.
Why This Is Best Practice
Adopted by: ISO 31000, "Risk Management — Guidelines," published by the International Organization for Standardization, is the internationally recognized standard for enterprise risk management, adopted or referenced by organizations across industries and countries as the common framework for structuring an organization's risk-management process, and forming the basis for many national and industry-specific risk-management standards built on its core structure. Impact: Organizations that manage risk only through isolated, disconnected efforts — an incident response process for outages, a separate security review for new systems, an unrelated insurance review for property — tend to miss risks that fall between these isolated efforts' scope, and lack a consistent way to compare and prioritize risks across very different categories (operational, financial, strategic, reputational) that a unified framework specifically enables. Why best: A collection of disconnected, ad hoc risk-management efforts, however individually competent, doesn't provide the organization a single, comparable view of its overall risk profile or a consistent process for deciding where to invest limited risk-management resources — ISO 31000's structured process specifically provides this unifying framework, at the cost of requiring genuine organizational commitment to implement consistently rather than treating it as a one-time exercise.
Sources: ISO 31000:2018, "Risk Management — Guidelines," International Organization for Standardization
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 68 lines · 72 tokens per session scan A 83999d960194
apply-iso-31000-risk-framework is a skill published in the GitHub repository jeffreytse/grimoire-core (4 stars, last pushed 23d ago), licensed MIT. It adds 72 tokens to every session and 1,430 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
counseling-psychology
Therapeutic frameworks, assessment, ethical practice, and client documentation for counselors and psychologists.
semantic-model-disambiguation
Analyze Power BI semantic models for column-level overlaps that confuse Copilot and Fabric data agents. Detect ambiguity, review with domain expert, apply fixes via MCP.
prompt-2-data
Generate comprehensive synthetic relational data for any specified subject with multiple normalized CSV files maintaining referential integrity.
infrastructure-as-code
Domain: DevOps & Cloud Engineering.
academic-paper-drafting
End-to-end academic paper drafting for CHI, HBR, journals, and conferences with venue-specific templates, drafting workflows, and revision strategies.
research-first-development
Build knowledge bases that build software — research before code, teach before execute.