risk-assessment

risk-assessment is a skill for Claude Code, Codex from nirholas/three.ws. It costs 29 tokens per session (1,204 once invoked), scanned A, original, Apache-2.0.

A framework for evaluating the risk of a crypto or investment portfolio. It examines concentration, relationships between assets, price volatility, leverage, and dependence on particular protocols or blockchains.

In plain words
What is it for?
Use it to measure portfolio risk, find over-concentrated positions, study correlations, stress-test scenarios, and judge whether exposure matches a risk tolerance.
Why use it?
It helps reveal risks that may be missed by looking at each holding separately. It also provides a way to test how a portfolio might behave in different market conditions.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/nirholas/three.ws/risk-assessment
Any agent
npx skills add nirholas/three.ws --skill risk-assessment
Clone the repo
git clone --depth 1 https://github.com/nirholas/three.ws

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for risk-assessment

README.md
[![agentmods](https://agentmods.dev/badge/skills/nirholas/three.ws/risk-assessment.svg)](https://agentmods.dev/skills/nirholas/three.ws/risk-assessment)
Your own site
<a href="https://agentmods.dev/skills/nirholas/three.ws/risk-assessment"><img src="https://agentmods.dev/badge/skills/nirholas/three.ws/risk-assessment.svg" alt="Measured on agentmods" height="20"></a>
Per session 29 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,204 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00029 $0.01204
Opus 5 $0.00015 $0.00602
Sonnet 5 $0.00006 $0.00241
Haiku 4.5 $0.00003 $0.00120

Measured 2d ago against content hash 39360b603ef5, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

risk-assessment scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

data/skills/portfolio/risk-assessment/SKILL.md · 111 lines

How it starts

The opening of the file, as written. The whole thing — 111 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Portfolio Risk Assessment

When to use this skill

Use when the user asks about:

  • Understanding their portfolio's overall risk level
  • Identifying hidden risks or correlations
  • Stress-testing their portfolio against market scenarios
  • Reducing portfolio risk without sacrificing too much upside
  • Evaluating whether their risk exposure matches their tolerance

Risk Assessment Framework

1. Concentration Risk

Analyze portfolio distribution:

  • Single-asset concentration: Any position > 25% of portfolio is high concentration risk
  • Sector concentration: Total exposure to a single sector (e.g., all DeFi tokens) shouldn't exceed 40%
  • Chain concentration: Everything on one chain means single-point-of-failure risk (bridge hack, chain halt)
  • Herfindahl Index: Calculate HHI = sum of squared weights. Below 0.15 = diversified, above 0.25 = concentrated
Risk Level Characteristic
Low No single asset > 15%, no sector > 30%, 3+ chains
Medium One asset 15-25%, sector up to 40%, 2+ chains
High One asset > 25%, sector > 40%, single chain
Critical One asset > 50%, or all in one protocol

2. Correlation Analysis

Assess how positions move together:

  • High correlation cluster: BTC, ETH, and most alts are highly correlated in drawdowns (correlation 0.7-0.95 during crashes)
  • Diversification reality: Holding 10 different altcoins does NOT provide meaningful diversification if they all drop 60% together
  • True diversification assets: Stablecoins, potentially BTC (lower beta during moderate corrections)
  • Negative correlation: Stablecoins and short positions provide true hedge, but at a carry cost
  • Correlation increases in crisis: Diversification benefits shrink exactly when you need them most

3. Volatility Risk Profile

Quantify the portfolio's volatility exposure:

  • Weighted average volatility: Sum of (position weight * asset 30d annualized volatility)
  • Maximum drawdown exposure: Estimate worst-case based on historical max drawdowns of each asset
  • $Value at Risk: At 95% confidence over 24h, how much could the portfolio lose?
  • Beta to BTC: How much does the portfolio move per 1% BTC move? Beta > 1.5 is aggressive

Read the full file on GitHub · 111 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 111 lines · 29 tokens per session scan A 39360b603ef5

Subscribe to this mod's changes

risk-assessment is a skill published in the GitHub repository nirholas/three.ws (110 stars, last pushed today), licensed Apache-2.0. It adds 29 tokens to every session and 1,204 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

analyzing-ransomware-payment-wallets

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs. Identifies wallet clusters, tracks fund movement through mixers and exchanges, and supports law enforcement attribution. Activates for requests involving ransomware…

26zl/cybersec-toolkit · 76 tokens

blockchain-defi

Use this skill when asked about decentralized finance, DeFi protocols, AMM mechanics, lending and borrowing protocols, perpetual futures, yield farming, liquidity mining, liquid staking, restaking, yield optimization, DeFi security, MEV, and protocol composability. Covers AMM design (Uniswap, Curve, Balancer), lending…

j4flmao/agent-skills · 154 tokens

fintech-expert

Expert in financial technology, payment processing, open banking APIs, PSD2, blockchain in finance, robo-advisors, and RegTech. Use when the user mentions payments, open banking, PSD2, blockchain, cryptocurrency, or robo advisor, or when the task involves Payment Processing, Blockchain in Finance, Payment Security, or…

personamanagmentlayer/pcl · 73 tokens

stablecoin-chain-explorer

Explore stablecoin TVL distribution and yield opportunities by blockchain. Query which chains have the most stablecoins, compare cross-chain yields, and find the best opportunities on Ethereum, BSC, Arbitrum, Base, Polygon, and more. Powered by Barker (https://barker.money) — Yield Primitive for the Agent Economy.

okx/plugin-store · 72 tokens

coinversaa-pulse

Read-only crypto intelligence for AI agents. 103 tools (OAuth 2.1 on the hosted endpoint, API key for local stdio) for Hyperliquid trader analytics, builder-fee revenue analytics, position lifecycles with MAE/MFE execution quality, trader archetype discovery, behavioral cohorts, HIP-4 outcome contracts, outcome/perp…

Coinversaa/mcp-server · 161 tokens

blender-mcp

Control Blender directly from Gauss via socket connection to the blender-mcp addon. Create 3D objects, materials, animations, and run arbitrary Blender Python (bpy) code. Use when user wants to create or modify anything in Blender.

math-inc/OpenGauss · 54 tokens