Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add stanislavnianko/product-discovery-claude-skills --skill risk-assumption-mappinggit clone --depth 1 https://github.com/stanislavnianko/product-discovery-claude-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/stanislavnianko/product-discovery-claude-skills/risk-assumption-mapping)<a href="https://agentmods.dev/skills/stanislavnianko/product-discovery-claude-skills/risk-assumption-mapping"><img src="https://agentmods.dev/badge/skills/stanislavnianko/product-discovery-claude-skills/risk-assumption-mapping/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/stanislavnianko/product-discovery-claude-skills/risk-assumption-mapping"><img src="https://agentmods.dev/badge/skills/stanislavnianko/product-discovery-claude-skills/risk-assumption-mapping.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00077 | $0.01306 |
| Opus 5 | $0.00039 | $0.00653 |
| Sonnet 5 | $0.00015 | $0.00261 |
| Haiku 4.5 | $0.00008 | $0.00131 |
Grade A, and why
risk-assumption-mapping scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 98 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Risk & Assumption Mapping
Part of the discovery-phase skill pack ·
synthesisgroup · readsdiscovery-context.md(runprofile-builderfirst if missing).
Every chosen solution rides on unstated assumptions. This skill makes them visible. In outsourcing, also clarifies whose risk each one is — agency / client / shared — because this drives proposal language and SoW structure.
Step 1 — Read context
Read discovery-context.md (sections 3. Engagement, 6. Constraints — shape what counts as a risk) and opportunity-tree.md (anchors risks to a solution direction).
If discovery-context.md is missing, ask the BA inline: "(a) engagement mode (pre-sale / paid discovery / delivery / staff aug); (b) any regulatory or ethical constraints (GDPR / HIPAA / SOC2 / accessibility floor / none)?" — or proceed tagged [NO-OWNERSHIP] (risks listed flat, not split client/agency/shared). If opportunity-tree.md is missing, ask: "what solution direction are we evaluating, in one line?" — or brainstorm risks against the problem and tag [NO-SOLUTION-FRAME]. Never block; recommend profile-builder / opportunity-mapping for high-stakes work.
Step 2 — Brainstorm by 5 axes
Aim for 2-3 assumptions per axis. If an axis has zero, push harder.
- Desirability — do users actually want this? Will they pay (money / time / political capital)?
- Viability — does this help the client's business? Margin, CAC, retention, strategic fit
- Feasibility — can the agency / client team technically build it? Performance, data, ML accuracy, integration
- Usability — can users figure it out unassisted?
- Ethical / legal — privacy, consent, bias, regulatory (per context section 6), accessibility floor
Step 3 — Score each assumption
| Field | Note |
|---|---|
| Assumption (specific, falsifiable) | "Users will accept a 5-step onboarding" not "users will like onboarding" |
| Impact if wrong (1-5) | 5 = solution doesn't work at all if false |
| Evidence today (1-5) | 1 = pure speculation; 5 = prior production validation |
| Leverage = Impact × (6 − Evidence) | Higher = test first |
| Test method | Spike / PoC / fake-door / paper / data analysis |
| Retire-by signal | Specific observation that confirms safety |
| Kill signal | Specific observation that means "don't build" |
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 98 lines · 77 tokens per session scan A 874b7e3e0953
risk-assumption-mapping is a skill published in the GitHub repository stanislavnianko/product-discovery-claude-skills (1 stars, last pushed 4mo ago), licensed MIT. It adds 77 tokens to every session and 1,306 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
jtbd-extractor
Turn raw research into Jobs-to-be-Done statements showing what users are really trying to accomplish. Use when: extract jobs, jtbd analysis, jobs to be done, what job is the user hiring, underlying user needs.
assumption-mapper
Surfaces the assumptions a product or strategy depends on, classifies them by criticality and evidence quality, and produces a prioritized test plan. Use when: assumption mapping, identify assumptions, what could go wrong, leap-of-faith assumptions, riskiest assumption test, RAT, assumption inventory, validate before…
competitive-analyzer
Structured competitive teardown for product discovery - surface the 4-6 dimensions buyers actually weigh, score every competitor on each, and identify exploitable gaps. Use when: competitive analysis, competitor teardown, market positioning, where do we win, where do we lose, competitive gap analysis, competitor audit.
feedback-prioritizer
Triages a backlog of raw customer feedback into a ranked list of opportunities scored on reach, severity, strategic fit, and confidence. Outputs a prioritized list with explicit "do not act" callouts for vocal-minority signals. Use when: triage feedback, prioritize feature requests, customer feedback backlog, what…
north-star-metric-finder
Identifies a candidate North Star Metric (NSM) for a product - the single metric that captures the value the product delivers to its customers and predicts long-term business growth. Tests candidates against five criteria and surfaces input metrics that move it. Use when: north star metric, NSM, single metric that…
prd-taskmaster
Zero-config goal-to-tasks engine (the Atlas engine). Takes any goal (software, pentest, business, learning), runs adaptive discovery via brainstorming, generates a validated spec, parses into TaskMaster tasks, and hands off to execution. Use when user says "PRD", "product requirements", "I want to build", invokes…