Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add vivy-yi/finance-skills --skill strategic-risk-assessmentgit clone --depth 1 https://github.com/vivy-yi/finance-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vivy-yi/finance-skills/strategic-risk-assessment)<a href="https://agentmods.dev/skills/vivy-yi/finance-skills/strategic-risk-assessment"><img src="https://agentmods.dev/badge/skills/vivy-yi/finance-skills/strategic-risk-assessment/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/vivy-yi/finance-skills/strategic-risk-assessment"><img src="https://agentmods.dev/badge/skills/vivy-yi/finance-skills/strategic-risk-assessment.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00091 | $0.02058 |
| Opus 5 | $0.00046 | $0.01029 |
| Sonnet 5 | $0.00018 | $0.00412 |
| Haiku 4.5 | $0.00009 | $0.00206 |
Grade A, and why
strategic-risk-assessment scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 230 lines — stays where its author put it; the contents beside it link to each section on GitHub.
加载上下文
首次使用时: 读取 ../../CLAUDE.md 获取场景级配置(风险偏好/风险容忍度/战略背景)。
/strategic-risk-assessment — 战略风险评估
Examples
→ 示例:用户说"年度战略回顾,需要对主要战略风险做一次评估更新",系统应调用本技能,执行年度战略风险评估更新。
→ 示例:用户说"进入新市场有哪些主要风险,帮我做个系统性评估",系统应调用本技能,按战略风险框架评估市场进入风险。
→ 示例:用户说"大客户流失风险在上升,帮我评估对 3 年规划的影响",系统应调用本技能,执行客户集中度风险评估。
第一步:风险识别
风险来源分类框架:
□ 宏观风险:
→ 经济风险:[GDP/通胀/汇率/利率]
→ 政策风险:[监管/税收/产业/贸易]
→ 地缘风险:[区域冲突/制裁/供应链]
□ 行业风险:
→ 市场风险:[需求/供给/价格]
→ 技术风险:[颠覆性创新/技术路线]
→ 竞争风险:[新进入者/替代品/竞争对手]
□ 内部能力风险:
→ 资金链风险:[融资/流动性]
→ 人才风险:[关键人才/组织能力]
→ 执行风险:[战略执行/运营效率]
风险识别方法:
□ 信息来源:
→ PEST 分析:[已完成/需更新/未执行]
→ 波特五力分析:[已完成/需更新/未执行]
→ 内部分析(能力/资源):[已完成/需更新/未执行]
→ 历史风险事件:[列表]
□ 参与人员:
→ 高管访谈:[已完成/计划中]
→ 业务单元反馈:[已完成/计划中]
→ 外部顾问意见:[已完成/计划中]
第二步:风险评估
风险评级矩阵:
风险值 = 影响度 × 可能性
影响度(1-5):
1 = 轻微(< [X] 万,战略影响微弱)
3 = 中等([X-X] 万,部分战略目标受影响)
5 = 严重(> [X] 万,战略目标无法实现)
可能性(1-5):
1 = 极低(< 5%,基本不会发生)
3 = 中等(20-40%,有一定可能)
5 = 极高(> 80%,很可能发生)
风险等级:
15-25:🔴 重大风险(须立即应对)
8-14:🟡 中等风险(须监控和应对)
1-7:⚪ 低风险(可接受或监控)
风险评估结果:
| # | 风险描述 | 类别 | 影响度 | 可能性 | 风险值 | 等级 |
|---|---------|------|--------|--------|--------|------|
| 1 | [描述] | [宏观] | [5] | [4] | [20] | 🔴 |
| 2 | [描述] | [行业] | [3] | [4] | [12] | 🟡 |
| 3 | [描述] | [能力] | [4] | [2] | [8] | 🟡 |
□ 高风险项(风险值 ≥ 15):[X] 项
□ 中风险项(风险值 8-14):[X] 项
□ 低风险项(风险值 < 8):[X] 项
第三步:风险应对策略
风险应对选项:
□ 规避(Avoid):退出该业务/市场,消除风险源
□ 转移(Transfer):保险/对冲/分包/合资
□ 减轻(Reduce):采取措施降低影响或可能性
□ 接受(Accept):acknowledged 风险,准备应急计划
高风险项应对方案:
□ 风险 1:[描述]
→ 当前风险值:[20](🔴 重大)
→ 建议应对策略:[减轻]
→ 具体措施:
· [措施1] — 责任人 [X] — 完成 [日期]
· [措施2] — 责任人 [X] — 完成 [日期]
→ 预期效果:风险值从 [20] 降至 [12]
→ 残余风险:[X](措施后的残余值)
□ 风险 2:[描述]
→ ...
风险容忍度检查:
□ 风险容忍度定义:
→ 财务风险容忍度:[X](最大可接受风险值)
→ 战略风险容忍度:[X]
→ 合规风险容忍度:[X]
□ 超容忍度风险:[X] 项
→ [风险名称] — 风险值 [X] vs 容忍度 [X]
第四步:风险监控机制
风险监控指标:
□ 关键风险指标(KRI):
| 风险 | 监控指标 | 当前值 | 预警阈值 | 触发条件 |
|------|---------|--------|---------|---------|
| [风险1] | [指标] | [X] | [X] | [条件] |
| [风险2] | [指标] | [X] | [X] | [条件] |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 230 lines · 91 tokens per session scan A 4ff2a15ba00a
strategic-risk-assessment is a skill published in the GitHub repository vivy-yi/finance-skills (29 stars, last pushed 3mo ago), licensed MIT. It adds 91 tokens to every session and 2,058 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
infographics
Create professional infographics using Nano Banana Pro AI with smart iterative refinement. Uses Gemini 3 Pro for quality review. Integrates research-lookup and web search for accurate data. Supports 10 infographic types, 8 industry styles, and colorblind-safe palettes.
similarity-search-patterns
Implement efficient similarity search with vector databases. Use when building semantic search, implementing nearest neighbor queries, or optimizing retrieval performance.
figma-implement-design
Translate Figma nodes into production-ready code with 1:1 visual fidelity using the Figma MCP workflow (design context, screenshots, assets, and project-convention translation). Trigger when the user provides Figma URLs or node IDs, or asks to implement designs or components that must match Figma specs. Requires a…
datavis
Comprehensive data visualization toolkit for creating beautiful, mathematically elegant visualizations with D3.js, Chart.js, and custom SVG. Use when (1) building interactive data visualizations, (2) designing color palettes for charts, (3) choosing scales and visual encodings, (4) creating data pipelines from…
spec-kit-vibe-compat
Compatibility router for /speckit. workflows into /vibe-first Codex execution.
detecting-data-anomalies
Investigate outliers, rare events, spikes, and suspicious records in datasets. Use as an explicit anomaly-analysis helper when you want concrete anomaly-detection workflow guidance, not generic data validation or end-to-end ML ownership.