Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zhou210712/claude-for-legal-ZH --skill feature-risk-assessmentgit clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZHWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/feature-risk-assessment)<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/feature-risk-assessment"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/feature-risk-assessment/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/feature-risk-assessment"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/feature-risk-assessment.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00099 | $0.02301 |
| Opus 5 | $0.00049 | $0.01151 |
| Sonnet 5 | $0.00020 | $0.00460 |
| Haiku 4.5 | $0.00010 | $0.00230 |
Grade A, and why
feature-risk-assessment scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 147 lines — stays where its author put it; the contents beside it link to each section on GitHub.
功能风险评估
事项上下文
事项上下文。 检查实务级 CLAUDE.md 中的 ## 事项工作空间。如果 Enabled 为 ✗(企业法务用户的默认值),跳过本段其余内容——技能使用实务级上下文,事项机制不可见。如果已启用且无活跃事项,询问:"这是哪个事项?运行 /product-legal:matter-workspace switch <事项简称> 或说 实务级。"加载活跃事项的 matter.md 获取事项特定上下文和覆盖规则。输出写入事项文件夹 ~/.claude/plugins/config/claude-for-legal/product-legal/matters/<事项简称>/。除非 跨事项上下文 为 开,否则绝不读取其他事项的文件。
目的
上线审查是广度。这是深度。当单个议题需要超出表格行的分析——一个新型AI功能、一个儿童产品、一个监管机构正在积极关注的事项——本技能产出一份独立的评估。
不是每次上线都需要。大多数不需要。这是给那10%的,其中"做完个人信息保护影响评估,上线"的审查深度不够。
何时运行
- 上线审查发现一个不在校准表中的模式(全新)
- 上线审查发现**"通常阻断"**类别中的某项
- 法务负责人或领导层问"这里有什么风险"且需要的不是一句话
- 功能处于监管积极关注的领域(AI、儿童、生物特征、健康、金融)
- 法律团队外部有人担心,结构化的回答会有所帮助
如果以上都不满足,上线审查就足够了。不要为自身目的生成文书工作。
结构
1. 我们评估什么
一段话。功能做什么、新在哪里、为什么被升级到完整评估。
2. 风险
对每个独立风险(目标是2-5个,不是15个):
### 风险[N]:[简短名称]
**场景:**[需要发生什么才会导致出问题。要具体——不是"数据泄露"
而是"推荐算法因X将用户的敏感类别兴趣展示给了不该看到的人。"]
**谁受伤害:**[用户?公司?第三方?要具体。]
**可能性多大:**[低/中/高——附理由。"低——需要X和Y同时失效。"
不只是感觉评分。]
**如果发生有多严重:**[低/中/高——附理由。"高——
行政处罚+集团诉讼暴露+媒体报道"vs."低——一条愤怒的微博,无实际损害。"]
**现有缓解措施:**[已经降低可能性或影响的措施]
**缺口:**[还缺什么,如果有]
**剩余风险:**[在现有缓解措施之后——这是可接受还是需要更多?]
3. 监管环境(如相关)
仅当有监管机构对此领域有积极关注时才包含。如有:
- 哪个监管机构,他们最近说了什么/做了什么
- 此功能在他们看来如何
- 我们是希望他们从我们这里听到还是从一篇头条新闻中听到
在中国法语境下,关注市场监管总局、国家互联网信息办公室、工业和信息化部、公安部门及其他行业监管机构最近的执法动态和指引。
4. 先例(如有)
其他公司做过类似的事吗?发生了什么?
- 如果没出什么问题 → 有用,但不具有决定性
- 如果出了问题 → 他们的情况有什么不同,这里是否适用
不要高估先例。监管机构会变换优先级;一家公司侥幸过关不意味着下一家也会。
5. 选项
呈现2-3条现实路径:
| 选项 | 描述 | 风险降低 | 成本 |
|---|---|---|---|
| A:按设计上线 | [当前计划] | 无 | 无 |
| B:上线并增加[缓解措施] | [改动] | [多少] | [开发工作量、时间、用户体验] |
| C:不上线[组件] | [砍范围] | [多少] | [产品影响] |
6. 建议
选一个。解释理由。承认您正在做何种权衡。
**建议:选项[X]**
[理由。剩余什么风险。为什么可接受。谁接受。]
**如果答案是"非我能定":**[谁决定,他们需要知道什么]
校准检查
定稿前,对照 ~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md → 风险校准检查:
- 这份风险评估是针对这家公司校准的,还是泛泛的?
- 对处于承诺整改协议下的公司可能是"高"风险,对不在该情况下的公司可能是"中"
- 评估应反映实务画像中记载的实际监管环境、诉讼历史和风险偏好
交接
- 转AI治理: 如果深度评估由AI功能触发——这很常见——同时或紧接着运行
/ai-governance-legal:aia-generation [功能]。功能风险评估搭建决策框架;算法安全评估以AI治理所需的格式具体记录AI系统。两者不重复:FRA是产品法务决策文件;算法安全评估是治理记录。 - 转个人信息保护: 如果功能涉及新的数据采集或处理,运行
/privacy-legal:pia-generation [功能]。FRA的风险节可能与个人信息保护影响评估重叠——标记该重叠以避免重复工作,但两份文件都需要存在。 - 转AI治理供应商审查: 如果功能使用新的AI供应商,运行
/ai-governance-legal:vendor-ai-review [供应商协议],如在上线审查时尚未完成。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 147 lines · 99 tokens per session scan A 71d00e59b5d0
feature-risk-assessment is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 99 tokens to every session and 2,301 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…