返回 Skill 列表
extension
分类: 开发与工程无需 API Key

discovery.risk_assessment

引入风险的监管或政策义务

person作者: jakexiaohubgithub

Purpose

Enable QA and reliability partners to bring risk thinking into discovery conversations and influence scope decisions early.

Pre-run Checklist

  • ✅ Confirm initial feature concept or brief is available.
  • ✅ Collect historical incidents or bug trends for similar areas.
  • ✅ Align on acceptable risk tolerance with product and engineering.

Invocation Guidance

codex skills run discovery.risk_assessment \
  --vars "feature={{feature}}" \
         "scope={{scope}}" \
         "known_gaps={{known_gaps}}" \
         "compliance_requirements={{compliance_requirements}}"

Recommended Input Attachments

  • Post-incident reports or retrospective documents.
  • Quality dashboards highlighting defect rates or test coverage.

Claude Workflow Outline

  1. Restate the feature scope and critical user journeys.
  2. Categorize risks into functional, non-functional, data, and process buckets.
  3. For each risk, assign impact, probability, detection difficulty, and owner.
  4. Recommend mitigations, including tests, instrumentation, or process changes.
  5. Surface questions or dependencies that need resolution before definition completes.

Output Template

## Risk Overview
...

## Risk Matrix
| Risk | Category | Impact | Probability | Detection | Mitigation | Owner |
| --- | --- | --- | --- | --- | --- | --- |

## Follow-up Questions
1. ...
2. ...

Follow-up Actions

  • Log high risks in the squad RAID register.
  • Schedule risk reviews with security or compliance as needed.
  • Ensure mitigation actions are reflected in planning artifacts.