Token导航 LogoToken导航TokenDH.com
运维和基础设施需要联网github未标认证来源可访问许可证需确认审计通过

legal-risk-scoring法律风险评分

Agent Skill

legal-risk-scoring 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

423

周安装

18

GitHub Stars

55

下载量

148
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:legal-risk-scoring(法律风险评分)
来源仓库:https://github.com/vm0-ai/vm0-skills
仓库路径:skills/legal-risk-scoring
安装命令:
npx skills add https://github.com/vm0-ai/vm0-skills --skill legal-risk-scoring
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/vm0-ai/vm0-skills --skill legal-risk-scoring

简介

评估法律风险并输出综合评分与处置建议矩阵。legal-risk-scoring 属于运维和基础设施类 Skill,可作为该场景下的辅助能力补充。

  • 适用于 Codex、Claude 等宿主中处理基础设施类任务。
  • 通过 GitHub 安装,依赖本地配置与风险参数定义。
  • 使用前需初始化风险偏好阈值与责任人映射表。
  • 维护状态未说明,评分模型可能随政策变化失效。

SKILL.md

Scoring Model

Two-Axis Evaluation Grid

Every legal risk is measured across two independent axes:

Impact Magnitude (consequences if the risk becomes reality):

RatingDescriptorMeaning
1TrivialMinimal disruption; no meaningful financial, operational, or reputational consequence. Absorbed within day-to-day operations.
2MinorContained impact; financial exposure under 1% of the relevant contract or transaction value; brief operational hiccup; no public visibility.
3SubstantialTangible impact; financial exposure in the 1-5% range of relevant value; noticeable operational interference; possibility of limited external attention.
4SeriousMajor impact; financial exposure between 5-25% of relevant value; significant operational disruption; probable public scrutiny; potential for regulatory interest.
5SevereExistential-level impact; financial exposure exceeding 25% of relevant value; core business operations threatened; material reputational harm; regulatory action anticipated; potential personal exposure for directors and officers.

Occurrence Probability (how likely the risk is to materialize):

RatingDescriptorMeaning
1NegligibleEssentially theoretical; no known precedent in comparable situations; would demand extraordinary circumstances.
2LowConceivable but not anticipated; sparse precedent; requires specific precipitating events.
3ModeratePlausible; some analogous situations have materialized; precipitating conditions are foreseeable.
4ElevatedExpected to happen; clear precedent exists; precipitating conditions are commonplace in analogous contexts.
5Near CertainVirtually guaranteed; strong historical pattern; precipitating conditions are already present or imminent.

Computing the Score

Risk Score = Impact Magnitude x Occurrence Probability

Score BandCategoryIndicator
1-4Baseline RiskGREEN
5-9Intermediate RiskYELLOW
10-15Elevated RiskORANGE
16-25Acute RiskRED

Visual Grid

                     OCCURRENCE PROBABILITY
               Negligible  Low   Moderate  Elevated  Near Certain
                  (1)      (2)     (3)       (4)        (5)
IMPACT
Severe    (5) |   5    |   10   |   15   |   20   |     25     |
Serious   (4) |   4    |    8   |   12   |   16   |     20     |
Substantial(3)|   3    |    6   |    9   |   12   |     15     |
Minor     (2) |   2    |    4   |    6   |    8   |     10     |
Trivial   (1) |   1    |    2   |    3   |    4   |      5     |

Category Profiles and Response Protocols

GREEN -- Baseline Risk (Score 1-4)

Profile:

  • Low-consequence issues with negligible probability
  • Routine operational risks with well-established controls already in place
  • Familiar risk patterns that the organization regularly manages

Protocol:

  • Accept: Proceed with existing controls in place
  • Log: Enter into the risk register for ongoing visibility
  • Periodic check: Revisit during quarterly or annual review cycles
  • No escalation: The responsible team member manages independently

Typical scenarios:

  • Vendor agreement with a small deviation from preferred terms in a non-material area
  • Standard confidentiality agreement with a reputable counterparty in a familiar jurisdiction
  • Routine administrative compliance task with a clear owner and deadline

YELLOW -- Intermediate Risk (Score 5-9)

Profile:

  • Issues of moderate consequence that could arise under realistic conditions
  • Risks deserving active attention without requiring emergency response
  • Situations where precedent provides a management roadmap

Protocol:

  • Reduce exposure: Deploy targeted controls or negotiate improved terms
  • Active surveillance: Review monthly or upon occurrence of defined trigger events
  • Thorough documentation: Capture the risk, all mitigation steps, and decision rationale in the register
  • Designated owner: A specific individual holds accountability for tracking and mitigation
  • Stakeholder communication: Relevant business contacts are informed of the risk and the mitigation approach
  • Escalation triggers: Define specific conditions that would push this risk to a higher category

Typical scenarios:

  • Agreement with a liability ceiling below the preferred level but within a negotiable range
  • Vendor processing personal data in a territory with uncertain adequacy status
  • Regulatory development that may affect a business line over the medium term
  • IP provision that is broader than optimal but consistent with market practice

ORANGE -- Elevated Risk (Score 10-15)

Profile:

  • Weighty issues with a realistic chance of materializing
  • Risks capable of producing significant financial, operational, or public-facing harm
  • Situations demanding senior-level attention and structured mitigation

Protocol:

  • Senior counsel involvement: Brief the head of legal or designated senior attorney
  • Structured mitigation plan: Build a concrete, time-bound plan to reduce the risk
  • Leadership awareness: Ensure relevant business leaders understand the risk and the recommended path
  • Frequent review: Weekly check-ins or milestone-based reassessment
  • External counsel assessment: Engage outside specialists for domain-specific guidance as warranted
  • Detailed written analysis: Produce a full risk memorandum covering analysis, alternatives, and recommendations
  • Contingency planning: Define the response playbook if the risk materializes

Typical scenarios:

  • Agreement containing uncapped indemnification in a material obligation area
  • Data processing operation that may violate regulatory requirements without restructuring
  • Credible litigation threat from a significant counterparty
  • Intellectual property infringement allegation with a plausible basis
  • Formal regulatory inquiry or audit notification

RED -- Acute Risk (Score 16-25)

Profile:

  • The most consequential issues, with high or near-certain probability of materializing
  • Risks that threaten fundamental business viability, expose officers and directors, or endanger key stakeholders
  • Demands immediate executive engagement and rapid mobilization

Protocol:

  • Immediate executive briefing: Notify General Counsel, C-suite, and Board as the situation warrants
  • Outside counsel retention: Engage specialized external lawyers without delay
  • Dedicated response team: Stand up a cross-functional team with clearly defined roles and authority
  • Insurance notification: Alert carriers where coverage may apply
  • Crisis protocols: Activate crisis management procedures when reputational exposure exists
  • Evidence preservation: Institute a litigation hold if legal proceedings are a possibility
  • Continuous monitoring: Daily or more frequent status reviews until resolved or downgraded
  • Board-level reporting: Include in governance risk reporting as appropriate
  • Regulatory communication: File any mandatory regulatory notifications

Typical scenarios:

  • Pending litigation with substantial financial exposure
  • Personal data breach affecting regulated information
  • Active regulatory enforcement proceeding
  • Material breach of or against the organization under a significant contract
  • Government investigation
  • Infringement claim targeting a core product or revenue-generating service

Formal Documentation Standards

Risk Assessment Memorandum

Every formal evaluation should follow this structure:

## Legal Risk Evaluation

**Prepared**: [date]
**Analyst**: [name of person conducting the evaluation]
**Subject**: [description of the matter under review]
**Privilege designation**: [Yes/No -- mark as attorney-client privileged where applicable]

### 1. Risk Statement
[Precise, concise articulation of the legal risk]

### 2. Factual Background
[Relevant facts, chronology, and business context]

### 3. Scoring Analysis

#### Impact Magnitude: [1-5] - [Descriptor]
[Supporting rationale including potential financial exposure, operational consequences, and reputational dimensions]

#### Occurrence Probability: [1-5] - [Descriptor]
[Supporting rationale including precedent, triggering conditions, and current circumstances]

#### Composite Score: [Number] - [GREEN/YELLOW/ORANGE/RED]

### 4. Aggravating Factors
[Elements that amplify the risk]

### 5. Countervailing Factors
[Elements that dampen the risk or contain exposure]

### 6. Mitigation Alternatives

| Alternative | Effectiveness | Resource Demand | Recommended? |
|---|---|---|---|
| [Option A] | [High/Med/Low] | [High/Med/Low] | [Yes/No] |
| [Option B] | [High/Med/Low] | [High/Med/Low] | [Yes/No] |

### 7. Recommended Course of Action
[Specific recommendation with supporting rationale]

### 8. Post-Mitigation Risk Level
[Projected risk category after implementing recommended measures]

### 9. Ongoing Monitoring Plan
[Frequency and method of review; conditions that would trigger reassessment]

### 10. Immediate Next Steps
1. [Task - Responsible party - Due date]
2. [Task - Responsible party - Due date]

Risk Register Format

For entry into the team's centralized risk tracker:

FieldContent
IdentifierUnique tracking code
Discovery DateWhen the risk first came to light
SummaryBrief characterization
DomainContract / Regulatory / Litigation / IP / Data Privacy / Employment / Corporate / Other
Impact Rating1-5 with descriptor
Probability Rating1-5 with descriptor
Composite ScoreCalculated value
CategoryGREEN / YELLOW / ORANGE / RED
Accountable PersonIndividual responsible for monitoring
Active ControlsMitigations currently deployed
DispositionOpen / Mitigated / Accepted / Closed
Next ReviewScheduled reassessment date
RemarksSupplementary context

Criteria for Engaging Outside Counsel

Situations Requiring External Representation

  • Filed litigation: Any lawsuit brought by or against the organization
  • Government proceedings: Any inquiry from a regulatory agency, government body, or law enforcement
  • Criminal risk: Any scenario involving potential criminal liability for the entity or its people
  • Capital markets implications: Any matter that could affect securities disclosures or regulatory filings
  • Governance-level matters: Any issue necessitating board notification or board-level approval

Situations Strongly Favoring External Engagement

  • Uncharted legal territory: Questions lacking settled authority where the organization's position could establish precedent
  • Multi-jurisdictional complexity: Matters spanning unfamiliar or conflicting legal regimes
  • Outsized financial stakes: Exposure exceeding the organization's defined risk appetite thresholds
  • Specialist knowledge gaps: Subject areas not covered by in-house expertise (antitrust, anti-corruption, patent prosecution, etc.)
  • Major regulatory shifts: New legal frameworks that require compliance program construction or significant adaptation
  • Strategic transactions: Mergers, acquisitions, or major deals requiring diligence, structuring, and regulatory clearance

Situations Worth Evaluating for External Support

  • Significant contractual disputes: Substantial disagreements over interpretation with important business partners
  • Workforce claims: Actual or threatened claims involving discrimination, harassment, wrongful termination, or retaliation
  • Data security events: Incidents that may trigger mandatory notification duties
  • IP conflicts: Infringement allegations (inbound or outbound) involving material products or services
  • Coverage disagreements: Disputes with insurance carriers over claim coverage

Selecting the Right Firm

When recommending outside engagement, prompt the user to weigh:

  • Subject matter depth and track record
  • Familiarity with the relevant jurisdiction
  • Industry sector experience
  • Conflict clearance status
  • Fee structure expectations (hourly, flat, blended, contingency)
  • Firm diversity commitments
  • Pre-existing relationships (panel membership, prior engagements)

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

33.43%
按下载量换算49

Claude

31.83%
按下载量换算47

Cursor

20.62%
按下载量换算31

Gemini CLI

8.93%
按下载量换算13

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills