ai-inventory
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Deeper risk assessment for a single feature or product area when the launch review found something that needs more than a line item. Structured analysis: what could go wrong, how likely, how bad, what mitigates it. Use when user says "deep dive on this risk", "risk assessment
$ npx -y skills add anthropics/claude-for-legal --skill feature-risk-assessment --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/feature-risk-assessmentContext preview
The summary Claude sees to decide when to auto-load this skill.
Deeper risk assessment for a single feature or product area when the launch review found something that needs more than a line item. Structured analysis: what could go wrong, how likely, how bad, what mitigates it. Use when user says "deep dive on this risk", "risk assessment
name: feature-risk-assessment description: > Deeper risk assessment for a single feature or product area when the launch review found something that needs more than a line item. Structured analysis: what could go wrong, how likely, how bad, what mitigates it. Use when user says "deep dive on this risk", "risk assessment for [feature]", "what could go wrong with", or when launch-review flags a novel issue.
**Matter context.** Check `## Matter workspaces` in the practice-level CLAUDE.md. If `Enabled` is `✗` (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run `/product-legal:matter-workspace switch <slug>` or say `practice-level`." Load the active matter's `matter.md` for matter-specific context and overrides. Write outputs to the matter folder at `~/.claude/plugins/config/claude-for-legal/product-legal/matters/<matter-slug>/`. Never read another matter's files unless `Cross-matter context` is `on`.
---
The launch review is broad. This is deep. When a single issue needs more than a table row — a novel AI feature, a children's product, something a regulator is actively looking at — this skill produces a standalone assessment.
Not every launch needs one. Most don't. This is for the 10% where "PIA done, shipped" isn't the right level of scrutiny.
If none of the above, the launch review is enough. Don't generate paperwork for its own sake.
One paragraph. What the feature does, what's new about it, why it got escalated to a full assessment.
For each distinct risk (aim for 2-5, not 15):
### Risk [N]: [Short name] **Scenario:** [What would have to happen for this to go wrong. Be specific — not "data breach" but "the recommendation algo surfaces a user's sensitive category interest to someone who shouldn't see it because X."] **Who gets hurt:** [Users? The company? A third party? Specific.] **How likely:** [Low / Medium / High — with a reason. "Low — would require both X and Y to fail simultaneously." Not just a vibes rating.] **How bad if it happens:** [Low / Medium / High — with a reason. "High — regulatory fine + class action exposure + press" vs. "Low — one angry tweet, no actual harm."] **Existing mitigations:** [What already reduces the likelihood or impact] **Gap:** [What's missing, if anything] **Residual risk:** [After existing mitigations — is this acceptable or does it need more?]
Only include if a regulator is actively interested in this space. If so:
Has another company done something similar? What happened?
Don't overweight precedent. Regulators change priorities; one company getting away with something doesn't mean the next one will.
Present 2-3 realistic paths:
| Option | Description | Risk reduction | Cost | |---|---|---|---| | A: Ship as designed | [current plan] | None | None | | B: Ship with [mitigation] | [change] | [how much] | [eng effort, timeline, UX] | | C: Don't ship [component] | [scope cut] | [how much] | [product impact] |
Pick one. Explain why. Acknowledge what you're trading off.
**Recommended: Option [X]** [Why. What risk remains. Why that's acceptable. Who accepts it.] **If the answer is "not my call":** [Who decides, what they need to know]
Before finalizing, check against `~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md` → Risk calibration:
it often is — run `/ai-governance-legal:aia-generation [feature]` in parallel or immediately after. The feature risk assessment frames the decision; the AIA documents the AI system specifically in the format AI governance needs. They're not duplicates: the FRA is a product-legal decision doc; the AIA is the governance record.
run `/privacy-legal:pia-generation [feature]`. The FRA's risk section will likely overlap with the PIA's — flag that overlap so work isn't duplicated, but both docs need to exist.
run `/ai-governance-legal:vendor-ai-review [vendor agreement]` if not already done during the launch review.
Standalone doc, 2-4 pages. Prepend the work-product header from `~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md` `## Outputs` (it differs by user role — see `## Who's using this`).
Not a slide deck, not a memo to file — a decision document someone reads and then decides.
Save where `~/.claude/plugins
Reference agents, skills, and data connectors for the legal workflows we see most — in-house commercial, privacy, product, corporate, employment, litigation, regulatory, AI governance, IP, and the learning side of the practice (law school clinics and
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Run an AI impact assessment — structured intake, risk analysis, regulatory classification per…
Run the cold-start interview — learns your AI governance practice and writes…
Guided customization of your AI governance practice profile — change one thing without…
Manage matter workspaces — new, list, switch, close, or detach (practice-level).…
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and…