Skip to content
Security
Skill

/tech-risk-assessment

Assess the security risk of a technology or product decision for leadership — new technology/vendor adoption, build-vs-buy, third-party/supply-chain, or M&A technical due diligence — and give a clear recommendation with trade-offs. Use to inform a strategic technology decision.

From plugin
awesome-claude-security
6111 skills17 agents13 commands1 MCP
Install
$ npx -y skills add jassics/awesome-claude-security --skill tech-risk-assessment --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/tech-risk-assessment

Context preview

The summary Claude sees to decide when to auto-load this skill.

Assess the security risk of a technology or product decision for leadership — new technology/vendor adoption, build-vs-buy, third-party/supply-chain, or M&A technical due diligence — and give a clear recommendation with trade-offs. Use to inform a strategic technology decision.

SKILL.md

tech-risk-assessment.SKILL.md
name: tech-risk-assessment
description: >-
  Assess the security risk of a technology or product decision for leadership — new
  technology/vendor adoption, build-vs-buy, third-party/supply-chain, or M&A
  technical due diligence — and give a clear recommendation with trade-offs. Use to
  inform a strategic technology decision.

Goal

A decision-ready security risk assessment of the option(s) under consideration, with a recommendation that weighs security against velocity, cost, and strategic fit.

Steps

1. **Frame the decision** — what's being decided (adopt X / build vs. buy / acquire Y), the options, the data/systems involved, and the decision criteria. 2. **Assess each option's security posture:**

  • **Build** — can we build and operate it securely? cost of doing so, our maturity.
  • **Buy / adopt** — vendor security posture, certifications/attestations, data

handling and residency, integration and access scope, lock-in, and exit.

  • **Third-party / supply-chain risk** — dependencies, provenance, and the blast

radius if the vendor/component is compromised.

  • **M&A due diligence** — target's security posture, debt, incident history,

compliance exposure, and integration risk. 3. **Assess integration & data risk** — trust boundaries created, data exposure, identity/access, and the new attack surface (`threat-modeling`). 4. **Total cost incl. security** — build/operate/secure cost over time, not just license/sticker. 5. **Recommend** — a clear call with the risk trade-offs, required conditions/ mitigations, and residual risk stated honestly.

Output

A tech-risk assessment: decision · options · per-option security posture · third- party/integration/data risk · total cost incl. security · recommendation + conditions

  • residual risk. Use `security-reporting`; diagram integration/trust boundaries with

`security-diagramming`.

Notes

Decide with explicit trade-offs, not security absolutism — the goal is the best risk-adjusted technology choice for the business. Weight third-party/supply-chain and exit/lock-in risk; they're routinely underestimated. State residual risk and the conditions under which the recommendation holds.

Read more
Ships withawesome-claude-security

A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.

Get the whole plugin

Other skills on awesome-claude-security.