risk-taxonomy — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited risk-taxonomy (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Every risk surfaced from a deal must be classified along five dimensions. Narrative-only risk lists fail the verifier-stack standard.
<$1M / $1-5M / $5-25M / $25-100M / >$100MFinancial — revenue concentration, working capital deterioration, covenant breach risk, deferred revenue recognition, related-party transactions, material weakness in controls, going concern, off-balance-sheet liabilities, tax exposure, ASC 606 misapplication
Commercial — customer concentration (>20% from one customer = High), pricing pressure, churn acceleration, market saturation, competitive moat erosion, channel partner dependency, regulatory exposure on revenue model
Operational — key-person risk, supply chain single-source, supplier concentration, manufacturing capacity, IT system fragility, cyber incident exposure, regulatory compliance gap, key contract auto-renewal exposure
Legal/Regulatory — pending litigation, regulatory investigation, IP infringement claims, employment class actions, environmental liability, antitrust scrutiny, change-of-control restrictions, indemnity caps inadequate
Strategic — technology disruption, business-model obsolescence, integration risk (for acquirer), retention of key contracts post-close, customer migration to competitor
Some categories materially shift severity by industry. The taxonomy carries industry overlays for SaaS, manufacturing, healthcare, services, retail, and financial services:
Every risk surfaced should look like this:
- Family: Financial
Category: Revenue concentration
Severity: 8 (High)
Likelihood: High
Impact: $5-25M
Description: Top customer 28% of revenue with no long-term contract
Source: 10-K p.14, Risk FactorsNever surface a risk without categorization. If you cannot classify a risk, the right output is "I observed a potential risk but could not classify it under the 246-category framework. The category that may apply is X; the missing input that would let me classify it is Y."
Narrative risks ("the company faces competitive pressure") are insufficient. Always:
source-hierarchy skill for ranking)This is what makes a risk register useful in an IC meeting — not the prose around it.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.