supply-chain-risk-assessor✓ Pass

Comprehensive supply chain risk identification and assessment skill with heat mapping

38out of 100
242
★ stars
13
↓ downloads
76
◉ views

// Install Skill

Install Skill

Skills are third-party code from public GitHub repositories. SkillHub scans for known malicious patterns but cannot guarantee safety. Review the source code before installing.

Install globally (user-level):

npx skillhub install a5c-ai/babysitter/supply-chain-risk-assessor

Install in current project:

npx skillhub install a5c-ai/babysitter/supply-chain-risk-assessor --project

skill.install.customTargetHelp

npx skillhub install a5c-ai/babysitter/supply-chain-risk-assessor --target-dir /path/to/skills

Suggested path: ~/.claude/skills/supply-chain-risk-assessor/

AI Review

38
out of 100
Instruction Quality40
Description Precision25
Usefulness39
Technical Soundness55

Babysitter pattern — well-structured YAML schemas for risk assessment but purely conceptual. No scripts, no calculations, no heat map generation code. Reads as a specification, not a working tool.

prototypemoderatesupply-chain-managersrisk-analystsrisk-assessmentsupply-chain-risk
Reviewed by claude-code on 3/21/2026

SKILL.md Content

---
name: supply-chain-risk-assessor
description: Comprehensive supply chain risk identification and assessment skill with heat mapping
allowed-tools:
  - Read
  - Write
  - Glob
  - Grep
  - Bash
metadata:
  specialization: supply-chain
  domain: business
  category: risk-management
  priority: high
---

# Supply Chain Risk Assessor

## Overview

The Supply Chain Risk Assessor provides comprehensive risk identification, assessment, and visualization capabilities for supply chain risk management. It supports structured risk categorization, probability-impact analysis, heat mapping, and control effectiveness evaluation.

## Capabilities

- **Risk Category Taxonomy**: Financial, operational, geopolitical, compliance categorization
- **Probability and Impact Assessment**: Likelihood and consequence scoring
- **Risk Score Calculation and Ranking**: Prioritized risk listing
- **Heat Map Visualization**: Visual risk representation
- **Root Cause Analysis Integration**: Risk driver identification
- **Risk Appetite Alignment**: Threshold and tolerance management
- **Control Effectiveness Evaluation**: Mitigation effectiveness assessment
- **Risk Register Maintenance**: Centralized risk documentation

## Input Schema

```yaml
risk_assessment_request:
  scope:
    categories: array             # supplier, logistics, demand, etc.
    geography: array
    time_horizon: string
  risk_inputs:
    identified_risks: array
      - risk_name: string
        category: string
        description: string
        probability: float        # 1-5 scale
        impact: float             # 1-5 scale
        velocity: string          # slow, medium, fast
    historical_incidents: array
    external_factors: array
  controls:
    existing_controls: array
    control_effectiveness: object
  risk_appetite: object
```

## Output Schema

```yaml
risk_assessment_output:
  risk_register:
    risks: array
      - risk_id: string
        name: string
        category: string
        description: string
        probability: float
        impact: float
        risk_score: float
        risk_level: string        # Low, Medium, High, Critical
        root_causes: array
        controls: array
        control_effectiveness: string
        residual_risk: float
        owner: string
        mitigation_status: string
  heat_map:
    visualization_data: object
    distribution: object
  summary:
    total_risks: integer
    by_category: object
    by_level: object
    trends: object
  recommendations: array
  action_plan: array
```

## Usage

### Comprehensive Risk Assessment

```
Input: Supply chain scope, identified risks, historical incidents
Process: Score risks, calculate rankings, generate heat map
Output: Complete risk assessment with prioritized register
```

### Category-Specific Analysis

```
Input: Supplier category risks, control inventory
Process: Deep-dive risk analysis for supplier domain
Output: Supplier risk profile with mitigation priorities
```

### Control Effectiveness Review

```
Input: Current controls, incident data, audit findings
Process: Evaluate control performance, identify gaps
Output: Control effectiveness report with recommendations
```

## Integration Points

- **Risk Management Systems**: GRC platforms
- **Incident Management**: Historical event data
- **Supplier Systems**: Supplier risk inputs
- **Tools/Libraries**: Risk frameworks, FMEA templates, visualization

## Process Dependencies

- Supply Chain Risk Assessment
- Supplier Risk Monitoring and Early Warning
- Business Continuity and Contingency Planning

## Best Practices

1. Conduct comprehensive risk identification workshops
2. Use consistent probability-impact scales
3. Validate assessments with subject matter experts
4. Review and update risk register quarterly
5. Link risks to business objectives
6. Communicate risk status to leadership regularly

License

Declared license: MIT

MIT License

Copyright (c) 2026 a5c-ai

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

View the license in the source repository — the version published there is authoritative.