enterprise-risk skillA
enterprise-risk is agent-read markdown (skill) from cbrock84/headcount: Identifies, assesses, and tracks organizational risk — building and maintaining a risk register, scoring exposure, assigning owners and treatments, and preparing for audit. Use this to stand up a risk program, assess the risk in a decision or initiative, prepare for a certification or audit, decide whether a risk should be accepted, mitigated, transferred, or avoided, or report risk posture to leadership..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Enterprise risk ## The register is the artifact A risk that is not written down with an owner is not managed. Each entry carries: - **The risk stated as a cause and consequence** — "if X happens, then Y." "Cybersecurity" is a category, not a risk. "If an employee's credentials are phished, an attacker reaches customer records" is a risk you can do something about. - **Likelihood and impact**, on a stated scale, with the reasoning. The reasoning matters more than the score. - **Current controls** and an honest view of whether they work. - **Residual risk** after those controls — the number that actually matters and the one most often omitted. - **A named owner.** A person, not a department. - **Treatment and a date.** ## Treatment is a decision with four options **Mitigate** (reduce it), **transfer** (insure or contract it away), **avoid** (do not do the thing), or **accept**. Accepting is legitimate and often correct — but acceptance must be explicit, at the right level of authority, and recorded. Risk accepted by silence is risk nobody owns. Anything above the threshold that only the chief executive can accept goes to them. Never let an …
Read the whole file at its exact version.
How to install
mdr add cbrock84/headcount/enterprise-risk@git:20260916.0e7cd01mdr add cbrock84/headcount/enterprise-risk@sha256:4d7363c799fe0fe2Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_q23iz5dqtdfn4wsi)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260916.0e7cd01 latest | 2026-09-16 | 0e7cd01 | 3,799 B | A | view · diff |
| git:20260901.0757404 | 2026-09-01 | 0757404 | 3,460 B | A | view · diff |
| git:20260901.aa45383 | 2026-09-01 | aa45383 | 2,996 B | A | view · diff |
| git:20260828.f80dcb5 | 2026-08-28 | f80dcb5 | 2,690 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (3799 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
cbrock84/headcount · 1,664 stars · license MIT · pushed 2026-09-17 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_q23iz5dqtdfn4wsi GET https://markdownregistry.com/api/v1/resolve?ref=cbrock84/headcount/enterprise-risk GET https://markdownregistry.com/api/v1/blob/4d7363c799fe0fe213d15153bdebfcdbe97ba9bea2ff981f29a85c04fe858a9d
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.