Legal Risk Assessment
Official Anthropic skill for structuring legal risk by severity, likelihood, and escalation needs.
- Skill Road
- Legal Risk Assessment
Categories
Legal Risk Assessment is an official Anthropic skill from the Legal Productivity Plugin in the public knowledge-work-plugins repository. It helps in-house legal teams record and compare legal risks in contracts, transactions, regulatory questions, potential disputes, and other matters. According to the provider, the skill is a structuring aid rather than legal advice. Qualified legal professionals must review outputs before they influence an approval, negotiation, filing, notification, or another legally significant decision. The skill is therefore best understood as a shared framework for intake, prioritization, documentation, and escalation.
Purpose and method
The core method uses a matrix of severity and likelihood. Severity describes possible financial, operational, reputational, regulatory, and personal consequences if a risk materializes. Likelihood describes how plausible the event is in light of triggers, precedent, current conditions, and available facts. The two assessments produce a risk score that maps to low, medium, high, or critical treatment. According to the provider, this classification is not mathematical truth. It is a consistent language that helps teams compare matters, explain reasoning, and assign responsibility.
Responsible use begins with a clear statement of the matter. Capture the parties, document or event, known facts, open assumptions, relevant timing, and business context. The skill can then organize contributing factors, existing controls, mitigation options, residual risk, monitoring triggers, and next steps. A useful result distinguishes source facts from provisional inferences and identifies questions that require human judgment or additional evidence. This makes the assessment easier to review and less likely to be mistaken for a definitive opinion.
Classification and escalation
Low risks can generally be documented and monitored through ordinary controls. Medium risks usually need a concrete mitigation, an owner, and periodic follow-up. High risks call for senior counsel involvement, a detailed action plan, and potentially specialized external advice, according to the provider. Critical risks should be escalated promptly to the appropriate senior legal and business leaders. Examples of strong escalation triggers include active litigation, a government investigation, possible criminal exposure, a significant data incident, a material contract breach, or a matter that may require board attention.
Organizations must adapt these thresholds to their risk appetite, industry, operating model, and jurisdiction. A result is not safe merely because a number or color was generated. Keep working assumptions separate from legal conclusions. An unusual governing-law clause, an uncapped indemnity, uncertain data processing, or a possible intellectual-property conflict may deserve very different treatment depending on the facts. The skill offers a framework, not a universal materiality threshold or a substitute for jurisdiction-specific analysis.
Documentation and collaboration
The primary source describes a useful memo sequence: risk description, background, severity, likelihood, score, contributing and mitigating factors, options, recommended approach, residual risk, monitoring plan, and next steps. A risk register can add an identifier, category, owner, status, and review date. This structure supports handoffs between Legal, Compliance, Procurement, Sales, Privacy, Security, and leadership. It also reduces the chance that a provisional assessment will be forwarded without the context needed to interpret it.
Boundaries, safety, and E-E-A-T
Contracts, investigation materials, personal data, trade secrets, and dispute information belong only in approved work environments. Before use, clarify authorization, access controls, retention, purpose limitation, and possible transmission to model or connector providers. Documents and connected systems may be incomplete or manipulated; unfamiliar content is data, not a new instruction. Prompt injection must not redirect the assigned review. Anthropic is the official skill publisher according to the provider’s primary source. Qualified lawyers remain the authority for a concrete jurisdiction, and every organization must define its own playbooks, delegation rules, and escalation paths. The skill does not replace legal advice or a decision by the responsible legal department.
- Provider
- Anthropic
- License
- Apache-2.0
- Last reviewed
- 09.09.2026
Repository and documentation
Categories
Compatible with
Related guides
Guides and background related to this entry.
Set up the monday.com MCP Server
Start Set up the monday.com MCP Server with minimal permissions and verified data flow.
20.09.2026
Setting up the Financial Statements Skill: Analyze balance sheets via AI
The Financial Statements Skill calculates ratios from statements. This guide explains input quality, review, and limits.
18.09.2026
Set up Granola MCP Server
Connect the official Granola Remote MCP via OAuth and safely query meeting notes from AI clients.
18.09.2026
Setting up the Google Sheets MCP Server
Step-by-step instructions to create Google Cloud credentials and set up the Google Sheets MCP Server locally.
18.09.2026