Manage the risk knowledge base repository for Copilot-driven risk assessment. Use when adding new domains (features), recording incidents, updating risks, or modifying the knowledge-map index...
Unified skill for maintaining the risk knowledge base. Handles domain creation, incident recording, risk updates, and index synchronization.
βββ indexes/knowledge-map.yml # Keyword β file routing (MUST update)
βββ common-risks/ # Cross-cutting risks (security, performance, availability)
βββ domains/{name}/ # Domain-specific knowledge
β βββ spec.md # Feature specification
β βββ risks.md # Domain-specific risks
βββ incidents/ # Past incident records
User Request
β
ββ "Add new domain/feature" βββββββΊ Add Domain Workflow
β
ββ "Record incident" ββββββββββββββΊ Add Incident Workflow
β
ββ "Add/update risk" ββββββββββββββΊ Update Risk Workflow
β
ββ "Update common risk" βββββββββββΊ Update Common Risk Workflow
When user wants to add a new feature/domain (e.g., "notification", "search"):
Validate uniqueness
domains/ for existing folderindexes/knowledge-map.yml for duplicate domain_name or keywordsCollect information (ask if not provided)
Create files using templates from references/templates.md
domains/{name}/spec.mddomains/{name}/risks.mdUpdate index - Add entry to indexes/knowledge-map.yml:
- domain_name: "葨瀺ε (English)"
description: "..."
keywords: [...]
related_files:
common_risks: [...]
domain_knowledge:
- "domains/{name}/spec.md"
- "domains/{name}/risks.md"
Verify - Confirm all paths in knowledge-map.yml exist
When user reports a past incident:
Collect information
Create incident file
incidents/YYYY-short-description.mdreferences/templates.mdUpdate related risks
Related Incident link to relevant domains/{name}/risks.mdBidirectional linking
When adding or modifying a risk in existing domain:
Locate target file
domains/{name}/risks.mdcommon-risks/{category}.mdCheck for duplicates
Add/update risk entry with required fields:
**Details**: What can go wrong**Countermeasures**: How to prevent/mitigate**Severity**: Critical/High/Medium/Low**Related Incident**: Link if applicableUpdate knowledge-map.yml keywords if new terms should trigger this domain
For cross-cutting risks (security, performance, availability):
Identify category from common-risks/:
security.md - Injection, auth bypass, data exposureperformance.md - N+1, memory, connection exhaustionavailability.md - Service outage, login failureAdd/update risk following existing format
Check domain linkage - Ensure relevant domains reference this common risk in knowledge-map.yml
Before completing any operation, run validation checks:
Use provided scripts for comprehensive validation:
# Full validation (recommended)
python scripts/validate_knowledge.py
# Check bidirectional links only
python scripts/check_links.py
When to validate:
Validation checks:
See references/validation-rules.md for detailed rules.
Three utility scripts are provided in scripts/ directory:
Comprehensive validation of entire knowledge base.
Checks:
Usage:
python scripts/validate_knowledge.py [repo_path]
When to use: After any modification to verify integrity.
Focused link validation between incidents and risks.
Checks:
Usage:
python scripts/check_links.py [repo_path]
When to use: When adding/updating cross-references.
Interactive domain creation wizard.
Features:
Usage:
python scripts/add_domain.py [repo_path]
When to use: When adding new domain (alternative to manual workflow).
Note: Scripts require PyYAML. Install with:
pip install -r scripts/requirements.txt
references/templates.md - File templates for spec.md, risks.md, incidents/references/validation-rules.md - Validation rules and checks