Product ai risk
Skill jpoindexter/product-management-skills/skills/product-ai-risk
Operational product-management skills and a /pm router for Codex and Claude.
npx -y skills add jpoindexter/product-management-skills --skill product-ai-riskAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 14 days oldThe repository was created 14 days ago. New is not bad, but a brand new repository carrying a familiar-sounding name is the shape a typosquat arrives in, and there has been no time for anyone else to find a problem with it.
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Review AI-product safety, reliability, privacy, security, fairness, uncertainty, human oversight, fallback, monitoring, drift, latency, and cost risks. Use for AI launch gates, agent actions, high-impact automation, incident preparation, production failure analysis, or system feasibility review.
SKILL.md
2.9 KB, as published. Nobody here has run it
Product AI Risk
Model how the full sociotechnical system can fail, detect failure early, limit exposure, and recover safely.
Inputs
- Users, affected non-users, workflow, and environment
- Model capabilities, data flows, tools, and external actions
- Decision impact and error tolerance
- Human oversight and operational ownership
- Evaluation, monitoring, rollback, and incident capabilities
- Regulatory, contractual, privacy, and policy constraints
Workflow
- Map the system boundary: inputs, data, model, retrieval, tools, people, actions, feedback, and downstream dependencies.
- Identify harms from wrong output, omission, delay, disclosure, manipulation, overreliance, disparate performance, and unauthorized action.
- Assess severity, likelihood, detectability, exposure, and reversibility by affected group.
- Define preventive controls: scope limits, permissions, data minimization, grounding, validation, confirmation, rate limits, and human approval.
- Define detective controls: quality slices, drift, data integrity, latency, cost, abuse, override, and incident signals.
- Design uncertainty communication, safe fallback, correction, appeal, and manual recovery.
- Set staged exposure, kill switch, rollback, and incident ownership.
- Establish launch blockers, accepted risks, residual risk owner, and review schedule.
- Escalate high-impact or regulated decisions to qualified legal, security, privacy, safety, and domain owners.
Output contract
Return system map, risk register, affected groups, controls, monitoring, human-oversight design, fallback and recovery plan, launch blockers, residual risk acceptance, owners, and review triggers.
Quality gate
- The review covers the workflow and organization, not only the model.
- Critical actions use least privilege and confirmation appropriate to impact.
- Distribution shift and data feedback loops are monitored.
- Safe failure is usable under real operating conditions.
- Residual risk has an accountable human owner.
Avoid
- A generic ethics checklist without system-specific failure paths
- Treating disclaimers as controls
- Human review without time, expertise, authority, or interface support
- Monitoring averages that hide harmed segments
- Launching without rollback because the model passed offline tests
Source grounding
Operational synthesis informed by uncertainty, trust, feedback, and responsible AI practices in Building AI-Powered Products and data quality, distribution shift, monitoring, latency, and feedback-loop principles in Designing Machine Learning Systems.