agentsclimarketplace

Legal hr risk taxonomy

Skill Raishin/vanguard-frontier-agentic/skills/cross-functional/legal-hr-risk-taxonomy

Curated marketplace of AI skills, agents, and rules for cloud, zero-trust, and compliance-aware engineering - works with Claude Code, Codex, Cursor, Copilot, and more.

Install
npx -y skills add Raishin/vanguard-frontier-agentic --skill legal-hr-risk-taxonomy

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 18 stars18 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Use this skill to assign consistent risk labels to a Legal or HR matter — severity ratings, privilege and privacy sensitivity labels, retaliation and discrimination risk labels, matter-type classes, escalation-gate triggers, and the audit-log schema. It standardizes the vocabulary every Legal and HR agent and case capsule uses so risk is rated the same way across the ecosystem. It does not give legal or HR advice and never concludes that a matter is safe or compliant.

SKILL.md

4.5 KB, as published. Nobody here has run it

Legal-HR Risk Taxonomy

Purpose

This skill is the shared risk vocabulary for the Legal and HR agent ecosystem. It defines the severity scale, sensitivity labels, matter-type classes, escalation-gate triggers, and the audit-log schema, so every agent and every case capsule rates and labels risk the same way. It does not give legal or HR advice and never concludes that a matter is safe, compliant, or approved.

When to use

  • An agent must assign a risk_rating or sensitivity label to a matter.
  • An agent must decide whether an escalation gate is triggered.
  • A capsule or audit-log entry must be filled in with consistent labels.

Severity scale

RatingMeaning
CriticalImmediate legal or regulatory exposure; do not proceed without counsel sign-off.
HighMaterial litigation, regulatory, or financial exposure; escalation strongly indicated.
MediumManageable with documented controls; monitor and document.
LowLimited exposure on current evidence; note and monitor.
UnknownJurisdiction or material facts missing; cannot rate. Mandatory when documentation is incomplete.

Unknown is mandatory, not a fallback. An agent never upgrades a matter to a ratable severity to avoid an escalation.

Sensitivity labels

  • privilege_sensitivity: none / possible / likely-privileged.
  • privacy_sensitivity: low / moderate / high / special-category.
  • retaliation_risk, discrimination_or_harassment_risk, regulatory_risk: none-observed / possible / elevated / unknown.
  • litigation_hold_needed: no / recommended / yes / unknown.

Escalation-grade matter types

The following are escalation-grade by default — they always reach a qualified human owner regardless of severity rating: harassment, discrimination, retaliation, whistleblower, workplace safety, wage/hour, worker classification, union/labor, immigration, medical leave, disability accommodation, pay equity, executive misconduct, mass layoff or reorganization, employee data breach, and litigation-hold or discovery matters.

Escalation gates

A matter must be paused and escalated when any gate is true:

  • The matter is an escalation-grade matter type (above).
  • A claim, complaint, charge, grievance, or subpoena has been filed or threatened.
  • Protected activity, protected characteristics, or whistleblower status are in play.
  • Attorney-client privilege or work-product protection may be implicated.
  • Financial or reputational exposure is material.
  • A board, audit-committee, or regulatory-reporting trigger may apply.
  • The matter crosses Legal and HR and no documented controls exist.
  • Legal and HR agents disagree.

See references/risk-labels.md for the full matter_type value list and the audit-log schema.

Audit-log schema

Every handoff and escalation produces one audit-log event with the minimum necessary fields: event_id, case_id, timestamp, initiating_agent, receiving_agent, human_owner, matter_type, risk_rating, escalation_status, data_sensitivity, privilege_sensitivity, action_recommended, action_prohibited, evidence_summary, open_questions, decision_status, retention_category. Field rules are in the reference file.

References

Security notes

  • A rating is an opinion on exposure, never a clearance. Never record "this is compliant" or "safe to proceed"; use the severity scale only.
  • The audit log is minimum-necessary. It carries labels and summaries, never raw medical, privileged, credential, or protected-class content.
  • When facts are missing, rate Unknown and trigger the escalation gate rather than guessing a lower severity.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.