exposure-risk-quantification

Installation
SKILL.md

Exposure Risk Quantification — FAIR Scoring, $-Loss, and the Board Deliverable

Companion skill: osint-methodology (the "how to think" recon skill — see its §9 severity rubric and §16 client deliverable templates). This skill is the "how to quantify and present" layer on top of a finished recon pass: it takes findings the methodology skill's pipeline already produced and turns them into a number a board will act on.

0. When to Use / When NOT

Use this skill when: you have a completed set of recon findings (from any engagement, not just one tool's output) and need to (a) compute a defensible 0–100 + A–F risk score, (b) estimate a $-denominated loss range, (c) rank attack-path chains by exploitability, or (d) assemble a board/exec one-pager. Also use it to explain a score — "why did this grade come out D and not F" is exactly what §7 is for.

Do NOT use this skill when: you still need to go collect findings — that's osint-methodology (methodology) / offensive-osint (arsenal). This skill does not probe anything; it has nothing to say until a recon pass has already produced findings, assets, and (ideally) ownership/proof annotations.

Installs
2
GitHub Stars
2.3K
First Seen
Aug 7, 2026
exposure-risk-quantification — elementalsouls/claude-osint