From Day Zero CTO
Maintain the canonical Day Zero CTO risk register. Use to review RISKS.md row by row, update severity/owner/mitigation/next review, close or punt risks, accept mitigations, resolve evidence gaps, and log decisions from risk review.
How this skill is triggered — by the user, by Claude, or both
Slash command
/day-zero-cto:review-risksThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Run a risk-register review ritual over `RISKS.md`. This is different from `review-engineering-risk`: that skill creates a fresh risk assessment report; this skill maintains the canonical risk register. The generated `risks/registry.json`, `risks/risk-*.html` detail pages, and `core/risks.html` page are indexes/views over the Markdown source plus report signals; do not edit them directly.
Run a risk-register review ritual over RISKS.md. This is different from review-engineering-risk: that skill creates a fresh risk assessment report; this skill maintains the canonical risk register. The generated risks/registry.json, risks/risk-*.html detail pages, and core/risks.html page are indexes/views over the Markdown source plus report signals; do not edit them directly.
<project>/knowledge/wiki/core/RISKS.md, <project>/knowledge/wiki/core/DECISIONS.md, plus STRATEGY.md, recent relevant reports, and read-only repo evidence only as needed. If <project>/knowledge/wiki/risks/registry.json or a matching <project>/knowledge/wiki/risks/risk-*.html page exists, use it for stable risk IDs and matched report-signal context, but treat RISKS.md as the editable source.Keep active: risk still stands; update next review if needed.Update: change severity, evidence, impact, owner, mitigation, or review trigger.Close: risk is no longer material; capture why.Punt: no update now; set a later calendar date, plus any event, owner, or evidence trigger.Needs evidence: name the missing evidence and owner before deciding.DECISIONS.md update. Examples that count as decisions:
RISKS.md and, when needed, DECISIONS.md; ask for approval before writing unless the user explicitly asked you to apply changes directly.<project>/knowledge/wiki/core/RISKS.md:
Next Review. External triggers are allowed, but only as an addition, such as 2026-07-06 or on receipt of legal opinion.## Closed Risks table when useful, with Closed Date, Risk, Reason, and Prior Mitigation.## Review History table when useful, with Review Date, Risk, Outcome, Notes, and Next Review.<project>/knowledge/wiki/core/DECISIONS.md for risk-review decisions:
dzcto artifact --project "<project folder>" --kind engineering-risk --title "<risk review title>" --data-file "<json report data file>"
dzcto refresh "<project folder>"
Risk Signals From Reports, and the canonical risk registry rendered from RISKS.md. Summarize active, updated, closed, punted, and evidence-needed risks, decisions logged or updated, plus next review dates and any external triggers.core/risks.html#risk-signals as an intake view for report-derived risk candidates, but manage real operating risks in RISKS.md.RISKS.md and structured report risk signals on refresh.DECISIONS.md tracks choices made while addressing those risks.npx claudepluginhub chuckblake/day-zero-cto --plugin day-zero-ctoFetches up-to-date documentation from Context7 for libraries and frameworks like React, Next.js, Prisma. Use for setup questions, API references, and code examples.
Applies a firm's KYC/AML rules grid to parsed onboarding records: assigns risk rating, checks required documents, outputs rule outcomes with citations, and routes for escalation.
Generates daily or weekly digests of activity from connected sources (chat, email, docs, tasks, CRM), highlighting action items, decisions, mentions, and project updates.