Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Qa Risk

ASecurity

[QA Method] Risk-based test prioritization: risk matrix, severity classification, dynamic reprioritization, test depth allocation.

2 stars
0 votes
0 copies
0 views
Added 9/20/2026
testinggotestingapisecurity

Works with

api

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add VirtoCommerce/vc-mcp-testing-module --skill qa-risk --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Qa Risk?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Qa Risk
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/virtocommerce-qa-risk-vc-mcp-testing-module/badge)](https://www.skillsdirectory.com/skills/virtocommerce-qa-risk-vc-mcp-testing-module)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: qa-risk
description: "[QA Method] Risk-based test prioritization: risk matrix, severity classification, dynamic reprioritization, test depth allocation."
argument-hint: "feature | sprint | release | VCST-XXXX"
disable-model-invocation: true
---

# /qa-risk — Risk-Based Test Prioritization

Apply risk-based testing strategy to prioritize test effort where it matters most. Use when planning test coverage for a sprint, release, or individual feature to allocate time based on likelihood and business impact.

## Usage
```
/qa-risk Checkout payment flow
/qa-risk sprint 42 release
/qa-risk VCST-5678 — assess risk for configurable products
/qa-risk release 3.8 — full release risk assessment
```

## Execution

1. **Read the risk framework:** Load `risk-prioritization-framework.md` from this skill folder for the full 5x5 matrix, severity/priority definitions, and allocation tables.

2. **Identify the scope:**
   - If a JIRA ticket: fetch details, identify affected module(s) and user flows
   - If a sprint: list all tickets/features in scope
   - If a release: identify all changed modules, new features, and dependency updates

3. **Assess risk for each item:**
   - Score Likelihood (1-5) based on: change complexity, code maturity, historical defect rate
   - Score Impact (1-5) based on: revenue effect, user base size, data integrity, security exposure
   - Calculate Risk Score = Likelihood x Impact
   - Classify: Low (1-4), Medium (5-9), High (10-15), Critical (16-25)

4. **Map to product risk categories:**
   - Revenue: checkout, payment, cart, pricing
   - Data Integrity: orders, inventory, customer data, import/export
   - Security: authentication, authorization, PCI, input validation
   - User Experience: navigation, search, catalog, responsive
   - Platform Stability: APIs, background jobs, integrations, infrastructure

5. **Allocate test depth:**
   - Critical (16-25): Full regression + exploratory, 40% of time budget
   - High (10-15): Critical paths + key scenarios, 30% of time budget
   - Medium (5-9): Smoke + targeted checks, 20% of time budget
   - Low (1-4): Visual check or skip, 10% of time budget

6. **Output risk register:**
   - Table: Feature | Risk Category | Likelihood | Impact | Score | Level | Test Depth | Assigned Suite
   - Highlight any items above the risk appetite threshold
   - Recommend test suite selection (smoke/critical/sprint/full)

7. **Check for dynamic triggers:**
   - Production bug in same area → escalate risk level
   - Hotfix deployed → re-assess affected modules
   - Module dependency update → check downstream impact
   - Infrastructure change → platform stability risk increase

## Integration with Other Skills
- Critical risk items should get decision tables + state transitions
- Higher-risk bugs get a deeper discovery pass during `/qa-bug` reproduction (see `qa/shared-instructions.md` Discovery pass)

## Rules
- Revenue-critical flows (checkout, payment) start at minimum Medium risk regardless of change size
- Never skip testing a Critical risk item — escalate if time is insufficient
- Risk assessment must be documented before test execution begins
- Re-assess risk when scope changes mid-sprint
- A "no changes" module still has residual risk from platform updates — minimum Low

Attribution

VirtoCommerceVirtoCommerce
View sourceMore from VirtoCommerce →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Screen Reader Testing

Practical guide to testing web applications with screen readers for comprehensive accessibility validation.

393431 votes

Python Testing

使用pytest、TDD方法、夹具、模拟、参数化和覆盖率要求的Python测试策略。

2456590 votes

Tdd Workflow

在编写新功能、修复错误或重构代码时使用此技能。强制执行测试驱动开发,包含单元测试、集成测试和端到端测试,覆盖率超过80%。

2456590 votes

Springboot Tdd

使用JUnit 5、Mockito、MockMvc、Testcontainers和JaCoCo进行Spring Boot的测试驱动开发。适用于添加功能、修复错误或重构时。

2456590 votes

Eval Harness

克劳德代码会话的正式评估框架,实施评估驱动开发(EDD)原则

2456590 votes
View all in testing →