# Build Medical Device Risk Management Files

Medical device teams need consistent, traceable risk decisions across the product lifecycle. This skill structures ISO 14971 analysis, controls, verification, and post-production review.

## Install

```bash
npx skillstore add davila7/risk-management-specialist
```

## Metadata

- Status: approved
- Slug: davila7-risk-management-specialist
- Skillstore revision: r2
- Version status: missing
- Tree hash: ea06f0fe039afe4851c6b67408f8238c88a78e48dbdeca267cc5d8b8d80720b2
- Author: davila7
- GitHub username: davila7
- License: MIT
- Repository: https://github.com/davila7/claude-code-templates/tree/main/cli-tool/components/skills/enterprise-communication/risk-management-specialist
- Ref: c43861a65bb95efcae259cd161c9d6f4dc7eec6f
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: allowed
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands
- Quality score: 83
- Quality tier: gold
- Public page: https://skillstore.pages.dev/skills/davila7-risk-management-specialist
- Manifest: https://skillstore.pages.dev/api/skills/davila7-risk-management-specialist/manifest

## Capabilities

- Structures ISO 14971 risk management plans with scope, criteria, roles, responsibilities, and lifecycle activities.
- Identifies hardware, software, cybersecurity, usability, and combination-product hazards from supplied device context.
- Organizes probability, severity, risk evaluation, and acceptability rationale using user-provided criteria.
- Proposes risk controls in priority order and identifies verification evidence for each control.
- Connects risk activities with IEC 62304, ISO 13485, FDA submission, and EU MDR documentation needs.
- Reviews clinical and post-production information for signals that may require risk file updates.

## Use Cases

- Plan Product Risk Activities: Create a lifecycle risk management plan with responsibilities, review points, acceptability criteria, and required records.
- Analyze Software Hazards: Connect software failure modes, hazardous situations, controls, and verification evidence within an IEC 62304 development process.
- Review Post-Market Signals: Assess complaints, vigilance reports, and clinical findings for changes to risk estimates, controls, and benefit-risk conclusions.

## Prompt Templates

### Outline a Risk Management Plan

```
Create an ISO 14971 risk management plan outline for [device]. Include scope, responsibilities, review milestones, acceptability criteria, required records, and post-production activities.
```

### Build a Preliminary Hazard Analysis

```
Develop a preliminary hazard analysis for [device and intended use]. Cover energy, biological, software, cybersecurity, usability, and environmental hazards. State assumptions and missing evidence.
```

### Evaluate Risk Controls

```
Review these hazards, risk estimates, and proposed controls: [details]. Apply the ISO 14971 control hierarchy, identify verification evidence, and flag unsupported residual-risk conclusions.
```

### Perform a Lifecycle Risk File Review

```
Assess this risk file and post-production evidence: [details]. Trace new signals to hazards, reassess risk and benefit-risk conclusions, and propose prioritized updates with accountable owners.
```

## Limitations

- It does not replace qualified regulatory, quality, engineering, clinical, or legal review.
- It does not provide licensed standards text or guarantee compliance with current jurisdictional requirements.
- Risk estimates depend on supplied evidence and acceptability criteria; the skill cannot establish true event probabilities without data.
- The included script, reference, and asset files are placeholders, so the package provides guidance rather than working automation or templates.

## Best Practices

- Provide intended use, users, environments, device architecture, and available evidence before requesting risk analysis.
- Supply approved severity, probability, and acceptability criteria so evaluations follow organizational policy.
- Require traceability from hazards through controls, verification evidence, residual risk, and post-production review.

## Anti Patterns

- Do not treat generated risk records as approved evidence without cross-functional review and document control.
- Do not assign numerical probabilities when supporting data and estimation methods are unavailable.
- Do not rely on warnings or training before considering inherent safety and protective measures.

## Security Audit

- Audited at: 2026-07-23T14:25:24.939\+00:00
- Summary: All 16 medium static findings are false positives. Four are Markdown fence delimiters, and twelve are inline-code resource names that do not execute commands. No prompt injection or other intent-level security issue was found.

## Stats

- Views: 266
- Downloads: 11
- Favorites: 0
- Popularity score: 0
