impediment-prioritization
Ranks any list of impediments and their countermeasures using a value-stream scoring model (ROI, Cost to Implement, Ease of Deployment, Risk Factor) and a fixed prioritization formula. Use when someone asks to prioritize, rank, sequence, or triage impediments, countermeasures, remediation items, ris
- 0
- Installs
- —
- Rating
- —
- Success rate
- 2
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 f17bc8f1f4f1affa… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Impediment Prioritization Skill
A domain-agnostic skill for ranking impediments and their countermeasures. Works with any {impediment, countermeasure} list — GHQR findings, audit results, retro action items, risk registers, architecture review gaps, etc.
When to Activate
Activate when the user:
- Asks to prioritize, rank, sequence, or triage impediments, gaps, risks, findings, or remediation items
- Provides a list of impediments with proposed countermeasures (or asks you to propose countermeasures for a list of problems)
- Asks "what should we fix first" on any improvement / remediation backlog
- Mentions value-stream prioritization, A3 countermeasures, ROI-vs-effort, or lean impediment ranking
Inputs
Accepted input: a list of {impediment, countermeasure} pairs. Sources include (non-exhaustive):
| Source | Maps to Impediment | Maps to Countermeasure |
|---|---|---|
| GHQR / health-check findings | Finding or gap (Status ≠ Expected) | Recommendation / expected value |
| Audit results | Non-conformance | Remediation action |
| Retrospective | "What went wrong" item | Agreed improvement |
| Risk register | Risk | Mitigation |
| Architecture review | Gap vs. target state | Proposed change |
| User free-form list | Problem statement | Proposed fix |
Rules:
- One countermeasure per impediment. If the input suggests multiple remediation paths, select the primary one and note alternatives in the rationale — do not emit multiple rows for the same impediment.
- Collapse duplicates before scoring.
- If a source link / citation is available, attach it to the countermeasure.
- If a confidence level is available on the source, surface it as an optional
Confidencecolumn.
Scoring Rubric (1–10 scales)
Score each impediment's countermeasure against all four criteria. See references/scoring-rubric.md for anchoring examples at the 1 / 5 / 10 levels across multiple domains (platform engineering, security, SRE, application development, governance).
| Criterion | Scale | Definition |
|---|---|---|
| Return on Investment (ROI) | 1 = low, 10 = high | Efficiency gain delivered by the countermeasure to this step AND to the overall value stream. Not purely financial — weight throughput, cycle-time reduction, defect removal, user / developer experience, and compliance lift. |
| Cost to Implement | 1 = inexpensive, 10 = very expensive | Human capital (salary + time of people needed) plus any purchases, licenses, or infrastructure required to implement the countermeasure. |
| Ease of Deployment | 1 = extremely hard, 10 = very easy | Remediation effort required to actually deploy the countermeasure end-to-end. Reflects technical complexity, change-management burden, and rollback risk. |
| Risk Factor | 1 = low risk, 10 = very high risk | Risk weighted on impact to the overall value stream if the countermeasure goes wrong, stalls, or is deferred. |
Every score must be accompanied by a one-line rationale. When a score is an estimate rather than drawn from explicit data, mark the rationale with (estimated).
Formula
Priority = ((ROI * (10 / Cost)) + (Ease * (10 / Risk))) / 2
- Theoretical range: 1 → 100. Practical range on typical backlogs: ~1 → 100.
- The scale minimum of
1guarantees Cost and Risk are never zero (no divide-by-zero). - Higher Priority = do first.
- Boundary checks:
- ROI=10, Cost=1, Ease=10, Risk=1 →
((10*10)+(10*10))/2 = 100 - ROI=1, Cost=10, Ease=1, Risk=10 →
((1*1)+(1*1))/2 = 1
- ROI=10, Cost=1, Ease=10, Risk=1 →
Use the formula verbatim. Do not reweight, normalize, or substitute.
Method (agent procedure)
- Ingest the impediment list. Confirm 1:1 impediment-to-countermeasure mapping; collapse duplicates.
- Confirm the countermeasure for each impediment. Prefer documented best practice for the domain. Cite a public / authoritative link when one is available.
- Score all four criteria using the rubric. Write a one-line rationale per criterion.
- Compute Priority using the formula. Round to one decimal place.
- Sort rows by Priority descending. Assign Rank starting at 1.
- Render the output table (see below).
- Call out the top 3 impediments with a short "why act first" paragraph.
- Optional tags: if the workflow requires ownership flags (e.g.,
[CSA Action Required]vs.[Customer Self-Service]for GHQR/PAK, or[Owner: Team X]/[Self-Service]for internal backlogs), include them on the top-ranked items. Skip if not requested.
Output Template
## Prioritized Impediments
**Scoring:** ROI (1 low → 10 high), Cost (1 cheap → 10 expensive), Ease (1 hard → 10 easy), Risk (1 low → 10 high).
**Formula:** `Priority = ((ROI * (10/Cost)) + (Ease * (10/Risk))) / 2`
| Rank | Impediment | Countermeasure | ROI | Cost | Ease | Risk | Priority | Rationale |
|------|------------|----------------|-----|------|------|------|----------|-----------|
| 1 | [gap] | [action + link] | [n] | [n] | [n] | [n] | [n.n] | ROI: …<br>Cost: …<br>Ease: …<br>Risk: … |
### Top 3 — Act First
1. **[Impediment]** — [why it wins on the formula + optional ownership tag]
2. …
3. …
Worked example (GitHub Enterprise adoption):
| Rank | Impediment | Countermeasure | ROI | Cost | Ease | Risk | Priority | Rationale |
|---|---|---|---|---|---|---|---|---|
| 1 | 2FA not enforced at org level | Enforce org-wide 2FA (docs) | 9 | 2 | 8 | 2 | 42.5 | ROI: removes broad credential-compromise classCost: admin toggle + member commsEase: single org setting, members re-enrollRisk: low — can stage with grace period |
| 2 | Secret scanning disabled | Enable secret scanning + push protection org-wide (docs) | 8 | 3 | 7 | 3 | 25.0 | ROI: catches leaked creds pre-mergeCost: GHAS seats if not bundled (estimated)Ease: org-level defaultRisk: push-protection may block legitimate commits; stage per repo |
| 3 | No CODEOWNERS on critical repos | Add CODEOWNERS to top-20 repos (docs) | 6 | 4 | 6 | 4 | 15.0 | ROI: targeted review coverageCost: team time to define owners (estimated)Ease: file-level change, but requires owner buy-inRisk: review bottlenecks if owners undersized |
Worked example (generic retrospective action items):
| Rank | Impediment | Countermeasure | ROI | Cost | Ease | Risk | Priority |
|---|---|---|---|---|---|---|---|
| 1 | Flaky test suite blocks deploys daily | Quarantine top-10 flaky tests + add retry policy | 9 | 2 | 8 | 2 | 42.5 |
| 2 | No on-call runbook for payment service | Draft runbook from last 3 incidents | 7 | 3 | 8 | 2 | 31.7 |
| 3 | Manual release notes take 2h/release | Generate from Conventional Commits via CI | 6 | 4 | 5 | 3 | 15.8 |
Assumptions & Guardrails
- Scores are estimates informed by the rubric and any available source / citation. Mark estimated rationales explicitly with
(estimated). - Never fabricate context (team size, budget, tool inventory, organizational constraints). If required, ask the user or mark the score as estimated.
- Final ranking is a recommendation — it should be reviewed with the accountable team / owner before it's committed to an execution plan.
- Read-only by default — this skill does not execute remediations; it produces a ranked list consumed downstream.
Downstream Integration (optional)
The ranked table produced by this skill is the deliverable. Wire it into whatever downstream artifact your workflow needs (Jira epic, ADR, OKR backlog, incident review, health check report, etc.). This skill does not depend on any sibling skills or external templates.
Files
2- SKILL.md
dd6c9adda48.9 KB - references/scoring-rubric.md
6bab4c033d5.8 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from github/awesome-copilot8
Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks. Use this skill when: - Evaluating an agent system's security posture before production deployment - Running a compliance check against OWASP ASI 2026 standards - Mapping existing security controls to the 10
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching tools miss. Use this skill when asked to scan code for security vulnerabilities, find bugs, check for
Use this skill when the user explicitly asks to map, document, or onboard into an existing codebase. Trigger for prompts like "map this codebase", "document this architecture", "onboard me to this repo", or "create codebase docs". Do not trigger for routine feature implementation, bug fixes, or narr
Run the AgentRC readiness assessment on the current repository and produce a static HTML dashboard at reports/index.html. Wraps `npx github:microsoft/agentrc readiness` and hands off rendering to the @ai-readiness-reporter custom agent. Supports policies (--policy) for org-specific scoring. Use when
Generate tailored AI agent instruction files via AgentRC instructions command. Produces .github/copilot-instructions.md (default, recommended for Copilot in VS Code) plus optional per-area .instructions.md files with applyTo globs for monorepos. Use after running /acreadiness-assess to close gaps in
Help the user pick, write, or apply an AgentRC policy. Policies customise readiness scoring by disabling irrelevant checks, overriding impact/level, setting pass-rate thresholds, or chaining org baselines with team overrides. Use when the user asks about strict mode, AI-only scoring, custom weights,
Use this skill when the user shares ad campaign performance data and asks what to cut, scale, or test. Trigger for prompts like "analyze my ad campaigns", "where am I wasting ad spend", "reallocate my ad budget", "which ads are actually working", or "ROAS analysis". Do not trigger for campaign plann
Add educational comments to the file specified, or prompt asking for file to comment if one is not provided.
Related devops skillsscan passed
Use when managing an Uncloud cluster — deploying services, configuring Caddy ingress, adding static proxy routes for non-cluster devices, publishing ports, scaling, inspecting logs, or managing machines and volumes with the `uc` CLI.
Configure deployment settings for /land-and-deploy.
Build or maintain Cloudflare Sandbox apps on the stable @cloudflare/sandbox package. Use sandbox-next for preview apps and sandbox-migrate-to-next for stable-to-preview migrations.
Deploy tRPC on AWS Lambda with awsLambdaRequestHandler() from @trpc/server/adapters/aws-lambda for API Gateway v1 (REST, APIGatewayProxyEvent) and v2 (HTTP, APIGatewayProxyEventV2), and Lambda Function URLs. Enable response streaming with awsLambdaStreamingRequestHandler() wrapped in awslambda.strea
Automates CI/CD pipeline setup. Use when setting up or modifying build and deployment pipelines. Use when you need to automate quality gates, configure test runners in CI, or establish deployment strategies.
Deploys and manages full-stack web applications (Next.js, Angular) with Server-Side Rendering (SSR) using Firebase App Hosting. Use when deploying Next.js/Angular apps, configuring apphosting.yaml or firebase.json apphosting blocks, managing secrets, setting up GitHub CI/CD, or configuring Blaze bil