TopRank Skills

Home / Claw Skills / Document / vendor-risk-assessment
Official OpenClaw rules 54%

vendor-risk-assessment

Assess third-party vendor risk for AI and SaaS products. Evaluates security posture, data handling, compliance, financial stability, and operational resilience. Use when onboarding new vendors, conducting annual reviews, or building a vendor management program. Generates a scored risk report with mitigation recommendations. Built by AfrexAI.

Stars

0

Installs

0

Status

ACTIVE

Visibility

PUBLIC

安装方式

直接复制以下提示词,发送给你的 AI 助手即可完成安装。

请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 vendor-risk-assessment 技能。 若已安装,则直接安装 vendor-risk-assessment 技能。

Overview

Skill Key
1kalin/vendor-risk-assessment
Author
1kalin
Source Repo
openclaw/skills
Version
-
Source Path
skills/1kalin/vendor-risk-assessment
Latest Commit SHA
29764954365b5d48521cb5aa45e68f5c507bce45

Extracted Content

SKILL.md excerpt

# Vendor Risk Assessment

Evaluate any AI/SaaS vendor across 6 risk dimensions. Outputs a scored report with go/no-go recommendation.

## When to Use
- Onboarding a new SaaS or AI vendor
- Annual vendor review cycle
- Evaluating build-vs-buy decisions
- Due diligence for partnerships or acquisitions
- Compliance requirements (SOC2, ISO 27001, GDPR)

## How to Use

The user provides vendor details (name, product, website, any available documentation).
The agent researches and scores the vendor across 6 dimensions.

### Input Format
```
Vendor: [Company Name]
Product: [Product/Service Name]
Website: [URL]
Use Case: [What you'd use it for]
Data Sensitivity: [low/medium/high/critical]
Additional Context: [Any docs, certifications, or concerns]
```

## Assessment Framework

### 6 Risk Dimensions (each scored 1-10)

#### 1. Security Posture
- SOC2 Type II certification?
- Penetration testing cadence
- Encryption (at rest + in transit)
- Access controls and authentication
- Incident response plan
- Bug bounty program

#### 2. Data Handling & Privacy
- Data residency and sovereignty
- Data retention and deletion policies
- Sub-processor transparency
- GDPR/CCPA compliance
- Data portability (can you get your data out?)
- AI training opt-out policies

#### 3. Compliance & Certifications
- SOC2, ISO 27001, HIPAA, FedRAMP
- Industry-specific (PCI-DSS, HITRUST, etc.)
- AI-specific (EU AI Act readiness, NIST AI RMF)
- Audit frequency and transparency
- Regulatory track record

#### 4. Financial Stability
- Funding stage and runway
- Revenue indicators (public or estimated)
- Customer concentration risk
- Acquisition risk
- Pricing stability history

#### 5. Operational Resilience
- Uptime SLA and historical performance
- Disaster recovery plan
- Multi-region availability
- Dependency on single cloud provider
- Support responsiveness and escalation paths
- Change management process

#### 6. Contractual Terms
- Termination and exit clauses
- Liability caps and indemnification
- IP...

Related Claw Skills

edholofy

dojo.md

★ 4

University for AI agents. 92 courses, 4400+ scenarios, any model via OpenRouter. Auto-training loops generate per-model SKILL.md documents. Works with Claude Code, OpenClaw, Cursor, Windsurf. No fine-tuning required.

lethehades

wps-macos-helper

★ 1

macOS WPS Office workflow helper skill for safer document preparation, conversion, export, and compatibility guidance

capt-marbles

firecrawl

★ 0

Web scraping and crawling with Firecrawl API. Fetch webpage content as markdown, take screenshots, extract structured data, search the web, and crawl documentation sites. Use when the user needs to scrape a URL, get current web info, capture a screenshot, extract specific data from pages, or crawl docs for a framework/library.

caqlayan

Tweet Processor

★ 0

Tweet Processor Skill

carev01

md-docs-search

★ 0

Full-text search across structured Markdown documentation archives using SQLite FTS5. Use when you need to search large collections of Markdown articles that are separated by "---" delimiters and contain source URLs (marked with "*Source:" pattern). Provides fast BM25-ranked search with automatic source URL extraction for citations. Ideal for research, documentation lookups, and knowledge base exploration. Requires indexing documentation first with `docs.py index`.

camelsprout

duckdb-en

★ 0

DuckDB CLI specialist for SQL analysis, data processing and file conversion. Use for SQL queries, CSV/Parquet/JSON analysis, database queries, or data conversion. Triggers on "duckdb", "sql", "query", "data analysis", "parquet", "convert data".