Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Vendor Evaluation

ASecurity

当评估新供应商提案、决定续约/更换、或并排比选两家供应商时使用;产出结构化评估报告(TCO 成本拆解、风险矩阵、优劣势、采购建议与谈判筹码);不适用于已定供应商的合同执行/付款/日常对账。触发词:供应商评估、续约决策、TCO、招投标比选、采购评审

3 stars
0 votes
0 copies
2 views
Added 9/19/2026
ai-agents

Works with

cursorcli

Security Analysis

A100/100

Scanned 9/19/2026

$npx -y skills add findscripter/everything-skills --skill vendor-evaluation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Vendor Evaluation?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Vendor Evaluation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/findscripter-vendor-evaluation/badge)](https://www.skillsdirectory.com/skills/findscripter-vendor-evaluation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: vendor-evaluation
title: 供应商评估决策
description: 当评估新供应商提案、决定续约/更换、或并排比选两家供应商时使用;产出结构化评估报告(TCO 成本拆解、风险矩阵、优劣势、采购建议与谈判筹码);不适用于已定供应商的合同执行/付款/日常对账。触发词:供应商评估、续约决策、TCO、招投标比选、采购评审
domain: 协作/knowledge
triggers: [供应商评估, 供应商比选, 续约还是更换, TCO 总拥有成本, 采购评审, 招投标比较, vendor review, 谈判筹码]
tags: [采购, 供应商管理, 成本分析, 风险评估, 决策]
level: 进阶
status: stable
agents: [claude-code, codex, cursor, gemini-cli]
tools: [知识库检索, 采购/合同系统, 文档解析]
requires: []
related: [tech-stack-evaluator, competitive-analysis, ma-playbook, contract-playbook-review]
combines_with: [contract-proposal-writer, contract-playbook-review]
license: Apache-2.0
source: anthropics/knowledge-work-plugins
source_license: Apache-2.0
---
## 何时使用

适用于在采购签批前对供应商做结构化评估并给出明确建议的场景:

- 评估一份新供应商提案,判断是否引入。
- 现有合同到期,决定续约、重新议价还是更换。
- 两家(或多家)供应商并排比选,需要 side-by-side 对比矩阵。
- 需要先算清 TCO(总拥有成本)并梳理谈判筹码,再交采购签批。

不该用的边界:
- 已选定供应商后的合同执行、下单、付款、日常对账——那属于采购运营,不在本技能范围。
- 纯法务条款审查、合规单点审计——本技能只做整体风险姿态评估,深度法审请转专门流程。
- 仅询价/比价而无评估决策需求时,直接报价对比即可,无需走完整框架。

## 步骤

1. 收集输入:①供应商名称;②场景(新引入 / 续约 / 比选);③材料(合同条款、报价、提案文档、或现有履约数据)。续约场景务必带上当前付费金额,用于评估涨跌幅。
2. 若有知识库/采购系统连接器,先检索:历史评估记录、现有合同、履约报告、采购政策与审批阈值、同类供应商的价格基线。
3. 按四维框架逐项分析(见下)。可解析上传的提案文档,从中抽取价格、条款、SLA。
4. 比选场景:额外产出对比矩阵,覆盖价格、功能、集成、安全、支持、合同条款、客户案例。
5. 汇总输出报告:摘要建议 + 成本表 + 风险矩阵 + 优劣势 + 建议 + 谈判筹码。

## 指令

四维评估框架,逐项落实:

- 成本分析(总拥有成本 TCO,不只是 license 费):实施与迁移成本、培训与上手成本、持续支持与维护、退出成本(数据迁移、合同解除)。
- 风险评估:供应商财务稳健性、安全与合规姿态、集中度风险(单一供应商依赖)、合同锁定与退出条款、业务连续性与灾备。
- 履约指标:SLA 达成率、支持响应时间、可用性与可靠性、功能交付节奏、客户满意度。
- 对比矩阵(仅比选时):价格、功能、集成、安全、支持、合同条款、参考案例并排列出。

输出模板:

```markdown
## 供应商评估:[供应商名称]
**日期:** [日期] | **类型:** [新引入 / 续约 / 比选]

### 摘要
[2-3 句话的建议结论]

### 成本分析
| 组成项 | 年度成本 | 备注 |
|--------|---------|------|
| License/订阅 | ¥[X] | [按席位/包年/按量] |
| 实施 | ¥[X] | [一次性] |
| 支持/维护 | ¥[X] | [含/加购] |
| **第 1 年合计** | **¥[X]** | |
| **3 年合计** | **¥[X]** | |

### 风险评估
| 风险 | 可能性 | 影响 | 缓解措施 |
|------|--------|------|---------|
| [风险] | 高/中/低 | 高/中/低 | [缓解] |

### 优势
- [优势 1]
- [优势 2]

### 顾虑
- [顾虑 1]
- [顾虑 2]

### 建议
[推进 / 议价 / 放弃] —— [理由]

### 谈判筹码
- [筹码 1]
- [筹码 2]
```

## 示例

输入:「比较 A 厂商 vs B 厂商的 CRM,A 报价 ¥80 万/年含实施,B 报价 ¥60 万/年实施另算 ¥25 万。」

处理:抽取双方报价 → 补齐 B 的实施成本算出真实首年 TCO(A ¥80 万 vs B ¥85 万)→ 列对比矩阵 → 标注 B 首年更贵但次年起更省、A 锁定期 3 年退出成本高 → 风险矩阵给出集中度与锁定风险 → 建议「议价:以 B 报价为筹码压 A 的实施费,或要求 A 缩短锁定期」。

## 注意事项

- TCO 优先:永远把实施、培训、支持、退出成本算进去,单看 license 费会严重低估。
- 续约必带现状价:不知道现在付多少,就无法判断涨价是否合理。
- 退出成本即谈判筹码:锁定期、数据迁移难度既是风险也是议价点,务必量化。
- 比选输出必须 side-by-side,避免分别描述导致无法对齐决策维度。
- 上传提案文档可自动抽取价格/条款/SLA,鼓励用户直接给原始材料而非二手转述。

## 互见

- 采购运营 / 合同执行类技能(评估通过后的下单付款流程)。
- 成本/预算分析类技能(TCO 进一步并入年度预算时)。
- 风险与合规审查类技能(需要深度法审或安全审计时)。

---
采编自 anthropics/knowledge-work-plugins(Apache-2.0)。

Attribution

findscripterfindscripter
View sourceSee grades on GitHubMore from findscripter →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →