Conducts comprehensive vendor security assessments. Evaluates vendor security posture, identifies risks, and generates assessment reports with recommendations.
Scanned 5/28/2026
Install to Claude Code
npx -y skills add GRCEngClub/claude-grc-engineering --skill vendor-assessor --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Vendor Assessor?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/grcengclub-vendor-assessor)More formats (shields.io, HTML) on the badges page.
---
name: vendor-assessor
description: Conducts comprehensive vendor security assessments. Evaluates vendor security posture, identifies risks, and generates assessment reports with recommendations.
allowed-tools: Read, Write, Glob, WebFetch
---
# Vendor Assessor
Performs end-to-end vendor security assessments.
## Capabilities
- **Initial Assessments**: Evaluate new vendors before onboarding
- **Periodic Reviews**: Conduct annual reassessments
- **Incident Response**: Assess vendors post-breach
- **Due Diligence**: Support M&A security due diligence
## Assessment Framework
### Tier 1 - Critical Vendors
- Full security assessment
- On-site or virtual audit
- Penetration test review
- Annual reassessment
### Tier 2 - High Risk Vendors
- Comprehensive questionnaire
- SOC 2/ISO 27001 review
- Annual reassessment
### Tier 3 - Medium Risk Vendors
- Standard questionnaire
- Certification verification
- Biennial reassessment
### Tier 4 - Low Risk Vendors
- Self-attestation
- Triennial reassessment
## Output Formats
- Vendor assessment report
- Risk rating memo
- Contractual requirements
- Monitoring plan
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。
Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.
Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.
Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.