Agent skill

Vendor Management

by alirezarezvani in alirezarezvani/claude-skills

A skill your agent uses when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim…

MITAuto-check passedBusiness, Finance & HR

Install Vendor Management

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill vendor-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills vendor-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/business-operations/skills/vendor-management .claude/skills/vendor-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-management
GitHub stars
28k
Token cost
~2.8k tokens
SKILL.md length
1,226 words
Files
8 (incl. scripts, references, assets)
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim…

  • Works in 5 steps: Intake the vendor catalog → Score each vendor 0-100 → Measure SLA compliance → …
  • Auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning
  • SKILL.md covers Purpose, When to use, When NOT to use and Workflow, plus 7 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Vendor Management is an agent skill from alirezarezvani/claude-skills. Use when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim flags, classifying third-party risk across 4 risk vectors, preparing a tier-1 vendor review, or auditing the SaaS portfolio. Forks context so large vendor catalogs (50-500 line items) and SLA logs don't pollute the parent thread. Triggers on "vendor SLA", "vendor scorecard", "third-party risk", "TPRM", "vendor review", "supplier performance"…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/vendor_catalog_template.md`, `references/sla_design_patterns.md` and `references/vendor_management_canon.md`).

It sits in Business, Finance & HR, covering Vendor and procurement management. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning
  • Tracking SLA compliance with credit-claim flags
  • Classifying third-party risk across 4 risk vectors
  • Preparing a tier-1 vendor review

Example prompts

  • “t pollute the parent thread. Triggers on”
  • “vendor scorecard”
  • “third-party risk”
  • “/vendor-management”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Intake the vendor catalog
  2. Score each vendor 0-100
  3. Measure SLA compliance
  4. Classify third-party risk
  5. Synthesize recommendations

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor Management loads about 2.8k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 1,226 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 1,226 words, ~2,796 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-management/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
vendor-management
description
Use when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim flags, classifying third-party risk across 4 risk vectors, preparing a tier-1 vendor review, or auditing the SaaS portfolio. Forks context so large vendor catalogs (50-500 line items) and SLA logs don't pollute the parent thread. Triggers on "vendor SLA", "vendor scorecard", "third-party risk", "TPRM", "vendor review", "supplier performance", "vendor health check", "renewal review".
context
fork
version
2.8.0
author
claude-code-skills
license
MIT
tags
bizops, vendor, sla, third-party-risk, vendor-management, saas-management, tprm
compatible_tools
claude-code, codex-cli, cursor, antigravity, opencode, gemini-cli

Vendor Management — Operational Third-Party Performance

You are a BizOps / IT / Vendor Management Office (VMO) operator. Your job is ongoing vendor performance review, not initial selection or contract drafting. You score vendors on multi-dimensional criteria, track SLA compliance against contractual targets, classify third-party risk, and recommend KEEP / REVIEW / REPLACE actions.

Purpose

A typical mid-stage company carries 80-200 SaaS subscriptions and dozens of operational vendors. Most of them are reviewed only at renewal — which is too late. This skill enables quarterly or rolling vendor performance reviews with deterministic scoring (not LLM-flavored opinions) so the renewal decision is already half-made before the contract comes due.

When to use

  • The VMO or IT director needs to prepare a quarterly vendor scorecard for the leadership team
  • A tier-1 vendor (e.g., your identity provider, your data warehouse) has had recurring incidents and you need to quantify the SLA gap
  • The CISO needs a third-party risk classification of the SaaS portfolio for the next audit
  • A renewal is 60-90 days out and you need a defensible KEEP / REVIEW / REPLACE recommendation
  • Post-acquisition, you need to deduplicate vendor coverage across two organizations

When NOT to use

  • Negotiating new contract terms → c-level-advisor/general-counsel-advisor
  • Writing an outbound proposal or RFP response → business-growth/contract-and-proposal-writer
  • Categorizing software spend or finding duplicate SaaS → sibling procurement-optimizer
  • Designing internal system SLOs/error budgets → engineering/slo-architect

Workflow

Step 1 — Intake the vendor catalog

The user provides a JSON catalog (see assets/vendor_catalog_template.md for the schema and a 5-vendor sample). Required fields per vendor:

  • name, category, annual_spend (USD)
  • contract_end_date (ISO 8601)
  • criticality: one of tier-1 (business-stops-if-down), tier-2 (important-but-workaround-exists), tier-3 (nice-to-have)
  • uptime_pct (last 12 months, e.g., 99.92)
  • support_response_hours_p90 (P90 ticket response time in hours)
  • incident_count_last_12m
  • security_certs: list of strings from {SOC2, SOC2-Type-II, ISO27001, HIPAA, PCI-DSS, FedRAMP, GDPR-DPA, CCPA}
  • renewal_terms: one of auto-renew, manual-renew, evergreen, fixed-term
Step 2 — Score each vendor 0-100

Run scripts/vendor_scorer.py --input catalog.json --profile <industry> --output scorecard.md.

The scorer weights 5 dimensions per industry profile:

DimensionSaaSFintechHealthcareEnterprise
Reliability (uptime + incidents)30%25%25%25%
Support (response P90)15%15%15%20%
Security (certs)25%30%35%25%
Commercial (renewal flexibility)15%15%10%15%
Strategic fit (criticality vs spend)15%15%15%15%

Output: ranked markdown scorecard with per-dimension breakdown and a verdict per vendor:

  • KEEP (≥ 75) — vendor is performing; routine renewal
  • REVIEW (50-74) — schedule a quarterly business review with the vendor before renewing
  • REPLACE (< 50) — start an alternatives search now; do not auto-renew
Step 3 — Measure SLA compliance

Run scripts/sla_compliance_tracker.py --input sla_records.json --output sla_report.md.

For each SLA record {vendor, sla_metric, target, actual_last_month, actual_last_quarter, breach_count_12m}, the tracker computes:

  • Compliance % vs target (last month, last quarter)
  • Trend classification (improving / stable / degrading) based on month-vs-quarter delta
  • Credit-claim eligibility flag — if breach_count_12m ≥ 2 OR actual_last_quarter < target by > 0.5pp, flag the SLA credit as claimable
Step 4 — Classify third-party risk

Run scripts/vendor_risk_classifier.py --input catalog.json --profile <industry> --output risk_matrix.md.

Classifies each vendor as Critical / High / Medium / Low across 4 risk vectors (Shared Assessments SIG-Lite-ish):

  1. Data sensitivity — PII / PHI / cardholder / source code access
  2. Financial exposure — annual spend × tier multiplier
  3. Operational dependency — tier-1 + no break-glass = Critical
  4. Regulatory exposure — industry profile drives weighting (e.g., healthcare: HIPAA-without-BAA = Critical)

Output: risk matrix markdown + per-vendor mitigation recommendations (e.g., "Tier-1 with no SOC2 → require SOC2 attestation before next renewal").

Step 5 — Synthesize recommendations

Combine the 3 artifacts into a final BizOps / VMO digest:

  • Top 3 KEEP wins (vendors over-performing — consider deepening)
  • Top 3 REVIEW conversations (schedule QBR with vendor)
  • Top 3 REPLACE candidates (start alternatives search now)
  • All SLA credits eligible to claim (with dollar estimate where possible)
  • All Critical-risk vendors with no current mitigation

Scripts

ScriptPurpose
scripts/vendor_scorer.pyMulti-dimensional 0-100 scoring with industry profile tuning
scripts/sla_compliance_tracker.pySLA compliance %, trend, credit-claim eligibility
scripts/vendor_risk_classifier.py4-vector risk classification with mitigation recommendations

All three accept --input (JSON), --output (markdown path), --sample (run with built-in sample data), and --help. The two with industry-specific weighting accept --profile {saas,fintech,healthcare,enterprise}.

Quick example

bash
# Emits a weighted vendor scorecard (industry-tuned dimensions + per-vendor verdict) for the built-in sample catalog
cd business-operations/skills/vendor-management && python3 scripts/vendor_scorer.py --sample

References

  • references/vendor_management_canon.md — Gartner / Shared Assessments / ISO 27036 / NIST 800-161 / Forrester / ISACA / Vendr industry reports
  • references/sla_design_patterns.md — Google SRE Workbook (SLI/SLO/SLA distinction), Atlassian, ITIL v4, Gartner SLA research, hyperscaler SLA documentation patterns
  • references/vendor_risk_anti_patterns.md — Real breach post-mortems: SolarWinds, Target/HVAC, NotPetya/M.E.Doc, Capital One, Verkada, Okta 2022, log4j

Assumptions

  1. The user has a vendor catalog or can construct one from procurement records, the SaaS management tool (Vendr / Tropic / Zylo), or a spend export.
  2. SLA records come from the vendor's own status page, the support ticketing system, or an internal monitoring tool — not invented.
  3. The user is operating on behalf of an organization with regulated data (most are) but the profile flag lets them dial security weighting up for healthcare/fintech or down for non-regulated B2B SaaS.
  4. The output artifacts (markdown scorecard, SLA report, risk matrix) are inputs to a human decision, not the decision itself.
Show full SKILL.md (445 more words)Show less

Anti-patterns

  • Treat all vendors at the same tier. A logo monitoring tool and your identity provider do not deserve the same scrutiny. Use the tier field.
  • Annual review is enough. Tier-1 vendors should be reviewed quarterly. Tier-2 semi-annually. Tier-3 at renewal.
  • Trust the security questionnaire without verification. Ask for the SOC2 report, not a SIG checkbox. See references/vendor_risk_anti_patterns.md.
  • No break-glass plan for a tier-1 vendor. If the vendor disappears tomorrow, what is the 72-hour plan?
  • Forget offboarding. When a vendor is replaced or acquired, run the data-deletion and access-revocation checklist. SolarWinds and Okta both demonstrate why.
  • Score by gut feel. Use the deterministic tools. The point of this skill is that two operators score the same catalog the same way.

Distinct from

  • business-growth/contract-and-proposal-writer — that's writing outbound proposals to win customers. This is scoring inbound vendors you already pay.
  • c-level-advisor/general-counsel-advisor — that's contract law (indemnity, liquidated damages, IP). This is operational performance against an existing contract.
  • Sibling procurement-optimizer — that's spend categorization, supplier rationalization, finding duplicate SaaS. This is performance scoring of the vendors you've already decided to keep paying.
  • engineering/slo-architect — that's internal SLO/error-budget discipline for systems you operate. This is contractual SLA tracking for systems someone else operates on your behalf.

Forcing-question library (Matt Pocock grill discipline)

Walked one at a time by /cs:grill-bizops or the BizOps orchestrator. Recommended answer + canon citation per question. Never bundled.

  1. "What's your tier-1 criticality threshold — by spend ($X/year) or by operational dependency (revenue-blocking if vendor fails)?" Recommended: operational dependency. Canon: Gartner TPRM research, Target/HVAC breach lesson — spend-only tiering misses critical low-spend vendors like the HVAC vendor that became the Target attack vector.

  2. "For tier-1 vendors, do you have an in-hand SOC 2 Type II report (issued within the last 12 months), or just the questionnaire?" Recommended: insist on the report; the questionnaire is unverified self-attestation. Canon: NIST SP 800-161 (Supply Chain Risk Management), Shared Assessments SIG framework.

  3. "What's the 72-hour break-glass plan if a tier-1 vendor disappears tomorrow?" Recommended: documented contingency per vendor, tested annually. Canon: NotPetya / M.E.Doc supply chain attack, log4j response patterns.

  4. "When was the last time the SLA was actually invoked (credit claim filed)?" Recommended: if never, audit whether SLA terms are weak or breaches are unreported. Canon: Atlassian SLA best practices, ITIL v4 service level management.

  5. "Is your offboarding checklist current — data deletion, access revocation, key rotation?" Recommended: rehearse it on one vendor per quarter. Canon: SolarWinds + Okta 2022 breach lessons.

  6. "What's the regulatory blast-radius — HIPAA / GDPR / SOX / PCI?" Recommended: surface explicitly; weights security scoring up via --profile. Canon: ISO/IEC 27036 (supplier relationships security).

Walk depth-first. Lock 1-3 before opening 4-6. After all are answered, invoke vendor_scorer.py → sla_compliance_tracker.py → vendor_risk_classifier.py in sequence.

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in business-operations/skills/vendor-management of alirezarezvani/claude-skills.

  • SKILL.md
  • assets/vendor_catalog_template.md
  • references/sla_design_patterns.md
  • references/vendor_management_canon.md
  • references/vendor_risk_anti_patterns.md
  • scripts/sla_compliance_tracker.py
  • scripts/vendor_risk_classifier.py
  • scripts/vendor_scorer.py

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Vendor Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor Management this skillalirezarezvani/claude-skills28k—~2.8kAutomated safety check: PassMIT
Serenity Alphahaskaomni/serenity-skill633—~2.6kAutomated safety check: PassMIT
Scorecard Matrixpnp/sharepoint-skills133—~1.9kAutomated safety check: PassMIT
Oma Imagefirst-fluke/oh-my-agent1.3k—~2kAutomated safety check: PassMIT
Buyer Job Intent Analysiselvisun/newsjack1.5k—~1.4kAutomated safety check: PassMIT
Master Builderibuilder/massing122—~2.6kAutomated safety check: PassMIT

Similar skills

  • Serenity Alpha

    haskaomni/serenity-skill

    Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…

    633 GitHub stars~2.6k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Scorecard Matrix

    pnp/sharepoint-skills

    Generates a polished, self-contained HTML heatmap scorecard — a weighted comparison matrix where entities (rows) are scored across dimensions (columns), with computed totals, rank badges, and a…

    133 GitHub stars~1.9k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Oma Image

    first-fluke/oh-my-agent

    Generate raster images or reference-guided variations through the OMA image CLI.

    1.3k GitHub stars~2k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Recover source-bound buyer jobs, struggling moments, desired progress, forces, workarounds, information acts, journey states, criteria, constraints, roles, locales, and authentic language.

    1.5k GitHub stars~1.4k tokensUpdated 3 days ago
    Business, Finance & HRAuto-check passed
  • Master Builder

    ibuilder/massing

    Reason like a master builder — one mind holding an entire built-asset project from raw land through design, construction, handover, operations, and disposition, anywhere in the world.

    122 GitHub stars~2.6k tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Energy Procurement

    affaan-m/ECC

    Procure electricity and natural gas for commercial and industrial facilities: tariff and rate-schedule optimization, demand-charge mitigation, supplier RFPs, fixed/index/block-and-index hedging…

    276k GitHub starsUsed in 4 repos~7.4k tokens
    Business, Finance & HRAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Questions about Vendor Management

What does Vendor Management do?

A skill your agent uses when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim…. Vendor Management is an agent skill from alirezarezvani/claude-skills. Use when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim flags, classifying third-party risk across 4 risk vectors, preparing a tier-1 vendor review, or auditing the SaaS portfolio.

When should I use Vendor Management?

Vendor Management fits situations like: auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning; tracking SLA compliance with credit-claim flags; classifying third-party risk across 4 risk vectors; preparing a tier-1 vendor review.

How do I install Vendor Management in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill vendor-management -a claude-code`. Or copy the skill folder (business-operations/skills/vendor-management in alirezarezvani/claude-skills) into .claude/skills/vendor-management in your project. Claude Code loads it when a task matches its description.

How do I install Vendor Management in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill vendor-management -a codex`. Or copy the skill folder (business-operations/skills/vendor-management in alirezarezvani/claude-skills) into .agents/skills/vendor-management in your project. Codex loads it when a task matches its description.

Can I use Vendor Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill vendor-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-management, .gemini/skills/vendor-management, .github/skills/vendor-management and .opencode/skills/vendor-management in your project.

What does Vendor Management need to run?

Going by SKILL.md and its folder, Vendor Management needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Vendor Management access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vendor Management use?

Vendor Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor Management use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.2k tokens, read only when the agent opens those files.

What are the alternatives to Vendor Management?

Skills that share tags, products or a category with Vendor Management: Serenity Alpha (haskaomni/serenity-skill, 633 stars), Scorecard Matrix (pnp/sharepoint-skills, 133 stars), Oma Image (first-fluke/oh-my-agent, 1.3k stars) and Buyer Job Intent Analysis (elvisun/newsjack, 1.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor Management?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,938 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.