Agent skill

Vendor Due Diligence

by borghei in borghei/Claude-Skills

Assess IT vendors and third-party partners with multi-factor risk scoring and regulatory compliance checklists.

MITAuto-check passedLegal & Compliance

Install Vendor Due Diligence

skills CLI
$ npx skills add borghei/Claude-Skills --skill vendor-due-diligence -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills vendor-due-diligence --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/legal/vendor-due-diligence .claude/skills/vendor-due-diligence && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-due-diligence
GitHub stars
891
Token cost
~3.2k tokens
SKILL.md length
1,249 words
Files
6 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

Assess IT vendors and third-party partners with multi-factor risk scoring and regulatory compliance checklists.

  • Works in 2 steps: Vendor Risk Scorer… → Vendor Comparison…
  • Evaluating technology vendors
  • SKILL.md covers Overview, Table of Contents, Clarify First and Tools, plus 7 more sections
  • Runs Python scripts from its folder; calls python

What it does

Vendor Due Diligence is an agent skill from borghei/Claude-Skills. Assess IT vendors and third-party partners with multi-factor risk scoring and regulatory compliance checklists. Use when evaluating technology vendors.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/monitoring_framework.md`, `references/regulatory_checklists.md` and `references/risk_assessment_framework.md`).

It sits in Legal & Compliance, covering Fundraising and pitch decks, Regulatory compliance and Vendor and procurement management. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Evaluating technology vendors
  • Tasks that involve Fundraising and pitch decks
  • Tasks that involve Regulatory compliance

Example prompts

  • “/vendor-due-diligence”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Vendor Risk Scorer (scripts/vendor_risk_scorer.py)
  2. Vendor Comparison (scripts/vendor_comparison.py)

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor Due Diligence loads about 3.2k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 43 tokens; SKILL.md has 1,249 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 1,249 words, ~3,171 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-due-diligence/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
vendor-due-diligence
description
Assess IT vendors and third-party partners with multi-factor risk scoring and regulatory compliance checklists. Use when evaluating technology vendors.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
The Glass Room
metadata.category
legal
metadata.domain
vendor-assessment
metadata.updated
2026-04-10
metadata.tags
vendor-assessment, due-diligence, risk-scoring, compliance, third-party-risk

⚠️ EXPERIMENTAL — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output.

Vendor Due Diligence Skill

Overview

Production-ready framework for assessing IT service providers, technology vendors, and third-party partners. Provides a Three-Phase Assessment (Initial Screening, Detailed Assessment, Final Evaluation), Multi-Factor Risk Scoring across 6 dimensions with critical-service weighting, regulatory compliance checklists for 8 frameworks, vendor comparison matrices, and ongoing monitoring with Early Warning Indicators. Designed for procurement teams, legal counsel, IT security, and compliance officers evaluating technology vendors.

Table of Contents

Clarify First

Before scoring the vendor, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Is the service critical/essential — the --critical flag applies a 2x weight to security and compliance, which can flip the composite score and the Approve/Reject recommendation
  • Applicable regulatory frameworks — GDPR, DORA, NIS2, SOX, PCI DSS, ISO 27001/SOC 2, HIPAA, FedRAMP — selects which compliance checklists run
  • Questionnaire responses + independent evidence — the 6-dimension scores; self-reported-only data inflates scores, so confirm whether SOC 2 / pen-test / financial evidence backs them

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the assessment.

Tools

1. Vendor Risk Scorer (scripts/vendor_risk_scorer.py)

Scores a vendor across 6 risk dimensions based on questionnaire responses. Calculates weighted composite score with 2x multiplier for critical services. Generates risk heat map and overall recommendation.

bash
# Score a vendor from questionnaire responses
python scripts/vendor_risk_scorer.py vendor_responses.json

# JSON output for dashboards
python scripts/vendor_risk_scorer.py vendor_responses.json --json

# Flag as critical service (2x weight on security + compliance)
python scripts/vendor_risk_scorer.py vendor_responses.json --critical
2. Vendor Comparison (scripts/vendor_comparison.py)

Takes multiple vendor risk assessment JSONs and generates a side-by-side comparison matrix. Ranks vendors by composite score and recommends preferred vendor with rationale.

bash
# Compare two vendors
python scripts/vendor_comparison.py vendor_a.json vendor_b.json

# Compare multiple vendors with JSON output
python scripts/vendor_comparison.py vendor_a.json vendor_b.json vendor_c.json --json

# Compare with critical service weighting
python scripts/vendor_comparison.py vendor_a.json vendor_b.json --critical

Reference Guides

ReferencePurpose
references/risk_assessment_framework.md6-dimension scoring system, weighting methodology, composite score interpretation
references/regulatory_checklists.mdPre-built compliance checklists for GDPR, DORA, NIS2, SOX, PCI DSS, ISO 27001/SOC 2, HIPAA, FedRAMP
references/monitoring_framework.mdQuarterly reviews, Early Warning Indicators, KPI metrics, risk mitigation strategies, onboarding checklists

Workflows

Workflow 1: Three-Phase Vendor Assessment

Phase 1: Initial Screening (Days 1-5)

  1. Gather basic vendor information (company profile, financial health, certifications)
  2. Run vendor_risk_scorer.py with preliminary data for initial risk classification
  3. Check applicable regulatory frameworks from regulatory_checklists.md
  4. Decision gate: Proceed to detailed assessment or reject early

Phase 2: Detailed Assessment (Days 5-15)

  1. Issue comprehensive vendor questionnaire covering all 6 risk dimensions
  2. Run vendor_risk_scorer.py with complete questionnaire responses
  3. Execute regulatory compliance checklists for all applicable frameworks
  4. Request supporting documentation (SOC 2 reports, pen test results, financials)
  5. Conduct reference checks and public record searches

Phase 3: Final Evaluation (Days 15-20)

  1. Run vendor_comparison.py if evaluating multiple vendors
  2. Compile Vendor Risk Report with dimension breakdowns
  3. Document gaps and required mitigations from risk_assessment_framework.md
  4. Present recommendation (Approve / Approve with Conditions / Reject)
  5. If approved, generate onboarding checklist from monitoring_framework.md
Workflow 2: Competitive Vendor Selection
  1. Define requirements -- Document must-have and nice-to-have criteria mapped to risk dimensions
  2. Screen candidates -- Run initial scoring on all candidates; eliminate any with Critical risk
  3. Deep-dive finalists -- Full 6-dimension assessment on top 2-3 vendors
  4. Compare -- Run vendor_comparison.py on finalist assessments
  5. Negotiate -- Use risk findings as leverage in contract negotiations (integrates with tech-contract-negotiation skill)
  6. Select and onboard -- Approve preferred vendor; set up monitoring per monitoring_framework.md
Workflow 3: Ongoing Vendor Monitoring
  1. Quarterly review -- Re-score vendor using updated data; compare against baseline
  2. Event-triggered review -- Re-assess on M&A, breaches, regulatory changes, or leadership turnover
  3. Annual re-assessment -- Full 6-dimension re-evaluation with updated questionnaire
  4. Early Warning response -- Monitor indicators from monitoring_framework.md; escalate per defined paths
  5. Exit planning -- If risk exceeds threshold, activate exit provisions and dual-source strategy

Troubleshooting

ProblemCauseSolution
All dimensions score 1 (Low Risk)Vendor self-reported optimistically on questionnaireCross-reference with SOC 2 reports, pen test results, and financial filings; adjust scores based on evidence
Composite score doesn't reflect known security issuesSecurity dimension not weighted for critical serviceRe-run with --critical flag to apply 2x multiplier on security and compliance dimensions
Comparison matrix shows all vendors tiedScoring inputs are too similar or too coarseRequest more granular data; use the 5-level scoring criteria from the risk framework to differentiate
Regulatory checklist seems incomplete for your industryOnly 8 frameworks are pre-builtCustomize checklists by adding industry-specific requirements as additional items
Vendor refuses to complete questionnaireVendor sees assessment as overly burdensomeShare only the dimensions relevant to their service scope; offer to accept SOC 2/ISO 27001 reports as partial substitutes
Risk score changed dramatically between quartersMajor event occurred (breach, M&A, leadership change)This is expected behavior; document the trigger event and follow the event-triggered review process
Show full SKILL.md (472 more words)Show less

Success Criteria

  • Assessment Completeness: 100% of vendor assessments cover all 6 risk dimensions with evidence-backed scores
  • Timeline Adherence: Three-phase assessment completed within 20 business days for 90% of evaluations
  • Risk Prediction Accuracy: Vendors flagged as High/Critical risk experience 3x more incidents than Low risk vendors over 12 months
  • Regulatory Coverage: All applicable regulatory checklists completed with zero missed frameworks for 95% of assessments
  • Comparison Consistency: Vendor comparison rankings remain stable when re-scored by different assessors (inter-rater reliability > 85%)
  • Monitoring Compliance: 100% of quarterly reviews completed on schedule with documented findings
  • Early Warning Detection: 80%+ of vendor incidents preceded by at least one Early Warning Indicator flagged in monitoring

Scope & Limitations

This skill covers:

  • Multi-factor risk scoring across 6 dimensions (Financial, Operational, Compliance, Security, Reputational, Strategic) with critical-service weighting
  • Regulatory compliance checklists for GDPR, DORA, NIS2, SOX, PCI DSS, ISO 27001/SOC 2, HIPAA, and FedRAMP
  • Side-by-side vendor comparison with composite ranking and dimension-level analysis
  • Ongoing monitoring framework with quarterly reviews, Early Warning Indicators, and escalation paths
  • Risk mitigation strategies and onboarding checklists by risk level

This skill does NOT cover:

  • Real-time vendor monitoring dashboards, automated data feeds, or integration with GRC platforms (all input is via JSON files)
  • Financial auditing, forensic accounting, or detailed financial statement analysis of vendors (use the finance/financial-analyst skill)
  • Physical security assessments, on-site facility audits, or hardware supply chain verification
  • Legal review of vendor contracts or negotiation of terms (use the legal/tech-contract-negotiation skill)
  • Vendor relationship management, performance optimization, or strategic partnership development beyond risk assessment

Anti-Patterns

Anti-PatternWhy It FailsBetter Approach
Relying solely on vendor self-assessment questionnairesVendors underreport risks; no independent verificationCross-reference questionnaire responses with SOC 2/ISO 27001 reports, pen test results, and public records
Applying the same weight to all dimensions regardless of service typeA payroll vendor and a marketing tool have different risk profilesUse --critical flag for critical services; adjust dimension weights based on service classification
Completing due diligence once and never revisitingVendor risk changes over time due to M&A, breaches, market shiftsImplement quarterly monitoring with annual re-assessment per the monitoring framework
Rejecting vendors for a single high-risk dimension without considering mitigationsEliminates potentially strong vendors with addressable gapsUse the gap analysis severity classification; require remediation plans for major concerns before final decision
Skipping the comparison matrix for sole-source procurementsMisses opportunity to benchmark the vendor against market standardsRun comparison against industry benchmarks or previous vendor assessments to establish a risk baseline

Tool Reference

scripts/vendor_risk_scorer.py

Score a vendor across 6 risk dimensions and generate an overall recommendation.

usage: vendor_risk_scorer.py [-h] [--json] [--critical]
                              input_file

positional arguments:
  input_file            Path to JSON file with vendor questionnaire responses

options:
  -h, --help            Show help message and exit
  --json                Output results as JSON
  --critical            Apply 2x weight to security and compliance
                        dimensions (for critical/essential services)

Outputs: 6-dimension risk scores (1-5 each), weighted composite score, risk level classification (Low/Moderate/High/Critical), overall recommendation (Approve/Approve with Conditions/Reject), dimension-level findings, and gap analysis.

scripts/vendor_comparison.py

Compare multiple vendors side-by-side and recommend preferred vendor.

usage: vendor_comparison.py [-h] [--json] [--critical]
                             input_files [input_files ...]

positional arguments:
  input_files           Paths to vendor assessment JSON files (minimum 2)

options:
  -h, --help            Show help message and exit
  --json                Output results as JSON
  --critical            Apply 2x weight to security and compliance
                        dimensions (for critical/essential services)

Outputs: Side-by-side comparison matrix, composite score ranking, per-dimension strength/weakness analysis, preferred vendor recommendation with rationale, and risk delta highlights.

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in legal/vendor-due-diligence of borghei/Claude-Skills.

  • SKILL.md
  • references/monitoring_framework.md
  • references/regulatory_checklists.md
  • references/risk_assessment_framework.md
  • scripts/vendor_comparison.py
  • scripts/vendor_risk_scorer.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Vendor Due Diligence next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor Due Diligence compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor Due Diligence this skillborghei/Claude-Skills891—~3.2kAutomated safety check: PassMIT
Gc Reviewalirezarezvani/claude-skills28k—~1.2kAutomated safety check: PassMIT
Sec Analyst MasterOctagonAI/skills127—~2.2kAutomated safety check: PassMIT
Contract Legal Researchinfometa/workbuddyskills348—~2.1kAutomated safety check: PassNone
Officecli Word FormFerroxLabs/wayland6083 repos~14kAutomated safety check: PassAGPL-3.0
Meeting Briefing Anthropiclawve-ai/awesome-legal-skills8471 repos~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Gc Review

    alirezarezvani/claude-skills

    /cs:gc-review <plan — General Counsel interrogation of contracts, IP, regulatory, term sheets, and employment-law surface.

    28k GitHub stars~1.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Sec Analyst Master

    OctagonAI/skills

    Comprehensive SEC filing analyst skill that orchestrates all Octagon SEC analysis skills.

    127 GitHub stars~2.2k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check passed
  • Contract Legal Research

    infometa/workbuddyskills

    Retrieve the legal basis and due-diligence facts that contract work depends on — supporting statutes and their effectiveness status, regulatory requirements, mandatory provisions for the contract…

    348 GitHub stars~2.1k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Officecli Word Form

    FerroxLabs/wayland

    A skill your agent uses to create fillable Word forms (.docx) with real Content Controls (SDT) + legacy FormField checkboxes + MERGEFIELD mail-merge placeholders + document protection.

    608 GitHub starsUsed in 3 repos~14k tokens
    Documents & OfficeAuto-check passed
  • Meeting Briefing Anthropic

    lawve-ai/awesome-legal-skills

    Prepare structured briefings for meetings with legal relevance and track resulting action items.

    847 GitHub starsUsed in 1 repo~2.3k tokens
    Productivity & AutomationAuto-check passed
  • Anti Money Laundering

    JoelLewis/finance_skills

    Guide BSA/AML compliance program design, ongoing transaction monitoring, and FinCEN reporting for broker-dealers, banks, and investment advisers.

    206 GitHub stars~6.2k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    891 GitHub stars~3.1k tokensUpdated 4 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    891 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    891 GitHub stars~3.6k tokensUpdated 4 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    891 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    891 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check passed

Questions about Vendor Due Diligence

What does Vendor Due Diligence do?

Assess IT vendors and third-party partners with multi-factor risk scoring and regulatory compliance checklists. Vendor Due Diligence is an agent skill from borghei/Claude-Skills. Assess IT vendors and third-party partners with multi-factor risk scoring and regulatory compliance checklists.

When should I use Vendor Due Diligence?

Vendor Due Diligence fits situations like: evaluating technology vendors; tasks that involve Fundraising and pitch decks; tasks that involve Regulatory compliance.

How do I install Vendor Due Diligence in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill vendor-due-diligence -a claude-code`. Or copy the skill folder (legal/vendor-due-diligence in borghei/Claude-Skills) into .claude/skills/vendor-due-diligence in your project. Claude Code loads it when a task matches its description.

How do I install Vendor Due Diligence in Codex?

Run `npx skills add borghei/Claude-Skills --skill vendor-due-diligence -a codex`. Or copy the skill folder (legal/vendor-due-diligence in borghei/Claude-Skills) into .agents/skills/vendor-due-diligence in your project. Codex loads it when a task matches its description.

Can I use Vendor Due Diligence in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill vendor-due-diligence -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-due-diligence, .gemini/skills/vendor-due-diligence, .github/skills/vendor-due-diligence and .opencode/skills/vendor-due-diligence in your project.

What does Vendor Due Diligence need to run?

Going by SKILL.md and its folder, Vendor Due Diligence needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Vendor Due Diligence access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor Due Diligence safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vendor Due Diligence use?

Vendor Due Diligence is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor Due Diligence use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Vendor Due Diligence?

Skills that share tags, products or a category with Vendor Due Diligence: Gc Review (alirezarezvani/claude-skills, 28k stars), Sec Analyst Master (OctagonAI/skills, 127 stars), Contract Legal Research (infometa/workbuddyskills, 348 stars) and Officecli Word Form (FerroxLabs/wayland, 608 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor Due Diligence?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.