Agent skill

Vendor Management

by borghei in borghei/Claude-Skills

Vendor lifecycle — weighted selection scorecards, risk tiering, renewal and notice-deadline tracking, spend concentration, and SLA credits.

MITAuto-check passedBusiness, Finance & HR

Install Vendor Management

skills CLI
$ npx skills add borghei/Claude-Skills --skill vendor-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills vendor-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/business-operations/vendor-management .claude/skills/vendor-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-management
GitHub stars
886
Token cost
~3.3k tokens
SKILL.md length
1,713 words
Files
11 (incl. scripts, references, assets)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

Vendor lifecycle — weighted selection scorecards, risk tiering, renewal and notice-deadline tracking, spend concentration, and SLA credits.

  • Works in 5 steps: Agree weighted criteria and the… → Define anchors for each criterion — what… → Score each candidate against evidence… → …
  • Selecting a vendor
  • SKILL.md covers When to use this skill, Inputs the skill expects, Clarify First and Workflows, plus 3 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Vendor Management is an agent skill from borghei/Claude-Skills. Vendor lifecycle — weighted selection scorecards, risk tiering, renewal and notice-deadline tracking, spend concentration, and SLA credits. Use when selecting a vendor, preparing a renewal, or reviewing a vendor portfolio.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts, reference files and assets (for example `assets/sample_portfolio.json`, `assets/sample_sla.json` and `assets/sample_vendor_candidates.json`).

It sits in Business, Finance & HR, covering Vendor and procurement management and Operations and SOPs. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Selecting a vendor
  • Preparing a renewal
  • Reviewing a vendor portfolio

Example prompts

  • “/vendor-management”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Agree weighted criteria and the must-have list before looking at any candidate. Record who agreed them and when.
  2. Define anchors for each criterion — what a 10 looks like and what a 5 looks like. This is what stops the scorecard becoming post-hoc…
  3. Score each candidate against evidence (demo, reference call, document reviewed), not impression. Note the evidence in the scorecard.
  4. Run the scorer and read the stability check before the ranking. A margin under 5% is a tie — decide it on commercial terms, exit cost, or…
  5. If the result flips when a weight moves 50%, take that criterion back to the decision owner before proceeding.

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor Management loads about 3.3k tokens when it runs, and up to ~8.1k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 1,713 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 1,713 words, ~3,302 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-management/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
vendor-management
description
Vendor lifecycle — weighted selection scorecards, risk tiering, renewal and notice-deadline tracking, spend concentration, and SLA credits. Use when selecting a vendor, preparing a renewal, or reviewing a vendor portfolio.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
business-operations
metadata.domain
procurement
metadata.updated
2026-07-21
metadata.tags
vendor-management, procurement, sla, renewal, third-party-risk

Vendor Management

Covers the vendor lifecycle from selection to exit. Two failures dominate this discipline: tiering vendors by spend rather than by blast radius, and losing every point of renewal leverage to a missed notice deadline. This skill is built around preventing both.

When to use this skill

  • Selecting a vendor and needing a scorecard that survives scrutiny
  • A renewal is approaching and the notice deadline needs to be found before it passes
  • Reviewing the vendor portfolio for concentration, risk tier coverage, and consolidation
  • Preparing a business review with SLA performance and credits owed
  • A vendor is underperforming and the case needs to be built on trend, not anecdote
  • Planning an exit and needing the sequence right

Inputs the skill expects

  • For selection: weighted criteria, must-have requirements, and 0-10 scores per vendor with evidence
  • For the portfolio: annual spend, category, renewal date, notice days, and auto-renew flag per vendor
  • Risk inputs per vendor: data classification, business criticality, alternative availability, subprocessor use
  • Internal owner per contract
  • For SLA reporting: committed metrics with target, actual, direction, credit tiers, and prior-period history
  • Annual contract value and the contractual credit cap

Clarify First

Before generating, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Is the notice deadline known, or only the renewal date? — the notice deadline is what constrains action, and missing it removes all leverage for a full term
  • Were the scoring weights set before any vendor was scored? — weights chosen after seeing candidates produce a justification, not a decision
  • What does this vendor actually hold or touch? — data sensitivity and criticality drive the risk tier; spend does not
  • Which must-haves are genuinely pass/fail? — every entry on that list eliminates a candidate, so preferences belong in the weighted criteria

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.

Workflows

Workflow 1 — Select a vendor
  1. Agree weighted criteria and the must-have list before looking at any candidate. Record who agreed them and when.
  2. Define anchors for each criterion — what a 10 looks like and what a 5 looks like. This is what stops the scorecard becoming post-hoc justification.
  3. Score each candidate against evidence (demo, reference call, document reviewed), not impression. Note the evidence in the scorecard.
  4. Run the scorer and read the stability check before the ranking. A margin under 5% is a tie — decide it on commercial terms, exit cost, or reference calls instead.
  5. If the result flips when a weight moves 50%, take that criterion back to the decision owner before proceeding.
bash
python3 business-operations/vendor-management/scripts/vendor_scorecard.py \
  --input business-operations/vendor-management/assets/sample_vendor_candidates.json \
  --format text
Workflow 2 — Review the portfolio
  1. Build the vendor list with renewal date, notice days, and auto-renew flag. The notice deadline is derived, and it is the date that matters.
  2. Set as_of explicitly so the analysis is reproducible and reviewable later.
  3. Run the analyser and work the urgent renewals first — anything marked LOCKED has already lost its negotiating window for this term.
  4. Check concentration in both forms: single-vendor share above 25-30% is a dependency, and category HHI tells you whether you have leverage or diversification.
  5. Treat every unowned contract as a future auto-renewal. Assign an owner before anything else in the report.
bash
python3 business-operations/vendor-management/scripts/portfolio_analyzer.py \
  --input business-operations/vendor-management/assets/sample_portfolio.json \
  --format text
Workflow 3 — Run an SLA review
  1. Collect committed metrics with target, actual, direction, and credit tiers. Include prior periods — the trend is the argument.
  2. Run the report and check credits earned against the contractual cap. Credits exceeding the cap mean the remedy structure is too weak to change behaviour.
  3. Claim the credits. Unclaimed credits are the norm, and most contracts require you to ask.
  4. Escalate severe breaches to the contract owner, not the account manager — the account manager cannot change the terms that caused it.
  5. Carry the findings into the renewal ask: credit tiers that bite, and a termination right after repeated breach.
bash
python3 business-operations/vendor-management/scripts/sla_report.py \
  --input business-operations/vendor-management/assets/sample_sla.json \
  --format json

Decision frameworks

Risk tiering [PROVEN]

Score data sensitivity plus business criticality, then apply modifiers.

Data classificationPointsBusiness criticalityPoints
PHI / health4Critical (revenue stops in hours)4
PII3High (core function stops in a day)3
Financial3Medium (productivity loss)2
Confidential2Low (inconvenience)1
Internal1
Public0

Modifiers: no ready alternative +2 · network access to your systems +2 · subprocessors +1 · non-adequate jurisdiction +1 · vendor under 20 people +1.

TotalTierCore obligations
8+Tier 1 criticalAnnual security review, quarterly business review, tested exit plan, SLA with credits
6-7Tier 2 highFull questionnaire at onboarding, semi-annual review, documented exit plan
4-5Tier 3 moderateShort-form questionnaire, annual review, verified data export
Under 4Tier 4 lowConfirm what data it touches; nothing further

Tier by blast radius, not spend. The $8K tool holding your entire customer list outranks the $400K hosting contract holding nothing sensitive.

Where renewal leverage comes from [PROVEN]
SourceWorthRequires
A real alternative10-30%3-6 weeks of genuine evaluation, an internal sponsor willing to switch
Vendor fiscal timing10-25%Knowing their year-end and aligning your close to it
Multi-year commitment10-20%Price protection, exit-on-SLA-failure, and an increase cap — all three
Volume / consolidation15-30%Real growth, not aspirational seat counts
Reference or case study5-15%Marketing time, not money
Annual prepay5-10%Cash-flow float, and a viability check first

Not leverage: complaining about price, threatening to leave without an alternative, escalating without a specific ask, or loyalty — long tenure lowers vendor risk, which is why tenured accounts are often priced higher.

Renewal calendar [PROVEN]
Days before renewalAction
180Usage vs entitlement; confirm owner; decide renew / renegotiate / exit
150Open the alternative evaluation if renegotiating seriously
120First vendor conversation — signal expectations before they build the quote
90Notice deadline on most annual contracts. Serve notice if there is any doubt.
60Negotiate substance: price, increase cap, true-down, SLA credits, exit rights
30Close; anything open now resolves in the vendor's favour

Serving notice is not leaving — it converts an auto-renewal into a negotiation.

Show full SKILL.md (714 more words)Show less
TermTarget
Annual increase capCPI, or 3-5% maximum
Seat true-down rightsAt renewal, without penalty
Termination for SLA failureDefined breach threshold, no penalty
Data export formatOpen, documented, and tested
Subprocessor change notice30 days with an objection right
Assignment on acquisitionConsent required, or an exit right

Seat true-down is the most valuable and least-requested term: nearly every SaaS contract lets you add seats mid-term and forbids reducing them.

Anti-Patterns

Tiering by spend

Mistake: Applying diligence proportional to contract value — heavy scrutiny on the big infrastructure contract, a credit card and no questions for the $8,000 tool. Why it happens: Procurement owns the process and procurement thresholds are denominated in money. Approval workflows trigger on spend because that is what finance systems can see. Instead: Tier on data sensitivity and business criticality, with modifiers for substitutability and subprocessors. The small tool holding your customer list has a far larger blast radius than the large contract holding nothing sensitive, and it is exactly the one that gets bought on a card without a security review.

Discovering the notice deadline after it passes

Mistake: Tracking renewal dates only, then finding at day 60 that the 90-day notice window closed a month ago and the contract has auto-renewed for another year. Why it happens: Renewal dates are what contracts and calendars display. The notice deadline is a derived date nobody computes, and auto-renew clauses are written to be easy to miss. Instead: Track both dates per contract, and treat the notice deadline as the real one. Serve notice at the deadline as routine on anything you intend to renegotiate — it reopens the contract without committing you to leave. An unowned contract is the one this happens to, so assign an internal owner to every vendor.

The scorecard that ratifies a decision already made

Mistake: Choosing the vendor, then building a weighted scorecard whose weights and scores produce that vendor as the winner. Why it happens: Rarely cynical. Someone forms a view during the demos, and weights get set afterwards with that view in the room — each individual weight feels defensible while the set of them is not. Instead: Set and record the weights, with named anchors for what a 10 and a 5 look like, before any candidate is scored. Then run the sensitivity check: if the winner changes when one weight moves 50%, the result is an artifact of the weighting rather than a finding about the vendors, and the decision owner needs to see that before signing.

Treating the SLA as a control

Mistake: Accepting a 99.9% uptime commitment with a 2% service credit and considering the risk managed. Why it happens: The SLA exists, it has numbers in it, and it satisfies the checklist item. Nobody computes what the credit is actually worth against what an outage costs. Instead: Price the remedy. A 2% credit on a $20K quarter is $400 for an outage that may cost you far more — that is a rounding error the vendor has already priced in, not a control. Negotiate tiered credits (5/10/25%), a cap above 20% of period fees, and a termination right after repeated breach. Losing the account changes vendor behaviour; credits do not. And measure availability against the error budget, not the percentage — missing 99.9% by half a point is nearly six times the permitted downtime.

Files

FilePurpose
scripts/vendor_scorecard.pyMust-have gating, weighted scoring, cost-value ratio, and a weight-sensitivity check on the result
scripts/portfolio_analyzer.pyRenewal and notice-deadline tracking, derived risk tiers, HHI spend concentration, consolidation candidates
scripts/sla_report.pySLA compliance with error-budget severity, credit tiers against the contractual cap, and multi-period trend
references/vendor-risk-tiering.mdTiering model, per-tier obligations, onboarding diligence, concentration risk, monitoring signals, vendor distress indicators
references/renewal-negotiation-leverage.mdRenewal calendar, ranked leverage sources, terms beyond price, making SLAs bite, negotiation sequence, exit execution
assets/vendor-selection-scorecard.mdSelection deliverable: must-haves, weighted criteria with anchors, stability check, risk tier, commercial position
assets/vendor-review-template.mdBusiness review: SLA performance, usage vs entitlement, risk checks, renewal plan with milestone dates
assets/sample_vendor_candidates.jsonFour candidates including one disqualified on a must-have and a near-tie between the top two
assets/sample_portfolio.jsonTen-vendor portfolio with a locked auto-renewal, an unowned contract, and a consolidation candidate
assets/sample_sla.jsonFive metrics in both directions with credit tiers, a capped credit total, and a degrading trend

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts, references, assets) in business-operations/vendor-management of borghei/Claude-Skills.

  • SKILL.md
  • assets/sample_portfolio.json
  • assets/sample_sla.json
  • assets/sample_vendor_candidates.json
  • assets/vendor-review-template.md
  • assets/vendor-selection-scorecard.md
  • references/renewal-negotiation-leverage.md
  • references/vendor-risk-tiering.md
  • scripts/portfolio_analyzer.py
  • scripts/sla_report.py
  • scripts/vendor_scorecard.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Vendor Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor Management this skillborghei/Claude-Skills886—~3.3kAutomated safety check: PassMIT
Process Mapperalirezarezvani/claude-skills28k—~2.2kAutomated safety check: PassMIT
Business Operations Skillsalirezarezvani/claude-skills28k—~2.3kAutomated safety check: PassMIT
Construction LawLeoYeAI/openclaw-master-skills2.2k—~2.3kAutomated safety check: PassMIT
Operationstravisjneuman/.claude101—~3.4kAutomated safety check: PassMIT
Carrier Relationship Managementaffaan-m/ECC276k5 repos~5.9kAutomated safety check: PassApache-2.0

Similar skills

  • Process Mapper

    alirezarezvani/claude-skills

    A skill your agent uses when a BizOps lead, COO, or process-improvement owner needs to document an end-to-end business process (procurement, employee onboarding, incident handoff…

    28k GitHub stars~2.2k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Business Operations Skills

    alirezarezvani/claude-skills

    A skill your agent uses when running, diagnosing, or designing internal business operations — process documentation, vendor SLAs, capacity planning, internal comms, SOP/runbook authoring…

    28k GitHub stars~2.3k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Construction Law

    LeoYeAI/openclaw-master-skills

    Construction law analysis covering FIDIC (2017 suite), PSSCOC, SIA Conditions, NEC4, and JCT.

    2.2k GitHub stars~2.3k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Operations

    travisjneuman/.claude

    Operations excellence expertise for supply chain optimization, process improvement (Lean, Six Sigma), capacity planning, vendor management, quality assurance, and operational efficiency.

    101 GitHub stars~3.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Supports freight managers in sourcing and vetting carriers, running RFPs, negotiating rates, building routing guides and scoring carrier performance.

    276k GitHub starsUsed in 5 repos~5.9k tokens
    Business, Finance & HRAuto-check passed
  • Serenity Alpha

    haskaomni/serenity-skill

    Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…

    633 GitHub stars~2.6k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    886 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    886 GitHub stars~4.2k tokensUpdated 2 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    886 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    886 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Vendor Management

What does Vendor Management do?

Vendor lifecycle — weighted selection scorecards, risk tiering, renewal and notice-deadline tracking, spend concentration, and SLA credits. Vendor Management is an agent skill from borghei/Claude-Skills. Vendor lifecycle — weighted selection scorecards, risk tiering, renewal and notice-deadline tracking, spend concentration, and SLA credits.

When should I use Vendor Management?

Vendor Management fits situations like: selecting a vendor; preparing a renewal; reviewing a vendor portfolio.

How do I install Vendor Management in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill vendor-management -a claude-code`. Or copy the skill folder (business-operations/vendor-management in borghei/Claude-Skills) into .claude/skills/vendor-management in your project. Claude Code loads it when a task matches its description.

How do I install Vendor Management in Codex?

Run `npx skills add borghei/Claude-Skills --skill vendor-management -a codex`. Or copy the skill folder (business-operations/vendor-management in borghei/Claude-Skills) into .agents/skills/vendor-management in your project. Codex loads it when a task matches its description.

Can I use Vendor Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill vendor-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-management, .gemini/skills/vendor-management, .github/skills/vendor-management and .opencode/skills/vendor-management in your project.

What does Vendor Management need to run?

Going by SKILL.md and its folder, Vendor Management needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Vendor Management access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vendor Management use?

Vendor Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor Management use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.8k tokens, read only when the agent opens those files.

What are the alternatives to Vendor Management?

Skills that share tags, products or a category with Vendor Management: Process Mapper (alirezarezvani/claude-skills, 28k stars), Business Operations Skills (alirezarezvani/claude-skills, 28k stars), Construction Law (LeoYeAI/openclaw-master-skills, 2.2k stars) and Operations (travisjneuman/.claude, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor Management?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 886 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.