Agent skill

Vendor Due Diligence Patrick Munro

by lawve-ai in lawve-ai/awesome-legal-skills

Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.

AGPL-3.0Auto-check passedLegal & Compliance

Install Vendor Due Diligence Patrick Munro

skills CLI
$ npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lawve-ai/awesome-legal-skills vendor-due-diligence-patrick-munro --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vendor-due-diligence-patrick-munro .claude/skills/vendor-due-diligence-patrick-munro && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-due-diligence-patrick-munro
GitHub stars
847
Token cost
~4.1k tokens
SKILL.md length
1,850 words
Files
3
Skills in repo
154
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.

  • Works in 8 steps: Three-Phase Assessment Process → Detailed Assessment Dimensions → Six-Dimension Risk Scoring → …
  • Evaluating new vendors
  • SKILL.md covers Overview, LEGAL DISCLAIMER, When to Use This Skill and Core Capabilities, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vendor Due Diligence Patrick Munro is an agent skill from lawve-ai/awesome-legal-skills. Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR. Provides three-phase process (Initial Screening / Detailed Assessment / Final Evaluation), six-dimension risk scoring (Financial/Operational/Compliance/Security/Reputational/Strategic) with weighted matrices, full DORA Art. 28-30 contractual checklist, NIS2 Art. 21(2) security measures enumeration, GDPR Art. 28 documentation checks, red flags per dimension, trigger-based review…

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `README.md`).

It sits in Legal & Compliance, covering Fundraising and pitch decks, Privacy and GDPR and Supply chain security. The repository describes itself as: A curated list of awesome Agent Skills for automating legal work. The licence is AGPL-3.0.

When your agent uses it

  • Evaluating new vendors
  • Technology providers
  • Conducting critical ICT third-party due diligence under DORA
  • Performing supply chain security assessment under NIS2

Example prompts

  • “/vendor-due-diligence-patrick-munro”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Three-Phase Assessment Process
  2. Detailed Assessment Dimensions
  3. Six-Dimension Risk Scoring
  4. DORA Critical Vendor Assessment
  5. NIS2 Vendor Assessment
  6. Risk Mitigation Strategies
  7. Ongoing Vendor Management
  8. Output Formats

What it can do on your machine

Read from SKILL.md and the folder at commit 045f738. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor Due Diligence Patrick Munro loads about 4.1k tokens when it runs. Until then it costs about 236 tokens; SKILL.md has 1,850 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~236
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from lawve-ai/awesome-legal-skills at commit 045f738, republished under its AGPL-3.0 licence (© lawve-ai). 1,850 words, ~4,102 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-due-diligence-patrick-munro/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
vendor-due-diligence-patrick-munro
description
Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR. Provides three-phase process (Initial Screening / Detailed Assessment / Final Evaluation), six-dimension risk scoring (Financial/Operational/Compliance/Security/Reputational/Strategic) with weighted matrices, full DORA Art. 28-30 contractual checklist, NIS2 Art. 21(2) security measures enumeration, GDPR Art. 28 documentation checks, red flags per dimension, trigger-based review criteria, and document templates. Use when: (1) Evaluating new vendors or technology providers, (2) Conducting critical ICT third-party due diligence under DORA, (3) Performing supply chain security assessment under NIS2, (4) Creating vendor onboarding documentation, (5) Establishing ongoing vendor monitoring, (6) Assessing concentration risk, or (7) Generating executive vendor risk reports.
metadata.author
Patrick Munro
metadata.license
agpl-3.0
metadata.version
2026-04-25

Vendor Due Diligence Framework

Overview

Risk-based vendor assessment framework that identifies material risks early, ensures DORA/NIS2/GDPR compliance, and provides clear recommendations for selection, contract calibration, and ongoing management. Built for regulated sectors (financial services under DORA, KRITIS sectors under NIS2) and for any organisation with meaningful ICT third-party exposure.

This skill provides frameworks for vendor assessment purposes only. It does not constitute legal, financial, or professional advice. Users should:

  • Consult qualified legal counsel for specific requirements in their jurisdiction;
  • Engage financial and security professionals for detailed assessments;
  • Verify all regulatory requirements independently;
  • Adapt frameworks to specific organisational needs and risk tolerance;
  • Not rely on this skill as a substitute for professional due diligence services.

The frameworks are templates. Actual assessments require expertise in law, finance, cybersecurity, and risk management. Neither the skill creator nor Claude/Anthropic assumes liability for decisions made based on this skill's output.

Regulatory references current as of 2026-04-23. EU (DORA, NIS2, GDPR) and German (NIS2UmsuCG, BDSG) citations reflect the consolidated text available at that date. Member State NIS2 transposition remains uneven; Germany's NIS2UmsuCG entered into force on 6 December 2025 with the BSI reporting portal opening on 6 January 2026. Verify the current consolidated text and national transposition status on EUR-Lex and the Bundesgesetzblatt before use.

When to Use This Skill

  • Evaluating new vendors, technology providers, or service partners;
  • Conducting critical ICT third-party due diligence under DORA Art. 28-30;
  • Supply chain security assessment under NIS2 Art. 21(2)(d);
  • GDPR Art. 28 processor due diligence;
  • Vendor onboarding documentation and assessment;
  • Ongoing monitoring frameworks (quarterly, annual, trigger-based);
  • Concentration risk assessment;
  • Executive-level vendor risk reports.

Core Capabilities

1. Three-Phase Assessment Process

Phase 1: Initial Screening (1-2 days): rapid assessment to determine whether a vendor warrants detailed evaluation.

  • Basic information verification (company registration, leadership, business model, customer base);
  • Quick risk indicators (recent negative news, public financial data, compliance claims, basic technical architecture);
  • Go/no-go decision with initial screening memo.

Phase 2: Detailed Assessment (1-2 weeks): comprehensive evaluation across all risk dimensions. See Section 2.

Phase 3: Final Evaluation (3-5 days): synthesis, risk scoring, mitigation strategies, recommendation.

2. Detailed Assessment Dimensions
Financial Due Diligence

Documents to request: 3 years audited financial statements; commercial credit report; professional liability insurance (€5M minimum); cyber insurance (€5M minimum for IT vendors); banking references.

Analysis: revenue trends and profitability; debt levels and liquidity ratios; customer concentration risk; financial stability score (1-5).

Red flags: consistent losses or negative cash flow; high customer concentration (>30% revenue from one client); recent credit downgrades; inadequate insurance coverage.

Documents to request: articles of incorporation and bylaws; material contracts (top 5 customers and suppliers); pending and historical litigation; regulatory filings; IP portfolio; data protection policies and GDPR documentation; subprocessor list (if data processor).

GDPR compliance review (Art. 28 GDPR): privacy policy and notices; DPA template; breach incident response procedures; international data transfer mechanisms (SCCs, adequacy); Art. 30 records of processing; DPIA process for high-risk processing.

Industry-specific: financial services clients - DORA compliance (Art. 28-30); KRITIS sectors - NIS2 compliance (Art. 21); AI systems - AI Act classification and compliance.

Red flags: pending significant litigation (>10% annual revenue); regulatory enforcement actions; material IP infringement claims; GDPR non-compliance (no DPA, inadequate security).

Security and Technical Due Diligence

Documents to request: security certifications (ISO 27001, SOC 2 Type II, PCI DSS where applicable); recent penetration testing results; security incident history (3 years); business continuity and disaster recovery plans; backup procedures and testing records; technical architecture diagrams; data residency documentation; subprocessor security assessments.

Security assessment: encryption standards (at rest and in transit); access controls and identity management; vulnerability management program; security awareness training; incident response procedures and SLAs; third-party security audits.

NIS2 Art. 21(2) security measures (for KRITIS vendors), mapped to the ten statutory sub-paragraphs:

  • (a) Risk analysis and information system security policies;
  • (b) Incident handling;
  • (c) Business continuity (backup management and disaster recovery) and crisis management;
  • (d) Supply chain security, including security-related aspects of relationships with direct suppliers and service providers;
  • (e) Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
  • (f) Policies and procedures to assess the effectiveness of cybersecurity risk-management measures;
  • (g) Basic cyber hygiene practices and cybersecurity training;
  • (h) Policies and procedures on the use of cryptography and, where appropriate, encryption;
  • (i) Human resources security, access control policies, and asset management;
  • (j) Multi-factor authentication or continuous authentication, secured voice/video/text communications, and secured emergency communication systems where appropriate.

DORA ICT risk management (for financial services vendors): Art. 6-16 ICT risk management framework; Art. 17-23 incident management; Art. 24-27 digital operational resilience testing; Art. 28-30 third-party risk monitoring.

Red flags: no ISO 27001 or equivalent; no SOC 2 Type II; recent major security incidents with inadequate response; inadequate backup and DR; data residency non-compliance.

Operational Due Diligence

Documents to request: SLA performance history (12 months minimum); customer satisfaction metrics; support structure and escalation procedures; change management and release procedures; service availability statistics; MTTR data.

Analysis: service delivery track record; support responsiveness; technical competency; scalability; exit/transition procedures.

Red flags: consistent SLA failures; poor customer references; inadequate support infrastructure; no documented exit procedures.

3. Six-Dimension Risk Scoring

Score each vendor 1 (Low) to 5 (Critical) across dimensions. Weighted matrix:

CategoryWeightScoreWeighted Score
Financial Risk20%
Operational Risk25%
Compliance Risk30%
Security Risk15%
Reputational Risk5%
Strategic Risk5%
TOTAL100%

Critical services (payment processing, customer data systems, core business operations) receive 2x weight on security and compliance factors.

Risk score interpretation:

  • 4.0-5.0: Low Risk; proceed with standard terms.
  • 3.0-3.9: Medium Risk; enhanced due diligence required.
  • 2.0-2.9: High Risk; additional safeguards needed.
  • 1.0-1.9: Critical Risk; consider alternative vendors or reject.
4. DORA Critical Vendor Assessment

For financial services clients, DORA Art. 28-30 impose enhanced requirements for ICT third-party service providers.

DORA Art. 28 - General Principles: comprehensive ICT third-party risk management framework; full contractual documentation of all services; identification of all ICT third-party dependencies; comprehensive exit strategies.

DORA Art. 30 - Mandatory Contract Elements: service description (clear, complete, up-to-date); service locations (including subcontracting); service levels (SLAs with measurement and reporting); GDPR-compliant DPA; minimum security standards; availability and business continuity (DR/BCP); detailed exit strategy; regular and for-cause audit rights; subcontracting prior notification with objection rights; access for authorities (BaFin, ECB, ESMA inspection rights); termination rights (material breach, regulatory concerns); appropriate liability allocation; notice requirements for material changes, incidents, regulatory changes.

Concentration risk (Art. 28(4)): is the vendor used by multiple financial entities? Does this create systemic risk? Are alternatives available? What is our dependency level?

Substitutability (Art. 28(4) read with Art. 29): can we switch vendors within 3-6 months (illustrative planning horizon; DORA itself requires "adequate transition periods" under Art. 30 rather than a fixed window)? Technical lock-ins? Data portability? Contractual barriers to exit?

ICT sub-outsourcing (Art. 30(2)(a), read with the Commission Delegated Regulation on subcontracting RTS, JC 2024 53): all subcontractors identified; subcontractor locations documented; subcontractor security verified; subcontractor change notification process.

Show full SKILL.md (706 more words)Show less
5. NIS2 Vendor Assessment

For vendors in NIS2 scope (KRITIS sectors under essential/important entity obligations), Art. 21 requires cybersecurity risk management measures.

Required assessments against Art. 21(2) measures are enumerated in Section 2 above. Supply chain security (Art. 21(2)(d)): vendor's own cybersecurity measures verified; vendor's supply chain security practices assessed; contractual cybersecurity obligations included; regular vendor security reviews; vendor incident notification requirements.

6. Risk Mitigation Strategies

Financial: shorter contract terms (1-2 years); payment terms protecting buyer (Net 30 vs. advance); parent company guarantees; performance bonds or escrow; more frequent financial reviews.

Compliance: enhanced contractual GDPR, DORA, NIS2 provisions; quarterly audit rights; regular compliance attestations; mandatory notification of regulatory changes; stricter SLAs with termination rights for non-compliance.

Security: required certifications as ongoing obligation; annual penetration testing at vendor cost; incident notification within 24 hours vs. 72; enhanced monitoring and logging; MFA requirements; regular security assessments.

Operational: robust SLAs with meaningful service credits; detailed exit and transition procedures; source code escrow for critical applications; dual sourcing for critical services; more frequent performance reviews.

Strategic: limit contract term; build exit provisions; avoid proprietary lock-in; maintain dual-source options.

7. Ongoing Vendor Management

Quarterly reviews: SLA compliance; service quality; security incidents; financial stability (where quarterly data available); compliance status.

Annual assessments: update full risk scoring matrix; contract performance and commercial terms review; market alternatives and pricing; strategic alignment; renewal or termination decision.

Trigger-based reviews (immediate): major security incident or data breach; regulatory enforcement action; material litigation; financial distress (credit downgrade, significant losses); acquisition or ownership change; service quality deterioration; repeated SLA failures; material contract breach.

8. Output Formats

Vendor Risk Report (10-20 pages): executive summary; vendor background; financial assessment; legal and compliance review; security and technical evaluation; operational assessment; risk scoring matrix with justifications; mitigation recommendations; recommended contract terms; implementation and monitoring plan; appendices.

Vendor Assessment Summary (2-3 pages): vendor overview and services; risk score summary table; key findings; recommendation (proceed/conditional/reject); required contract terms; next steps.

Vendor Comparison Matrix: side-by-side risk scores; compliance coverage comparison; cost-benefit analysis; strengths/weaknesses; recommended vendor with justification.

Vendor Risk Register (spreadsheet): vendor name and ID; service type and criticality; risk scores by category; overall rating; last assessment date; next review date; key risks and mitigations; contract key terms; primary contact; escalation contacts.

Vendor Onboarding Checklist: due diligence completed and approved; contract negotiated and executed; insurance certificates received; DPA signed; security documentation reviewed; access provisioning completed; integration plan approved; service transition timeline; monitoring procedures implemented; relationship management assigned; vendor added to risk register; first quarterly review scheduled.

Best Practices

  1. Start with Phase 1 screening before investing in detailed assessment.
  2. Scale diligence depth to service criticality and risk exposure.
  3. Use risk scoring to calibrate contract terms.
  4. Document all findings and recommendations (audit trail).
  5. Involve Legal, IT/Security, Procurement, Business Units, and Compliance throughout.
  6. Verify certifications directly with issuing bodies.
  7. Check references with current customers.
  8. Review vendor's own vendor management practices.
  9. Plan for ongoing monitoring, not only initial assessment.
  10. Track total vendor exposure across the organisation to identify dangerous concentration.

Common Mistakes

  1. Skipping financial due diligence for established vendors.
  2. Accepting vendor self-assessments without verification.
  3. Ignoring DORA/NIS2 requirements for critical vendors.
  4. Approving vendors without documented risk mitigation.
  5. Forgetting to assess exit and transition feasibility.
  6. Overlooking subprocessor and fourth-party risks.
  7. Neglecting ongoing monitoring after onboarding.
  8. Approving vendors without legal and security review.

Limitations

This skill does not: replace professional due diligence services; provide legal advice; guarantee vendor performance or eliminate risk; substitute for organisation-specific risk frameworks; fulfill regulatory obligations without expert validation; create attorney-client or fiduciary relationships.

Users must: adapt frameworks to their specific industry, jurisdiction, and risk tolerance; engage qualified professionals for regulated assessments; verify current regulatory requirements; obtain internal approvals; maintain documentation for audit and compliance; update criteria as regulations evolve.

Example Use Cases

  1. Financial institution under DORA assessing cloud service provider for critical payment systems.
  2. Healthcare organisation evaluating SaaS vendor handling protected health information.
  3. KRITIS-scope manufacturer performing NIS2 supply chain security assessment of industrial control system provider.
  4. E-commerce platform conducting payment processor due diligence under PCI DSS.
  5. Government agency performing FedRAMP compliance assessment for cloud infrastructure.
  6. Startup running rapid vendor screening for limited-risk, non-critical services.

© lawve-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in skills/vendor-due-diligence-patrick-munro of lawve-ai/awesome-legal-skills.

  • SKILL.md
  • LICENSE.txt
  • README.md

Open the folder on GitHubat commit 045f738

Compare with similar skills

Vendor Due Diligence Patrick Munro next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor Due Diligence Patrick Munro compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor Due Diligence Patrick Munro this skilllawve-ai/awesome-legal-skills847—~4.1kAutomated safety check: PassAGPL-3.0
Vendor Privacy Due Diligencemukul975/Privacy-Data-Protection-Skills301—~2.7kAutomated safety check: PassApache-2.0
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.3kAutomated safety check: PassMIT
General Counsel Advisoralirezarezvani/claude-skills28k—~2.3kAutomated safety check: PassMIT
TprmSushegaad/Claude-Skills-Governance-Risk-and-Compliance946—~2.3kAutomated safety check: PassMIT
AI Vendor Privacy Duemukul975/Privacy-Data-Protection-Skills301—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Vendor Privacy Due Diligence

    mukul975/Privacy-Data-Protection-Skills

    Pre-contract vendor privacy due diligence per GDPR Article 28(1).

    301 GitHub stars~2.7k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • General Counsel Advisor

    alirezarezvani/claude-skills

    General Counsel advisory for startups: contract review (MSA, SaaS, NDA, DPA, employment), IP strategy, term sheet decoding, and regulatory landscape mapping.

    28k GitHub stars~2.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Tprm

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert third-party risk management (TPRM) advisor — a vendor risk analyst for the full lifecycle: risk-based vendor tiering, tailored due-diligence questionnaires (SIG-style or mapped to ISO 27001…

    946 GitHub stars~2.3k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • AI Vendor Privacy Due

    mukul975/Privacy-Data-Protection-Skills

    Determines controller-processor relationships for AI services and conducts privacy due diligence.

    301 GitHub stars~2.4k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Pia Vendor Processing

    mukul975/Privacy-Data-Protection-Skills

    Conducts Privacy Impact Assessment for vendor and third-party data processing arrangements.

    301 GitHub stars~2k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed

More from lawve-ai/awesome-legal-skills

All 154 skills in this repo
  • Customs Trade Law Onur Kafkas

    lawve-ai/awesome-legal-skills

    U.S. An agent skill from lawve-ai/awesome-legal-skills.

    847 GitHub stars~4.1k tokensUpdated 8 days ago
    Auto-check passed
  • Eu Data Act Oliver Schmidt Prietz

    lawve-ai/awesome-legal-skills

    Practitioner skill for advising on EU Regulation 2023/2854 (Data Act).

    847 GitHub stars~3.9k tokensUpdated 8 days ago
    Auto-check passed
  • Litigation Deadline Calendar

    lawve-ai/awesome-legal-skills

    Calendar litigation and arbitration deadlines from a scheduling order.

    847 GitHub stars~4.3k tokensUpdated 8 days ago
    Auto-check passed
  • Outlook Emails Lawvable

    lawve-ai/awesome-legal-skills

    Read, search, and download emails and attachments from Microsoft Outlook via OAuth2.

    847 GitHub stars~672 tokensUpdated 8 days ago
    Auto-check passed
  • Ambiguity Report

    lawve-ai/awesome-legal-skills

    Turn an interpretive-ambiguity audit of a legal text — contract, statute, regulation, or judicial opinion — into a polished deliverable.

    847 GitHub stars~4.6k tokensUpdated 8 days ago
    Auto-check passed
  • Az Eu Website Privacy Audit

    lawve-ai/awesome-legal-skills

    Audits a website for compliance with Azerbaijan's Law on Personal Data No.

    847 GitHub stars~3.8k tokensUpdated 8 days ago
    Auto-check passed

Questions about Vendor Due Diligence Patrick Munro

What does Vendor Due Diligence Patrick Munro do?

Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR. Vendor Due Diligence Patrick Munro is an agent skill from lawve-ai/awesome-legal-skills. Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.

When should I use Vendor Due Diligence Patrick Munro?

Vendor Due Diligence Patrick Munro fits situations like: evaluating new vendors; technology providers; conducting critical ICT third-party due diligence under DORA; performing supply chain security assessment under NIS2.

How do I install Vendor Due Diligence Patrick Munro in Claude Code?

Run `npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a claude-code`. Or copy the skill folder (skills/vendor-due-diligence-patrick-munro in lawve-ai/awesome-legal-skills) into .claude/skills/vendor-due-diligence-patrick-munro in your project. Claude Code loads it when a task matches its description.

How do I install Vendor Due Diligence Patrick Munro in Codex?

Run `npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a codex`. Or copy the skill folder (skills/vendor-due-diligence-patrick-munro in lawve-ai/awesome-legal-skills) into .agents/skills/vendor-due-diligence-patrick-munro in your project. Codex loads it when a task matches its description.

Can I use Vendor Due Diligence Patrick Munro in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-due-diligence-patrick-munro, .gemini/skills/vendor-due-diligence-patrick-munro, .github/skills/vendor-due-diligence-patrick-munro and .opencode/skills/vendor-due-diligence-patrick-munro in your project.

What does Vendor Due Diligence Patrick Munro need to run?

SKILL.md names no scripts, command-line tools or credentials: Vendor Due Diligence Patrick Munro is instructions for the agent only.

Does Vendor Due Diligence Patrick Munro access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor Due Diligence Patrick Munro safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vendor Due Diligence Patrick Munro use?

Vendor Due Diligence Patrick Munro is published under the AGPL-3.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor Due Diligence Patrick Munro use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vendor Due Diligence Patrick Munro?

Skills that share tags, products or a category with Vendor Due Diligence Patrick Munro: Vendor Privacy Due Diligence (mukul975/Privacy-Data-Protection-Skills, 301 stars), Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), General Counsel Advisor (alirezarezvani/claude-skills, 28k stars) and Tprm (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor Due Diligence Patrick Munro?

lawve-ai (a GitHub organization) maintains it in lawve-ai/awesome-legal-skills, which has 847 GitHub stars. The repository holds 154 skills in this directory. The repository was last updated on October 2, 2026.

Source: lawve-ai/awesome-legal-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.