Vendor Privacy Due Diligence
mukul975/Privacy-Data-Protection-Skills
Pre-contract vendor privacy due diligence per GDPR Article 28(1).
Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.
$ npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install lawve-ai/awesome-legal-skills vendor-due-diligence-patrick-munro --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vendor-due-diligence-patrick-munro .claude/skills/vendor-due-diligence-patrick-munro && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vendor-due-diligence-patrick-munro" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/vendor-due-diligence-patrick-munro into .claude/skills/vendor-due-diligence-patrick-munro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-due-diligence-patrick-munro", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/vendor-due-diligence-patrick-munroType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install lawve-ai/awesome-legal-skills vendor-due-diligence-patrick-munro --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/vendor-due-diligence-patrick-munro .agents/skills/vendor-due-diligence-patrick-munro && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vendor-due-diligence-patrick-munro" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/vendor-due-diligence-patrick-munro into .agents/skills/vendor-due-diligence-patrick-munro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-due-diligence-patrick-munro", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install lawve-ai/awesome-legal-skills vendor-due-diligence-patrick-munro --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/vendor-due-diligence-patrick-munro .cursor/skills/vendor-due-diligence-patrick-munro && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vendor-due-diligence-patrick-munro" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/vendor-due-diligence-patrick-munro into .cursor/skills/vendor-due-diligence-patrick-munro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-due-diligence-patrick-munro", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/lawve-ai/awesome-legal-skills.git --path skills/vendor-due-diligence-patrick-munro--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install lawve-ai/awesome-legal-skills vendor-due-diligence-patrick-munro --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/vendor-due-diligence-patrick-munro .gemini/skills/vendor-due-diligence-patrick-munro && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vendor-due-diligence-patrick-munro" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/vendor-due-diligence-patrick-munro into .gemini/skills/vendor-due-diligence-patrick-munro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-due-diligence-patrick-munro", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install lawve-ai/awesome-legal-skills vendor-due-diligence-patrick-munroInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/vendor-due-diligence-patrick-munro .github/skills/vendor-due-diligence-patrick-munro && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vendor-due-diligence-patrick-munro" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/vendor-due-diligence-patrick-munro into .github/skills/vendor-due-diligence-patrick-munro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-due-diligence-patrick-munro", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install lawve-ai/awesome-legal-skills vendor-due-diligence-patrick-munro --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/vendor-due-diligence-patrick-munro .opencode/skills/vendor-due-diligence-patrick-munro && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vendor-due-diligence-patrick-munro" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/vendor-due-diligence-patrick-munro into .opencode/skills/vendor-due-diligence-patrick-munro/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-due-diligence-patrick-munro", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vendor-due-diligence-patrick-munroRisk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.
Vendor Due Diligence Patrick Munro is an agent skill from lawve-ai/awesome-legal-skills. Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR. Provides three-phase process (Initial Screening / Detailed Assessment / Final Evaluation), six-dimension risk scoring (Financial/Operational/Compliance/Security/Reputational/Strategic) with weighted matrices, full DORA Art. 28-30 contractual checklist, NIS2 Art. 21(2) security measures enumeration, GDPR Art. 28 documentation checks, red flags per dimension, trigger-based review…
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `README.md`).
It sits in Legal & Compliance, covering Fundraising and pitch decks, Privacy and GDPR and Supply chain security. The repository describes itself as: A curated list of awesome Agent Skills for automating legal work. The licence is AGPL-3.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 045f738. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vendor Due Diligence Patrick Munro loads about 4.1k tokens when it runs. Until then it costs about 236 tokens; SKILL.md has 1,850 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from lawve-ai/awesome-legal-skills at commit 045f738, republished under its AGPL-3.0 licence (© lawve-ai). 1,850 words, ~4,102 tokens.
.claude/skills/vendor-due-diligence-patrick-munro/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Risk-based vendor assessment framework that identifies material risks early, ensures DORA/NIS2/GDPR compliance, and provides clear recommendations for selection, contract calibration, and ongoing management. Built for regulated sectors (financial services under DORA, KRITIS sectors under NIS2) and for any organisation with meaningful ICT third-party exposure.
This skill provides frameworks for vendor assessment purposes only. It does not constitute legal, financial, or professional advice. Users should:
The frameworks are templates. Actual assessments require expertise in law, finance, cybersecurity, and risk management. Neither the skill creator nor Claude/Anthropic assumes liability for decisions made based on this skill's output.
Regulatory references current as of 2026-04-23. EU (DORA, NIS2, GDPR) and German (NIS2UmsuCG, BDSG) citations reflect the consolidated text available at that date. Member State NIS2 transposition remains uneven; Germany's NIS2UmsuCG entered into force on 6 December 2025 with the BSI reporting portal opening on 6 January 2026. Verify the current consolidated text and national transposition status on EUR-Lex and the Bundesgesetzblatt before use.
Phase 1: Initial Screening (1-2 days): rapid assessment to determine whether a vendor warrants detailed evaluation.
Phase 2: Detailed Assessment (1-2 weeks): comprehensive evaluation across all risk dimensions. See Section 2.
Phase 3: Final Evaluation (3-5 days): synthesis, risk scoring, mitigation strategies, recommendation.
Documents to request: 3 years audited financial statements; commercial credit report; professional liability insurance (€5M minimum); cyber insurance (€5M minimum for IT vendors); banking references.
Analysis: revenue trends and profitability; debt levels and liquidity ratios; customer concentration risk; financial stability score (1-5).
Red flags: consistent losses or negative cash flow; high customer concentration (>30% revenue from one client); recent credit downgrades; inadequate insurance coverage.
Documents to request: articles of incorporation and bylaws; material contracts (top 5 customers and suppliers); pending and historical litigation; regulatory filings; IP portfolio; data protection policies and GDPR documentation; subprocessor list (if data processor).
GDPR compliance review (Art. 28 GDPR): privacy policy and notices; DPA template; breach incident response procedures; international data transfer mechanisms (SCCs, adequacy); Art. 30 records of processing; DPIA process for high-risk processing.
Industry-specific: financial services clients - DORA compliance (Art. 28-30); KRITIS sectors - NIS2 compliance (Art. 21); AI systems - AI Act classification and compliance.
Red flags: pending significant litigation (>10% annual revenue); regulatory enforcement actions; material IP infringement claims; GDPR non-compliance (no DPA, inadequate security).
Documents to request: security certifications (ISO 27001, SOC 2 Type II, PCI DSS where applicable); recent penetration testing results; security incident history (3 years); business continuity and disaster recovery plans; backup procedures and testing records; technical architecture diagrams; data residency documentation; subprocessor security assessments.
Security assessment: encryption standards (at rest and in transit); access controls and identity management; vulnerability management program; security awareness training; incident response procedures and SLAs; third-party security audits.
NIS2 Art. 21(2) security measures (for KRITIS vendors), mapped to the ten statutory sub-paragraphs:
DORA ICT risk management (for financial services vendors): Art. 6-16 ICT risk management framework; Art. 17-23 incident management; Art. 24-27 digital operational resilience testing; Art. 28-30 third-party risk monitoring.
Red flags: no ISO 27001 or equivalent; no SOC 2 Type II; recent major security incidents with inadequate response; inadequate backup and DR; data residency non-compliance.
Documents to request: SLA performance history (12 months minimum); customer satisfaction metrics; support structure and escalation procedures; change management and release procedures; service availability statistics; MTTR data.
Analysis: service delivery track record; support responsiveness; technical competency; scalability; exit/transition procedures.
Red flags: consistent SLA failures; poor customer references; inadequate support infrastructure; no documented exit procedures.
Score each vendor 1 (Low) to 5 (Critical) across dimensions. Weighted matrix:
| Category | Weight | Score | Weighted Score |
|---|---|---|---|
| Financial Risk | 20% | ||
| Operational Risk | 25% | ||
| Compliance Risk | 30% | ||
| Security Risk | 15% | ||
| Reputational Risk | 5% | ||
| Strategic Risk | 5% | ||
| TOTAL | 100% |
Critical services (payment processing, customer data systems, core business operations) receive 2x weight on security and compliance factors.
Risk score interpretation:
For financial services clients, DORA Art. 28-30 impose enhanced requirements for ICT third-party service providers.
DORA Art. 28 - General Principles: comprehensive ICT third-party risk management framework; full contractual documentation of all services; identification of all ICT third-party dependencies; comprehensive exit strategies.
DORA Art. 30 - Mandatory Contract Elements: service description (clear, complete, up-to-date); service locations (including subcontracting); service levels (SLAs with measurement and reporting); GDPR-compliant DPA; minimum security standards; availability and business continuity (DR/BCP); detailed exit strategy; regular and for-cause audit rights; subcontracting prior notification with objection rights; access for authorities (BaFin, ECB, ESMA inspection rights); termination rights (material breach, regulatory concerns); appropriate liability allocation; notice requirements for material changes, incidents, regulatory changes.
Concentration risk (Art. 28(4)): is the vendor used by multiple financial entities? Does this create systemic risk? Are alternatives available? What is our dependency level?
Substitutability (Art. 28(4) read with Art. 29): can we switch vendors within 3-6 months (illustrative planning horizon; DORA itself requires "adequate transition periods" under Art. 30 rather than a fixed window)? Technical lock-ins? Data portability? Contractual barriers to exit?
ICT sub-outsourcing (Art. 30(2)(a), read with the Commission Delegated Regulation on subcontracting RTS, JC 2024 53): all subcontractors identified; subcontractor locations documented; subcontractor security verified; subcontractor change notification process.
For vendors in NIS2 scope (KRITIS sectors under essential/important entity obligations), Art. 21 requires cybersecurity risk management measures.
Required assessments against Art. 21(2) measures are enumerated in Section 2 above. Supply chain security (Art. 21(2)(d)): vendor's own cybersecurity measures verified; vendor's supply chain security practices assessed; contractual cybersecurity obligations included; regular vendor security reviews; vendor incident notification requirements.
Financial: shorter contract terms (1-2 years); payment terms protecting buyer (Net 30 vs. advance); parent company guarantees; performance bonds or escrow; more frequent financial reviews.
Compliance: enhanced contractual GDPR, DORA, NIS2 provisions; quarterly audit rights; regular compliance attestations; mandatory notification of regulatory changes; stricter SLAs with termination rights for non-compliance.
Security: required certifications as ongoing obligation; annual penetration testing at vendor cost; incident notification within 24 hours vs. 72; enhanced monitoring and logging; MFA requirements; regular security assessments.
Operational: robust SLAs with meaningful service credits; detailed exit and transition procedures; source code escrow for critical applications; dual sourcing for critical services; more frequent performance reviews.
Strategic: limit contract term; build exit provisions; avoid proprietary lock-in; maintain dual-source options.
Quarterly reviews: SLA compliance; service quality; security incidents; financial stability (where quarterly data available); compliance status.
Annual assessments: update full risk scoring matrix; contract performance and commercial terms review; market alternatives and pricing; strategic alignment; renewal or termination decision.
Trigger-based reviews (immediate): major security incident or data breach; regulatory enforcement action; material litigation; financial distress (credit downgrade, significant losses); acquisition or ownership change; service quality deterioration; repeated SLA failures; material contract breach.
Vendor Risk Report (10-20 pages): executive summary; vendor background; financial assessment; legal and compliance review; security and technical evaluation; operational assessment; risk scoring matrix with justifications; mitigation recommendations; recommended contract terms; implementation and monitoring plan; appendices.
Vendor Assessment Summary (2-3 pages): vendor overview and services; risk score summary table; key findings; recommendation (proceed/conditional/reject); required contract terms; next steps.
Vendor Comparison Matrix: side-by-side risk scores; compliance coverage comparison; cost-benefit analysis; strengths/weaknesses; recommended vendor with justification.
Vendor Risk Register (spreadsheet): vendor name and ID; service type and criticality; risk scores by category; overall rating; last assessment date; next review date; key risks and mitigations; contract key terms; primary contact; escalation contacts.
Vendor Onboarding Checklist: due diligence completed and approved; contract negotiated and executed; insurance certificates received; DPA signed; security documentation reviewed; access provisioning completed; integration plan approved; service transition timeline; monitoring procedures implemented; relationship management assigned; vendor added to risk register; first quarterly review scheduled.
This skill does not: replace professional due diligence services; provide legal advice; guarantee vendor performance or eliminate risk; substitute for organisation-specific risk frameworks; fulfill regulatory obligations without expert validation; create attorney-client or fiduciary relationships.
Users must: adapt frameworks to their specific industry, jurisdiction, and risk tolerance; engage qualified professionals for regulated assessments; verify current regulatory requirements; obtain internal approvals; maintain documentation for audit and compliance; update criteria as regulations evolve.
© lawve-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files in skills/vendor-due-diligence-patrick-munro of lawve-ai/awesome-legal-skills.
Open the folder on GitHubat commit 045f738
Vendor Due Diligence Patrick Munro next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vendor Due Diligence Patrick Munro this skilllawve-ai/awesome-legal-skills | 847 | — | ~4.1k | Automated safety check: Pass | AGPL-3.0 | |
| Vendor Privacy Due Diligencemukul975/Privacy-Data-Protection-Skills | 301 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.3k | Automated safety check: Pass | MIT | |
| General Counsel Advisoralirezarezvani/claude-skills | 28k | — | ~2.3k | Automated safety check: Pass | MIT | |
| TprmSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | — | ~2.3k | Automated safety check: Pass | MIT | |
| AI Vendor Privacy Duemukul975/Privacy-Data-Protection-Skills | 301 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 |
mukul975/Privacy-Data-Protection-Skills
Pre-contract vendor privacy due diligence per GDPR Article 28(1).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
alirezarezvani/claude-skills
General Counsel advisory for startups: contract review (MSA, SaaS, NDA, DPA, employment), IP strategy, term sheet decoding, and regulatory landscape mapping.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert third-party risk management (TPRM) advisor — a vendor risk analyst for the full lifecycle: risk-based vendor tiering, tailored due-diligence questionnaires (SIG-style or mapped to ISO 27001…
mukul975/Privacy-Data-Protection-Skills
Determines controller-processor relationships for AI services and conducts privacy due diligence.
mukul975/Privacy-Data-Protection-Skills
Conducts Privacy Impact Assessment for vendor and third-party data processing arrangements.
lawve-ai/awesome-legal-skills
U.S. An agent skill from lawve-ai/awesome-legal-skills.
lawve-ai/awesome-legal-skills
Practitioner skill for advising on EU Regulation 2023/2854 (Data Act).
lawve-ai/awesome-legal-skills
Calendar litigation and arbitration deadlines from a scheduling order.
lawve-ai/awesome-legal-skills
Read, search, and download emails and attachments from Microsoft Outlook via OAuth2.
lawve-ai/awesome-legal-skills
Turn an interpretive-ambiguity audit of a legal text — contract, statute, regulation, or judicial opinion — into a polished deliverable.
lawve-ai/awesome-legal-skills
Audits a website for compliance with Azerbaijan's Law on Personal Data No.
Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR. Vendor Due Diligence Patrick Munro is an agent skill from lawve-ai/awesome-legal-skills. Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.
Vendor Due Diligence Patrick Munro fits situations like: evaluating new vendors; technology providers; conducting critical ICT third-party due diligence under DORA; performing supply chain security assessment under NIS2.
Run `npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a claude-code`. Or copy the skill folder (skills/vendor-due-diligence-patrick-munro in lawve-ai/awesome-legal-skills) into .claude/skills/vendor-due-diligence-patrick-munro in your project. Claude Code loads it when a task matches its description.
Run `npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a codex`. Or copy the skill folder (skills/vendor-due-diligence-patrick-munro in lawve-ai/awesome-legal-skills) into .agents/skills/vendor-due-diligence-patrick-munro in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lawve-ai/awesome-legal-skills --skill vendor-due-diligence-patrick-munro -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-due-diligence-patrick-munro, .gemini/skills/vendor-due-diligence-patrick-munro, .github/skills/vendor-due-diligence-patrick-munro and .opencode/skills/vendor-due-diligence-patrick-munro in your project.
SKILL.md names no scripts, command-line tools or credentials: Vendor Due Diligence Patrick Munro is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vendor Due Diligence Patrick Munro is published under the AGPL-3.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vendor Due Diligence Patrick Munro: Vendor Privacy Due Diligence (mukul975/Privacy-Data-Protection-Skills, 301 stars), Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), General Counsel Advisor (alirezarezvani/claude-skills, 28k stars) and Tprm (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
lawve-ai (a GitHub organization) maintains it in lawve-ai/awesome-legal-skills, which has 847 GitHub stars. The repository holds 154 skills in this directory. The repository was last updated on October 2, 2026.
Source: lawve-ai/awesome-legal-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.