Agent skill

Managing Third Party Vendor Risk

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set…

Apache-2.0Auto-check passedLegal & Compliance

Install Managing Third Party Vendor Risk

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill managing-third-party-vendor-risk -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills managing-third-party-vendor-risk --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/managing-third-party-vendor-risk .claude/skills/managing-third-party-vendor-risk && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
managing-third-party-vendor-risk
GitHub stars
34k
Token cost
~2.2k tokens
SKILL.md length
996 words
Files
5 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set…

  • Works in 9 steps: Inventory and classify vendors → Tier by inherent risk → Run tier-appropriate due diligence → …
  • Assessing a new vendor
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Managing Third Party Vendor Risk is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set contractual right-to-audit clauses, monitor vendors continuously, and offboard securely. Use when assessing a new vendor, standing up a vendor-risk program, tiering a portfolio, reviewing a SOC 2/CAIQ, or writing security terms into a contract.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `scripts/process.py`).

It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Assessing a new vendor
  • Standing up a vendor-risk program
  • Tiering a portfolio
  • Reviewing a SOC 2/CAIQ

Example prompts

  • “/managing-third-party-vendor-risk”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Inventory and classify vendors
  2. Tier by inherent risk
  3. Run tier-appropriate due diligence
  4. Review evidence critically
  5. Identify gaps and decide
  6. Codify in the contract / DPA
  7. Monitor continuously
  8. Manage Nth-party and concentration risk
  9. Offboard securely

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Managing Third Party Vendor Risk loads about 2.2k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 119 tokens; SKILL.md has 996 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 996 words, ~2,167 tokens.

Download SKILL.mdSave it as .claude/skills/managing-third-party-vendor-risk/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
managing-third-party-vendor-risk
description
Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set contractual right-to-audit clauses, monitor vendors continuously, and offboard securely. Use when assessing a new vendor, standing up a vendor-risk program, tiering a portfolio, reviewing a SOC 2/CAIQ, or writing security terms into a contract.
domain
cybersecurity
subdomain
compliance-governance
tags
third-party-risk, vendor-risk-management, tprm, supply-chain-risk, c-scrm, nist-800-161, soc2, caiq, continuous-monitoring, governance
version
1.0
author
andrewibrah
license
Apache-2.0
nist_csf
GV.SC-01, GV.SC-04, GV.SC-06, GV.SC-07, ID.RA-05, GV.OC-03
mitre_attack
T1199, T1195, T1078, T1190, T1567

Managing Third-Party Vendor Risk

When to Use

  • When assessing a new vendor before onboarding, especially one that will handle sensitive data, connect to your network, or be embedded in a critical process.
  • When standing up or maturing a third-party risk management (TPRM) program and you need a repeatable tiering + assessment workflow.
  • When tiering an existing vendor portfolio so effort matches risk.
  • When reviewing vendor evidence — a SOC 2 Type II report, ISO 27001 certificate, CAIQ, or pen-test summary — and you need to know what to look for.
  • When writing security and privacy requirements into a contract / DPA, including breach-notification SLAs and right-to-audit.
  • When a vendor (or their subcontractor) suffers a breach and you must assess exposure.
  • When managing software supply-chain and Nth-party (fourth-party and beyond) risk.

Prerequisites

  • A vendor inventory (who you use, for what, and what data/access each has).
  • A defined risk-tiering model (criteria and thresholds) agreed with the business.
  • Access to standardized questionnaires (Shared Assessments SIG, CSA CAIQ) and a way to collect evidence.
  • Clarity on your own regulatory obligations that flow down to vendors (e.g., HIPAA BAAs, CMMC flowdown, GDPR processor terms, PCI).
  • Stakeholders identified: procurement, legal, security, data owner, and the business sponsor.

Workflow

1. Inventory and classify vendors

Catalog every third party and capture: data sensitivity handled, type of access (network, physical, none), business criticality, and regulatory scope. You cannot manage what you have not inventoried — shadow vendors are a common blind spot.

2. Tier by inherent risk

Score each vendor on inherent-risk factors (data sensitivity, access, criticality, regulatory scope, spend/concentration) and assign a tier (e.g., Critical / High / Moderate / Low). The tier drives how deep the assessment goes and how often you reassess. A payroll processor with PII and system access is not the same risk as a stock-photo subscription.

3. Run tier-appropriate due diligence
  • Critical/High: full SIG (or SIG Core), request SOC 2 Type II and/or ISO 27001, recent pen-test summary, and evidence of an incident-response capability. Consider an assessor call.
  • Moderate: SIG Lite or CAIQ, plus key attestations.
  • Low: lightweight questionnaire / self-attestation.
4. Review evidence critically

Don't just collect — read:

  • SOC 2 Type II: check scope, the Trust Services Criteria covered, the audit period (not just the date), and especially the exceptions/deviations and any qualified opinion. A clean cover page can hide noted exceptions.
  • ISO 27001: confirm the scope statement and the Statement of Applicability actually cover the service you're buying.
  • CAIQ: look for "no" answers and CCM domains left blank.
  • Pen-test: age, scope, and whether highs/criticals were remediated.
5. Identify gaps and decide

Compare findings against your control requirements. For each gap: accept, require remediation (with a date), add a compensating control on your side, or walk away. Record the residual risk and a risk-owner decision.

6. Codify in the contract / DPA

Bake requirements into the agreement: security control obligations, breach-notification timeline, data-handling and return/destruction terms, right-to-audit / right to assessment evidence, subcontractor (Nth-party) flowdown, and liability/insurance. Contracts are where TPRM gets teeth.

7. Monitor continuously

Tiering is not a one-time gate. For higher tiers: periodic reassessment, security-ratings feeds, breach/news monitoring, certificate-expiry tracking, and watching for material changes (acquisition, region change, new subprocessors). Re-tier on change.

8. Manage Nth-party and concentration risk

Map critical fourth parties (your vendor's key subprocessors) and watch for concentration (many vendors riding on the same upstream provider) — a single upstream outage or breach can hit your whole portfolio at once.

9. Offboard securely

On termination: revoke access and credentials, confirm data return or certified destruction, remove integrations/API keys, and update the inventory. Un-offboarded vendors are standing risk.

Show full SKILL.md (407 more words)Show less

Key Concepts

ConceptDefinition
Inherent riskRisk a vendor poses before controls — drives tiering.
Residual riskRisk remaining after the vendor's (and your) controls.
Vendor tierRisk band (Critical/High/Moderate/Low) setting assessment depth and cadence.
SIGShared Assessments Standardized Information Gathering questionnaire (full / Lite / Core).
CAIQCSA Consensus Assessments Initiative Questionnaire (maps to the Cloud Controls Matrix).
SOC 2 Type IIAttestation on control design and operating effectiveness over a period.
Right to auditContractual right to assess the vendor or obtain assessment evidence.
Nth-party / fourth-partyYour vendor's vendors (and beyond) — indirect supply-chain risk.
Concentration riskMany vendors depending on the same upstream provider.
C-SCRMCybersecurity Supply Chain Risk Management (NIST SP 800-161).

Tools & Systems

  • NIST SP 800-161 Rev 1 — Cybersecurity Supply Chain Risk Management practices.
  • NIST CSF 2.0 — GV.SC — the supply-chain risk-management category (program backbone).
  • Shared Assessments SIG and CSA CAIQ / STAR registry — standardized questionnaires.
  • SOC 2 / ISO 27001 / PCI AOC / pen-test reports — vendor evidence.
  • Security-ratings services (e.g., BitSight/SecurityScorecard-style) — continuous external signal.
  • TPRM platforms — OneTrust, ProcessUnity, Prevalent, ServiceNow VRM, etc., to manage the workflow and inventory.
  • GDPR DPA / HIPAA BAA / CMMC flowdown — regulatory contract instruments.

Common Scenarios

  • New SaaS onboarding. Tier it, send the right questionnaire, read the SOC 2 exceptions, set contract terms, then approve with documented residual risk.
  • Portfolio has 400 vendors, no tiers. Tier first; concentrate assessment effort on the Critical/High tail rather than spreading thin.
  • Vendor breach in the news. Pull the vendor record, assess data/access exposure, invoke the breach-notification clause, and require a post-incident report.
  • Auditor asks for your TPRM program. Show the tiering model, the assessment cadence, and evidence of continuous monitoring mapped to GV.SC.
  • Critical fourth party identified. Document the dependency and the concentration risk; build a contingency for that upstream provider.

Output Format

Produce a Vendor Risk Assessment using assets/template.md, containing:

  1. Vendor profile — service, data handled, access type, business criticality, regulatory scope.
  2. Inherent-risk tier — score and resulting tier, with rationale.
  3. Due-diligence performed — questionnaire used and evidence collected (SOC 2 period, ISO scope, pen-test age).
  4. Findings — gaps with severity, including notable SOC 2 exceptions.
  5. Decision & residual risk — approve/conditional/reject, with risk-owner sign-off.
  6. Contractual requirements — security terms, breach SLA, right-to-audit, subprocessor flowdown.
  7. Monitoring & reassessment plan — cadence, signals watched, re-tier triggers.
  8. Nth-party notes — critical subprocessors and concentration risk.

Use scripts/process.py to compute a vendor's inherent-risk tier from a profile JSON, set the assessment depth and reassessment cadence, and flag missing evidence for the assigned tier.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/managing-third-party-vendor-risk of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/standards.md
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Managing Third Party Vendor Risk next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Managing Third Party Vendor Risk compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Managing Third Party Vendor Risk this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.3kAutomated safety check: PassMIT
Soc2Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.7kAutomated safety check: PassMIT
Grc Knowledgemlunato47/claude-grc-plugin184—~6.1kAutomated safety check: PassMIT
Information Security Manager Iso27001davila7/claude-code-templates33k1 repos~2.9kAutomated safety check: PassMIT
Audit Frameworkscartography-cncf/cartography4.1k—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    946 GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Information Security Manager Iso27001

    davila7/claude-code-templates

    Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies.

    33k GitHub starsUsed in 1 repo~2.9k tokens
    Legal & ComplianceAuto-check passed
  • Audit Frameworks

    cartography-cncf/cartography

    Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/.

    4.1k GitHub stars~2.8k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 7 days ago
    Legal & ComplianceAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Managing Third Party Vendor Risk

What does Managing Third Party Vendor Risk do?

Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set…. Managing Third Party Vendor Risk is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set contractual right-to-audit clauses, monitor vendors continuously, and offboard securely.

When should I use Managing Third Party Vendor Risk?

Managing Third Party Vendor Risk fits situations like: assessing a new vendor; standing up a vendor-risk program; tiering a portfolio; reviewing a SOC 2/CAIQ.

How do I install Managing Third Party Vendor Risk in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill managing-third-party-vendor-risk -a claude-code`. Or copy the skill folder (skills/managing-third-party-vendor-risk in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/managing-third-party-vendor-risk in your project. Claude Code loads it when a task matches its description.

How do I install Managing Third Party Vendor Risk in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill managing-third-party-vendor-risk -a codex`. Or copy the skill folder (skills/managing-third-party-vendor-risk in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/managing-third-party-vendor-risk in your project. Codex loads it when a task matches its description.

Can I use Managing Third Party Vendor Risk in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill managing-third-party-vendor-risk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/managing-third-party-vendor-risk, .gemini/skills/managing-third-party-vendor-risk, .github/skills/managing-third-party-vendor-risk and .opencode/skills/managing-third-party-vendor-risk in your project.

What does Managing Third Party Vendor Risk need to run?

Going by SKILL.md and its folder, Managing Third Party Vendor Risk needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Managing Third Party Vendor Risk access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Managing Third Party Vendor Risk safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Managing Third Party Vendor Risk use?

Managing Third Party Vendor Risk is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Managing Third Party Vendor Risk use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Managing Third Party Vendor Risk?

Skills that share tags, products or a category with Managing Third Party Vendor Risk: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Soc2 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Grc Knowledge (mlunato47/claude-grc-plugin, 184 stars) and Information Security Manager Iso27001 (davila7/claude-code-templates, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Managing Third Party Vendor Risk?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.