Agent skill

SaaS Vendor Inventory

by mukul975 in mukul975/Privacy-Data-Protection-Skills

SaaS vendor data processing inventory management. An agent skill from mukul975/Privacy-Data-Protection-Skills.

Apache-2.0Auto-check passedBusiness, Finance & HR

Install SaaS Vendor Inventory

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills saas-vendor-inventory --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/saas-vendor-inventory .claude/skills/saas-vendor-inventory && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
saas-vendor-inventory
GitHub stars
301
Token cost
~2.3k tokens
SKILL.md length
920 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

SaaS vendor data processing inventory management. An agent skill from mukul975/Privacy-Data-Protection-Skills.

  • Works in 4 steps: Aggregate DNS query logs from internal… → Match resolved domains against SaaS… → Cross-reference with sanctioned vendor… → …
  • Tasks that involve Accounting and bookkeeping
  • SKILL.md covers Overview, Inventory Framework, Shadow IT Discovery Methods and Data Flow Mapping, plus 3 more sections
  • Runs Python scripts from its folder

What it does

SaaS Vendor Inventory is an agent skill from mukul975/Privacy-Data-Protection-Skills. SaaS vendor data processing inventory management. Covers shadow IT discovery, API-based data flow detection, processing purpose mapping, contract status tracking, and continuous inventory reconciliation for cloud service providers.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Business, Finance & HR, covering Accounting and bookkeeping, Project management and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Accounting and bookkeeping
  • Tasks that involve Project management
  • Tasks that involve Privacy and GDPR

Example prompts

  • “/saas-vendor-inventory”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Aggregate DNS query logs from internal resolvers
  2. Match resolved domains against SaaS provider domain databases
  3. Cross-reference with sanctioned vendor list
  4. Flag unmatched SaaS domains for investigation

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

SaaS Vendor Inventory loads about 2.3k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 920 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 920 words, ~2,259 tokens.

Download SKILL.mdSave it as .claude/skills/saas-vendor-inventory/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
saas-vendor-inventory
description
SaaS vendor data processing inventory management. Covers shadow IT discovery, API-based data flow detection, processing purpose mapping, contract status tracking, and continuous inventory reconciliation for cloud service providers.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
vendor-privacy-management
metadata.tags
saas-inventory, shadow-it, data-flow-detection, vendor-register, cloud-services

SaaS Vendor Data Processing Inventory

Overview

Modern organizations rely on dozens to hundreds of SaaS applications, many of which process personal data. GDPR Article 30 requires controllers to maintain records of processing activities, which includes documenting all processors. Shadow IT — SaaS applications adopted by business units without formal procurement or privacy review — creates significant compliance risk because unrecorded processing cannot be properly governed.

The EDPB Guidelines 07/2020 emphasize that controllers cannot claim ignorance of processing performed by vendors they engage, even if the engagement happened informally. Summit Cloud Partners maintains a comprehensive SaaS Vendor Data Processing Inventory to track all cloud services processing personal data, including those discovered through shadow IT detection.

Inventory Framework

Tier 1: Sanctioned SaaS — Formally Procured

Applications that have gone through formal procurement, privacy review, and DPA execution.

FieldDescription
Vendor nameLegal entity name
Product/service nameSaaS product name
CategoryCRM, HR, Analytics, Communication, DevOps, etc.
Business ownerDepartment and named individual
Procurement dateWhen the service was contracted
DPA statusExecuted / In negotiation / Not required
DPA referenceDPA document reference number
Privacy review statusCompleted / In progress / Pending
Risk tierPer vendor risk scoring model
Personal data categoriesWhat personal data is processed
Data subjectsWhose data is processed
Processing purposesWhy data is processed
Processing locationsWhere data is stored/processed
Integration methodSSO, API, manual upload, etc.
Data flow directionInbound / Outbound / Bidirectional
Contract expiryWhen the contract term ends
Auto-renewal dateWhen auto-renewal triggers
Annual costTotal annual spend
License countNumber of active users/seats
Tier 2: Known Unsanctioned — Shadow IT Detected

Applications detected through discovery tools that lack formal procurement or privacy review.

FieldDescription
Application nameAs detected
Detection methodCASB, DNS, expense, SSO log, etc.
Detection dateWhen first observed
Usage scopeEstimated users and frequency
Likely data categoriesInferred from application type
Risk assessmentPreliminary risk level
Remediation statusUnder review / Sanctioning in progress / Blocked / Accepted
Business unitDepartment(s) using the application
Tier 3: Evaluated and Excluded

Applications evaluated and determined to not process personal data.

FieldDescription
Application nameProduct name
Evaluation dateWhen reviewed
DeterminationNo personal data processing
RationaleWhy excluded from inventory
Next review dateWhen to re-evaluate

Shadow IT Discovery Methods

Method 1: Cloud Access Security Broker (CASB)

Deploy a CASB solution to monitor network traffic and identify cloud service usage.

Detection Capabilities:

  • SaaS application identification via API call pattern matching
  • User activity monitoring across sanctioned and unsanctioned services
  • Data transfer volume estimation
  • Risk scoring of discovered applications

Implementation at Summit Cloud Partners:

ComponentDetail
CASB vendorDeployed as inline proxy and API connector
CoverageAll corporate network egress and managed endpoints
Discovery scopeHTTP/HTTPS traffic to known SaaS domains
Update frequencyReal-time discovery, weekly consolidated reporting
IntegrationFeeds into SaaS inventory system via API
Method 2: DNS and Firewall Log Analysis

Analyze DNS resolution logs and firewall traffic logs to identify connections to SaaS providers.

Process:

  1. Aggregate DNS query logs from internal resolvers
  2. Match resolved domains against SaaS provider domain databases
  3. Cross-reference with sanctioned vendor list
  4. Flag unmatched SaaS domains for investigation
Method 3: SSO and Identity Provider Logs

Review identity provider (IdP) logs for OAuth consent grants and SAML integrations.

Detection Signals:

  • OAuth application consent grants not in approved list
  • SAML service provider registrations
  • OpenID Connect client registrations
  • API token generation for third-party services
Show full SKILL.md (363 more words)Show less
Method 4: Expense and Procurement Analysis

Review corporate expense reports and credit card statements for SaaS subscriptions.

Detection Signals:

  • Recurring charges to known SaaS providers
  • Expense claims categorized as "software" or "subscriptions"
  • Purchase order requests for cloud services bypassing IT procurement
Method 5: API Integration Audit

Scan internal systems for outbound API connections to third-party services.

Detection Signals:

  • Outbound API calls to non-sanctioned endpoints
  • Webhook configurations sending data to external services
  • Integration platform (Zapier, Workato, etc.) connections
  • Custom script connections to third-party APIs

Data Flow Mapping

For each sanctioned SaaS vendor, document the complete data flow:

Data Flow Template:

Summit Cloud Partners Internal Systems
         │
         ├─► [SaaS Application Name]
         │     │
         │     ├─ Integration: [SSO/API/Manual Upload/Browser Plugin]
         │     ├─ Authentication: [SAML SSO / OAuth 2.0 / Username-Password]
         │     ├─ Encryption in transit: [TLS version]
         │     ├─ Data categories sent: [list]
         │     ├─ Data categories received: [list]
         │     ├─ Data categories stored by vendor: [list]
         │     ├─ Vendor processing locations: [locations]
         │     ├─ Vendor sub-processors: [per sub-processor register]
         │     ├─ Data retention at vendor: [period]
         │     └─ Data deletion capability: [Yes/No — method]
         │
         └─► [Next SaaS Application]

Inventory Reconciliation

Quarterly Reconciliation Process
StepActivityResponsible
1Extract current CASB discovery reportInfoSec
2Extract current sanctioned vendor listPrivacy Team
3Compare: identify new unsanctioned applicationsPrivacy Team
4Compare: identify sanctioned apps no longer in usePrivacy Team
5Verify DPA status for all sanctioned vendorsPrivacy Team
6Check contract expiry dates (90-day lookahead)Legal/Procurement
7Update inventory recordsPrivacy Team
8Report to DPOPrivacy Team Lead
Reconciliation Outcomes
FindingAction
New unsanctioned SaaS discoveredInitiate shadow IT remediation workflow
Sanctioned SaaS no longer in useInitiate vendor termination data workflow
DPA expired or missingExpedite DPA execution or service suspension
Contract approaching expiryTrigger renewal privacy review
Data processing scope change detectedInitiate DPA amendment review

Contract Status Tracking

StatusDefinitionAction Required
Active — CompliantContract active, DPA executed, privacy review currentStandard monitoring
Active — DPA PendingContract active, DPA in negotiationExpedite DPA; restrict data sharing if > 30 days
Active — Review OverdueContract active, privacy review past dueSchedule immediate review
Expiring (< 90 days)Contract approaching expiryInitiate renewal assessment
ExpiredContract term endedInitiate termination data workflow
SuspendedService suspended pending privacy issue resolutionTrack resolution
TerminatedContract terminated, data return/deletion in progressTrack deletion certification

Key Regulatory References

  • GDPR Article 30(1)(d) — Controller ROPA must include categories of recipients (processors)
  • GDPR Article 28(1) — Use only processors with sufficient guarantees
  • GDPR Article 5(2) — Accountability principle — must document all processing relationships
  • GDPR Article 24 — Controller responsibility for demonstrating compliance
  • EDPB Guidelines 07/2020 — Controller knowledge of processing operations
  • EDPB Guidelines 04/2019 — Data Protection by Design and by Default (privacy in procurement)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/saas-vendor-inventory of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

SaaS Vendor Inventory next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

SaaS Vendor Inventory compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
SaaS Vendor Inventory this skillmukul975/Privacy-Data-Protection-Skills301—~2.3kAutomated safety check: PassApache-2.0
Fmx Respondkunchenguid/firstmate7.8k—~10kAutomated safety check: NotesMIT
Accounting Audit System Buildersickn33/agentic-awesome-skills47k1 repos~3.3kAutomated safety check: PassMIT
Accounting Software Selectionsickn33/agentic-awesome-skills47k1 repos~7.4kAutomated safety check: PassMIT
Research Financealirezarezvani/claude-skills28k—~2.7kAutomated safety check: PassMIT
Fin Close Managementevolution-foundation/evo-nexus5451 repos~2.5kAutomated safety check: PassCustom licence

Similar skills

  • Fmx Respond

    kunchenguid/firstmate

    Agent-only playbook for handling Relay mentions and follow-ups.

    7.8k GitHub stars~10k tokensUpdated today
    Business, Finance & HRAuto-check: notes
  • Accounting Audit System Builder

    sickn33/agentic-awesome-skills

    Routes an accounting or audit request to the right module skill, from software selection through monthly closing, asking only what is missing.

    47k GitHub starsUsed in 1 repo~3.3k tokens
    Business, Finance & HRAuto-check passed
  • Accounting Software Selection

    sickn33/agentic-awesome-skills

    Scores shortlisted accounting packages against 57 evidence-backed fields, emitted as CSV, SQL, JSON Schema or Notion on request.

    47k GitHub starsUsed in 1 repo~7.4k tokens
    Business, Finance & HRAuto-check passed
  • Research Finance

    alirezarezvani/claude-skills

    A skill your agent uses when managing the money for an internal R&D program or portfolio — building a multi-period program budget with the F&A (indirect) split, tracking burn rate and runway against…

    28k GitHub stars~2.7k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Fin Close Management

    evolution-foundation/evo-nexus

    Manage the month-end close process with task sequencing, dependencies, and status tracking.

    545 GitHub starsUsed in 1 repo~2.5k tokens
    Business, Finance & HRAuto-check passed
  • Fda Catalyst Vaccines

    agentii-ai/agentii-investment-intelligence

    Vaccine catalyst analysis across the two-gate path: CBER BLA review and the ACIP recommendation gate that turns FDA approval into commercial availability.

    207 GitHub stars~1.9k tokensUpdated 12 days ago
    Business, Finance & HRAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about SaaS Vendor Inventory

What does SaaS Vendor Inventory do?

SaaS vendor data processing inventory management. An agent skill from mukul975/Privacy-Data-Protection-Skills. SaaS Vendor Inventory is an agent skill from mukul975/Privacy-Data-Protection-Skills. SaaS vendor data processing inventory management.

When should I use SaaS Vendor Inventory?

SaaS Vendor Inventory fits situations like: tasks that involve Accounting and bookkeeping; tasks that involve Project management; tasks that involve Privacy and GDPR.

How do I install SaaS Vendor Inventory in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a claude-code`. Or copy the skill folder (skills/privacy/saas-vendor-inventory in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/saas-vendor-inventory in your project. Claude Code loads it when a task matches its description.

How do I install SaaS Vendor Inventory in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a codex`. Or copy the skill folder (skills/privacy/saas-vendor-inventory in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/saas-vendor-inventory in your project. Codex loads it when a task matches its description.

Can I use SaaS Vendor Inventory in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/saas-vendor-inventory, .gemini/skills/saas-vendor-inventory, .github/skills/saas-vendor-inventory and .opencode/skills/saas-vendor-inventory in your project.

What does SaaS Vendor Inventory need to run?

Going by SKILL.md and its folder, SaaS Vendor Inventory needs Python for the scripts in its folder. Our summary lists: Python 3.

Does SaaS Vendor Inventory access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is SaaS Vendor Inventory safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does SaaS Vendor Inventory use?

SaaS Vendor Inventory is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does SaaS Vendor Inventory use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to SaaS Vendor Inventory?

Skills that share tags, products or a category with SaaS Vendor Inventory: Fmx Respond (kunchenguid/firstmate, 7.8k stars), Accounting Audit System Builder (sickn33/agentic-awesome-skills, 47k stars), Accounting Software Selection (sickn33/agentic-awesome-skills, 47k stars) and Research Finance (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains SaaS Vendor Inventory?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.