Agent skill

Vendor Evaluation

by rampstackco in rampstackco/claude-skills

Evaluate, select, and contract with vendors and SaaS tools. An agent skill from rampstackco/claude-skills.

MITAuto-check passedBusiness, Finance & HR

Install Vendor Evaluation

skills CLI
$ npx skills add rampstackco/claude-skills --skill vendor-evaluation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rampstackco/claude-skills vendor-evaluation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rampstackco/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vendor-evaluation .claude/skills/vendor-evaluation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-evaluation
GitHub stars
935
Token cost
~2.8k tokens
SKILL.md length
1,503 words
Files
3 (incl. references)
Skills in repo
103
Repo updated
First seen
Licence
MIT

At a glance

Evaluate, select, and contract with vendors and SaaS tools. An agent skill from rampstackco/claude-skills.

  • Works in 12 steps: Define the need → Build vs buy → Generate the shortlist → …
  • Comparing alternatives
  • SKILL.md covers When to use, When NOT to use, Required inputs and The framework: 5 phases, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vendor Evaluation is an agent skill from rampstackco/claude-skills. Evaluate, select, and contract with vendors and SaaS tools. Use this skill when comparing alternatives, running an RFP, scoring vendors against criteria, negotiating contracts, planning a switch, or assessing a vendor's risk. Triggers on vendor evaluation, RFP, vendor selection, build vs buy, SaaS evaluation, vendor scorecard, vendor comparison, contract negotiation, vendor switch, procurement. Also triggers when a renewal is coming up or when a tool isn't meeting expectations.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `README.md` and `references/evaluation-rubric.md`).

It sits in Business, Finance & HR, covering Vendor and procurement management. The repository describes itself as: Stack-agnostic Claude Skills covering the full website lifecycle: brand, design, content, SEO, dev, ops, growth, and research. Build, ship, audit, optimize. The licence is MIT.

When your agent uses it

  • Comparing alternatives
  • Scoring vendors against criteria
  • Negotiating contracts
  • Planning a switch

Example prompts

  • “/vendor-evaluation”

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Define the need
  2. Build vs buy
  3. Generate the shortlist
  4. Score the finalists
  5. Negotiate
  6. Define the need
  7. Build vs buy
  8. Generate shortlist
  9. Run demos and trials
  10. Run security and compliance review
  11. Score
  12. Negotiate

What it can do on your machine

Read from SKILL.md and the folder at commit 482c9bf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor Evaluation loads about 2.8k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 125 tokens; SKILL.md has 1,503 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~125
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rampstackco/claude-skills at commit 482c9bf, republished under its MIT licence (© rampstackco). 1,503 words, ~2,840 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-evaluation/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
vendor-evaluation
description
Evaluate, select, and contract with vendors and SaaS tools. Use this skill when comparing alternatives, running an RFP, scoring vendors against criteria, negotiating contracts, planning a switch, or assessing a vendor's risk. Triggers on vendor evaluation, RFP, vendor selection, build vs buy, SaaS evaluation, vendor scorecard, vendor comparison, contract negotiation, vendor switch, procurement. Also triggers when a renewal is coming up or when a tool isn't meeting expectations.
category
process-and-team
catalog_summary
Tool and vendor selection using a structured rubric
display_order
3

Vendor Evaluation

Pick the right tool or service, negotiate fair terms, and avoid the lock-in traps. Stack-agnostic. Applies to SaaS, infrastructure providers, agencies, and any external dependency.


When to use

  • Selecting a tool or vendor for a new need
  • Evaluating alternatives to a current vendor
  • Build vs buy analysis
  • Renewal coming up: should we stay or switch?
  • Running a formal RFP or RFI
  • Comparing finalists in a vendor selection
  • Negotiating a contract
  • Assessing vendor risk (financial, security, dependency)

When NOT to use

  • General cost reduction (use cost-optimization)
  • Specific contract legal terms (those go to legal)
  • Performance issues with an existing vendor (try fixing before switching)
  • Hiring an agency for a one-off project (lighter framework needed)

Required inputs

  • The need (what problem are you solving, what would success look like)
  • Constraints (budget, timeline, integration requirements)
  • Stakeholders (users, IT, security, finance, legal)
  • Existing context (what's already used, what's been tried)
  • Compliance requirements

The framework: 5 phases

A structured vendor evaluation. Skip phases at your peril.

Phase 1: Define the need

Before looking at vendors, define what you actually need.

  • What problem are you solving?
  • What's the user / use case?
  • What does "success" look like in 6 months? In 2 years?
  • What's the budget (range, not just ceiling)?
  • What's the timeline?
  • Are there must-have integrations or constraints?

The temptation: skip this and start demoing. Vendors are happy to show off; you end up choosing what looks shiny rather than what fits.

Phase 2: Build vs buy

Before evaluating vendors, decide whether you should build instead.

Build when:

  • It's core to the business (differentiating)
  • The need is so specific no vendor matches
  • The economics work at your scale
  • You have the team to maintain it
  • Vendor lock-in would be unacceptable

Buy when:

  • It's table stakes (not differentiating)
  • The need is well-served by existing products
  • The economics favor it
  • The team should focus elsewhere
  • The vendor's specialization beats your generalism

Most teams over-build. The rule of thumb: buy unless there's a strong reason to build. Then question even that strong reason.

Phase 3: Generate the shortlist

Cast a wider net than feels comfortable, then narrow.

Sources:

  • Internal team's existing knowledge
  • Industry analyst reports (Gartner, Forrester, etc.)
  • Peer recommendations (other companies similar to yours)
  • Reviews (G2, Capterra; with caveats about review quality)
  • Adjacent vendors you already use (often have the feature you need)
  • Open-source alternatives

Cast wide first. Aim for 5-8 candidates. Then narrow to 2-4 finalists for deep evaluation.

Phase 4: Score the finalists

Use a scorecard. Without one, you'll be swayed by demo theatrics or who has the friendliest sales rep.

Scorecard dimensions (weight by your situation):

Functional fit (40%): Does it do what you need? Edge cases handled? UX quality. Workflow fit.

Technical fit (15%): Integration with your stack. API quality and completeness. Data export and portability. Performance at your scale. Self-hosted, hybrid, or SaaS-only.

Operational fit (10%): Onboarding effort. Training and adoption. Documentation quality. Support quality (test by submitting a ticket). SLAs.

Security and compliance (10%): SOC 2, ISO 27001, HIPAA, etc., as applicable. Data residency. Encryption at rest and in transit. Access controls and audit logs. Penetration test results (ask). Subprocessors.

Vendor health (10%): Years in business. Funding and runway (or revenue if private). Customer base size and similar customers. Public references. Roadmap visibility.

Cost (10%): License or subscription cost. Implementation and onboarding cost. Training cost. Integration cost. Opportunity cost (in-house resource time). Switching cost (in case of failure).

Lock-in risk (5%): Data export quality. Standard formats vs proprietary. Migration paths to alternatives. Open standards alignment. Contract escape clauses.

Score each finalist 1-5 on each dimension. Multiply by weight. Sum.

The score isn't gospel. It surfaces the tradeoffs.

Phase 5: Negotiate

Most enterprise contracts are negotiable. Most aren't negotiated.

What's negotiable:

  • Price (multi-year, volume, prepayment, end-of-quarter timing)
  • Terms (payment schedule, renewal terms)
  • Success commitments (training, onboarding, support)
  • SLAs (uptime, response time, credits)
  • Termination clauses (auto-renewal, notice period, data export)
  • Liability caps and indemnity (legal will care about these)
  • Subprocessors and data handling (security/legal cares)

Common negotiation moves:

  • Multi-year discount (3-year for a 15-30% discount is common)
  • Volume tiers (commit to higher usage for a per-unit discount)
  • Annual prepayment for a discount
  • Free or discounted onboarding
  • Pilot pricing (trial period at reduced rate)
  • "Most favored customer" clauses (if your size warrants)

What to avoid:

  • Multi-year lock with no escape clause for material breach
  • Auto-renewal with short notice window (under 60 days; want longer)
  • "All right, no further negotiation" stance from the start
  • Signing without legal review

Workflow

Step 1: Define the need

Write a one-page brief: what we need, why, success criteria, constraints, stakeholders.

Step 2: Build vs buy

Honestly answer the build/buy question. Document the rationale.

Step 3: Generate shortlist

Wider net first, narrowed via desk research:

  • Read summaries
  • Skim reviews
  • Look at customer logos
  • Skim docs
  • Skim API specs

Eliminate obvious misfits. Land on 2-4 finalists.

Step 4: Run demos and trials

For each finalist:

  • Demo with the use case (don't take their default demo; bring yours)
  • Trial period if possible
  • Reference calls with similar customers
  • Pilot with real data if feasible

Don't be charmed by the polished demo. Try it with your real workflow.

Step 5: Run security and compliance review

Critical for any vendor handling sensitive data:

  • Request SOC 2 / ISO 27001 reports
  • Review their security questionnaire (most have one ready)
  • Verify data handling matches your requirements
  • Identify subprocessors

This can take weeks for enterprise vendors. Start early.

Show full SKILL.md (603 more words)Show less
Step 6: Score

Apply the scorecard. Do this collaboratively with stakeholders.

The scoring conversation matters more than the final number. It surfaces disagreement (one person scored UX 5, another scored 2: why?).

Step 7: Negotiate

With the apparent winner:

  • Open negotiation by asking for terms (not just price)
  • Be willing to walk
  • Run negotiations with #2 in parallel where appropriate (gives you leverage)
Step 8: Plan the rollout

Contract signing is the start, not the end. Plan:

  • Onboarding owner
  • Training plan
  • Migration plan if replacing an incumbent
  • Success criteria at 30, 90, 180 days
  • Renewal calendar
Step 9: Document

Record:

  • The decision and the rationale
  • Alternatives considered
  • Scorecard results
  • Negotiated terms
  • Renewal date and notice deadlines
  • Owner of the relationship

This is gold for the next renewal or the next similar evaluation.


Failure patterns

Skipping the needs definition. Demoing first. Buying what's shiny. Realizing 6 months in that the actual need wasn't met.

Single-source decisions. Talking to one vendor; deciding. No comparison. Probably overpaying or under-fitting.

Charisma-driven decisions. Buying based on the sales rep's likability. The product is what you'll use for years; the rep won't be there.

Reference calls that the vendor curated. Of course their references love them. Find references the vendor didn't suggest.

Glossing over security. Security review skipped because of timeline pressure. Then a breach. Slow down or accept the risk explicitly.

Demos that don't match the use case. Their default demo, not yours. Always do a use-case demo.

Trial that doesn't simulate real usage. A trial with synthetic data tells you the product works in synthetic conditions. Use real (or close to real) data.

Negotiating only on price. Terms, SLAs, and exit clauses matter more for long-term satisfaction than 5% price.

Auto-renewal without notice tracking. Renewal happens; rate goes up 15%. No one was watching. Track renewals; review with notice.

Lock-in without exit plan. Tightly integrating into a vendor's proprietary surface. When you want to leave, you can't. Plan exit at the start.

Multi-year contract for an unproven vendor. Save the multi-year for vendors you trust. New vendor: shorter term, evaluate after.

No internal champion. Tool selected; no one drives adoption. Tool sits unused. Identify the champion before signing.

Negotiating after a verbal commitment. "Yes, we want to buy" means they have less reason to negotiate. Keep options open until terms are settled.

Ignoring red flags in security review. Vendor's security responses are evasive or incomplete. Treat as a no.

Comparing apples to oranges. Vendors price differently (per user, per usage, flat). Build a comparable cost model at your scale.


Output format

A vendor evaluation document includes:

  • Need brief: problem, success criteria, constraints
  • Build vs buy decision: with rationale
  • Shortlist: 2-4 finalists with brief description
  • Scorecard: filled out per finalist, or state the gap per the data-availability rule
  • Demo and trial notes: what was learned
  • Security and compliance summary: findings per finalist
  • Reference call notes: what customers said
  • Recommendation: which vendor, with rationale
  • Negotiated terms: what was agreed
  • Rollout plan: onboarding, training, migration
  • Renewal calendar: with notice deadline

If required data is unavailable

This skill's output depends on data, measurements, or tool results it cannot generate on its own. When a required input, tool, or data source is unavailable or unverifiable, the sanctioned output is the deliverable with the gap stated: what was needed, what was actually obtained or verified, and which parts of the output are affected. Fabricating, estimating, or interpolating a required number to complete the deliverable is never sanctioned. A stated gap is a complete answer.


Reference files

  • references/evaluation-rubric.md - Scoring template with weighted dimensions, 1-5 scale criteria for each dimension, and a worked vendor-comparison example.

© rampstackco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/vendor-evaluation of rampstackco/claude-skills.

  • SKILL.md
  • README.md
  • references/evaluation-rubric.md

Open the folder on GitHubat commit 482c9bf

Compare with similar skills

Vendor Evaluation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor Evaluation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor Evaluation this skillrampstackco/claude-skills935—~2.8kAutomated safety check: PassMIT
Serenity Alphahaskaomni/serenity-skill632—~2.6kAutomated safety check: PassMIT
Scorecard Matrixpnp/sharepoint-skills131—~1.9kAutomated safety check: PassMIT
Buyer Job Intent Analysiselvisun/newsjack1.5k—~1.4kAutomated safety check: PassMIT
Energy Procurementaffaan-m/ECC274k4 repos~7.4kAutomated safety check: PassApache-2.0
Master Builderibuilder/massing121—~2.6kAutomated safety check: PassMIT

Similar skills

  • Serenity Alpha

    haskaomni/serenity-skill

    Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…

    632 GitHub stars~2.6k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Scorecard Matrix

    pnp/sharepoint-skills

    Generates a polished, self-contained HTML heatmap scorecard — a weighted comparison matrix where entities (rows) are scored across dimensions (columns), with computed totals, rank badges, and a…

    131 GitHub stars~1.9k tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Recover source-bound buyer jobs, struggling moments, desired progress, forces, workarounds, information acts, journey states, criteria, constraints, roles, locales, and authentic language.

    1.5k GitHub stars~1.4k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Energy Procurement

    affaan-m/ECC

    Procure electricity and natural gas for commercial and industrial facilities: tariff and rate-schedule optimization, demand-charge mitigation, supplier RFPs, fixed/index/block-and-index hedging…

    274k GitHub starsUsed in 4 repos~7.4k tokens
    Business, Finance & HRAuto-check passed
  • Master Builder

    ibuilder/massing

    Reason like a master builder — one mind holding an entire built-asset project from raw land through design, construction, handover, operations, and disposition, anywhere in the world.

    121 GitHub stars~2.6k tokensUpdated 5 days ago
    Business, Finance & HRAuto-check passed
  • Procurement Audit

    vixues/LeAgent

    Review procurement contracts and purchase packages against uploaded compliance rules (招标/采购制度).

    231 GitHub stars~321 tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed

More from rampstackco/claude-skills

All 103 skills in this repo
  • After Action Report

    rampstackco/claude-skills

    Run a structured after-action review (postmortem, retrospective) on a launch, incident, or completed project to capture timeline, root cause analysis, contributing factors, and actionable lessons.

    935 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Analytics Strategy

    rampstackco/claude-skills

    Design measurement frameworks including event taxonomy, KPI hierarchy, dashboard architecture, attribution models, and analytics implementation strategy.

    935 GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Brand Style Guide

    rampstackco/claude-skills

    Build or audit a comprehensive brand style guide that documents the full brand system including story, logo system, color, typography, imagery, voice, applications, and dos/don'ts.

    935 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Brand Voice

    rampstackco/claude-skills

    Develop or document a complete brand voice and tone system covering voice attributes, tone shifts by context, vocabulary preferences, grammar rules, and copy examples.

    935 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Content And Copy

    rampstackco/claude-skills

    Write or edit website copy, blog content, and editorial pieces with attention to voice, structure, and goal.

    935 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Content Strategy

    rampstackco/claude-skills

    Develop a content strategy covering editorial positioning, content pillars, formats, calendar, governance, and topical authority planning.

    935 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Questions about Vendor Evaluation

What does Vendor Evaluation do?

Evaluate, select, and contract with vendors and SaaS tools. An agent skill from rampstackco/claude-skills. Vendor Evaluation is an agent skill from rampstackco/claude-skills. Evaluate, select, and contract with vendors and SaaS tools.

When should I use Vendor Evaluation?

Vendor Evaluation fits situations like: comparing alternatives; scoring vendors against criteria; negotiating contracts; planning a switch.

How do I install Vendor Evaluation in Claude Code?

Run `npx skills add rampstackco/claude-skills --skill vendor-evaluation -a claude-code`. Or copy the skill folder (skills/vendor-evaluation in rampstackco/claude-skills) into .claude/skills/vendor-evaluation in your project. Claude Code loads it when a task matches its description.

How do I install Vendor Evaluation in Codex?

Run `npx skills add rampstackco/claude-skills --skill vendor-evaluation -a codex`. Or copy the skill folder (skills/vendor-evaluation in rampstackco/claude-skills) into .agents/skills/vendor-evaluation in your project. Codex loads it when a task matches its description.

Can I use Vendor Evaluation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rampstackco/claude-skills --skill vendor-evaluation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-evaluation, .gemini/skills/vendor-evaluation, .github/skills/vendor-evaluation and .opencode/skills/vendor-evaluation in your project.

What does Vendor Evaluation need to run?

SKILL.md names no scripts, command-line tools or credentials: Vendor Evaluation is instructions for the agent only.

Does Vendor Evaluation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor Evaluation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vendor Evaluation use?

Vendor Evaluation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor Evaluation use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Vendor Evaluation?

Skills that share tags, products or a category with Vendor Evaluation: Serenity Alpha (haskaomni/serenity-skill, 632 stars), Scorecard Matrix (pnp/sharepoint-skills, 131 stars), Buyer Job Intent Analysis (elvisun/newsjack, 1.5k stars) and Energy Procurement (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor Evaluation?

rampstackco (a GitHub organization) maintains it in rampstackco/claude-skills, which has 935 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 7, 2026.

Source: rampstackco/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.