Serenity Alpha
haskaomni/serenity-skill
Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…
Implement vendor risk management programs. An agent skill from sickn33/agentic-awesome-skills.
$ npx skills add sickn33/agentic-awesome-skills --skill vendor-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills vendor-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vendor-management .claude/skills/vendor-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vendor-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/vendor-management into .claude/skills/vendor-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/vendor-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill vendor-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills vendor-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/vendor-management .agents/skills/vendor-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vendor-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/vendor-management into .agents/skills/vendor-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill vendor-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills vendor-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/vendor-management .cursor/skills/vendor-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vendor-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/vendor-management into .cursor/skills/vendor-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/vendor-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill vendor-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills vendor-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/vendor-management .gemini/skills/vendor-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vendor-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/vendor-management into .gemini/skills/vendor-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills vendor-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill vendor-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/vendor-management .github/skills/vendor-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vendor-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/vendor-management into .github/skills/vendor-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill vendor-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills vendor-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/vendor-management .opencode/skills/vendor-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vendor-management" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/vendor-management into .opencode/skills/vendor-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vendor-managementImplement vendor risk management programs. An agent skill from sickn33/agentic-awesome-skills.
Vendor Management is an agent skill from sickn33/agentic-awesome-skills. Implement vendor risk management programs. Assess third-party security and maintain vendor inventory. Use when managing supplier security.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/details.md`). Compatibility notes: Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process.
It sits in Business, Finance & HR, covering Vendor and procurement management. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml, python and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process.
From compatibility in the SKILL.md frontmatter.
Vendor Management loads about 3.8k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 39 tokens; SKILL.md has 148 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 148 words, ~3,835 tokens.
.claude/skills/vendor-management/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Implement a vendor risk management program covering vendor assessment questionnaires, risk scoring, contract tracking, SLA monitoring, and ongoing oversight for compliance with SOC 2, ISO 27001, and regulatory frameworks.
vendor_risk_tiers:
critical:
criteria:
- Processes or stores sensitive/regulated data (PII, PHI, PCI)
- Single point of failure (no alternative vendor)
- Has privileged access to production systems
- Handles authentication or security-critical functions
assessment_requirements:
- Full security questionnaire (SIG or custom)
- SOC 2 Type II report review (or equivalent)
- Penetration test results review
- On-site or virtual security assessment (optional)
- Business continuity and DR plan review
review_frequency: Annual
contract_requirements:
- Data processing agreement (DPA)
- Business associate agreement (BAA) if PHI
- Security SLA with breach notification timeline
- Right to audit clause
- Cyber insurance requirements
examples:
- Cloud infrastructure providers (AWS, Azure, GCP)
- Identity providers (Okta, Azure AD)
- Payment processors (Stripe, Adyen)
- Primary database or CRM SaaS
high:
criteria:
- Accesses significant company data (internal or confidential)
- Integrates with production systems via API
- Processes customer-facing transactions
- Substitution would cause significant business disruption
assessment_requirements:
- Security questionnaire
- SOC 2 report review (Type I or Type II)
- Compliance certifications verified
review_frequency: Annual
contract_requirements:
- Data processing agreement
- Security requirements appendix
- Incident notification clause (72 hours)
examples:
- Email/marketing platforms (SendGrid, HubSpot)
- Monitoring and logging SaaS (Datadog, Splunk)
- CI/CD platforms (GitHub, GitLab)
- Customer support platforms
medium:
criteria:
- Limited data access (internal data only)
- Non-production system integration
- Some business impact if unavailable
assessment_requirements:
- Abbreviated security questionnaire
- Compliance certification verification
review_frequency: Every 2 years
contract_requirements:
- Standard vendor terms with security clause
- NDA
examples:
- Project management tools
- HR platforms
- Travel and expense systems
low:
criteria:
- No access to company data
- No system integration
- Easily replaceable
assessment_requirements:
- Basic due diligence (public info review)
- Confirm no data sharing
review_frequency: Every 3 years or on renewal
contract_requirements:
- Standard terms
examples:
- Office supply vendors
- Facilities services
- General consulting (no data access)security_questionnaire:
section_1_governance:
questions:
- "Do you have a documented information security policy?"
- "Is there a designated CISO or security lead?"
- "Do you conduct annual security risk assessments?"
- "Do you have a security awareness training program?"
- "What compliance certifications do you hold? (SOC 2, ISO 27001, etc.)"
- "When was your last external security audit?"
- "Do you carry cyber liability insurance? What coverage limits?"
evidence_requested:
- Information security policy (or summary)
- SOC 2 Type II report (or bridge letter)
- ISO 27001 certificate
- Cyber insurance certificate
section_2_access_control:
questions:
- "How do you manage user access to systems containing our data?"
- "Is multi-factor authentication enforced for all personnel?"
- "How frequently do you conduct access reviews?"
- "What is your process for revoking access upon employee termination?"
- "Do you support SSO/SAML integration for customer access?"
- "How do you manage privileged access?"
evidence_requested:
- Access management policy
- MFA configuration documentation
- Access review records (sample)
section_3_data_protection:
questions:
- "How is our data encrypted at rest?"
- "How is our data encrypted in transit?"
- "In which geographic regions is our data stored?"
- "Do you use sub-processors? If so, provide a list."
- "What is your data retention policy?"
- "How is our data isolated from other customers? (multi-tenancy model)"
- "Can you provide data export in standard formats upon request?"
- "What is your data destruction process at contract end?"
evidence_requested:
- Encryption standards documentation
- Sub-processor list
- Data flow diagram showing customer data handling
section_4_vulnerability_management:
questions:
- "How frequently do you perform vulnerability scans?"
- "How frequently do you conduct penetration tests?"
- "What is your patch management SLA for critical vulnerabilities?"
- "Do you have a responsible disclosure or bug bounty program?"
- "How do you manage vulnerabilities in third-party dependencies?"
evidence_requested:
- Penetration test executive summary (last 12 months)
- Vulnerability management policy
- Patch management SLA documentation
section_5_incident_response:
questions:
- "Do you have a documented incident response plan?"
- "What is your breach notification timeline?"
- "Have you experienced a data breach in the last 3 years?"
- "How would you notify us in the event of a security incident?"
- "Do you conduct incident response tabletop exercises?"
evidence_requested:
- Incident response plan summary
- Breach notification procedure
section_6_business_continuity:
questions:
- "Do you have a business continuity plan?"
- "Do you have a disaster recovery plan?"
- "What are your RTO and RPO targets?"
- "How frequently do you test your DR plan?"
- "What is your uptime SLA?"
- "Do you have geographic redundancy?"
evidence_requested:
- BCP/DR plan summary
- Uptime SLA documentation
- Most recent DR test results
section_7_compliance:
questions:
- "Do you process data subject to GDPR, HIPAA, or PCI DSS?"
- "How do you support our compliance obligations?"
- "Do you have a Data Processing Agreement (DPA) template?"
- "How do you handle data subject access requests (DSARs)?"
- "Are you FedRAMP authorized? If so, at what impact level?"
evidence_requested:
- DPA template
- Compliance certification documentationrisk_scoring:
dimensions:
data_sensitivity:
weight: 30
scores:
1: "No access to company or customer data"
2: "Access to public or non-sensitive internal data"
3: "Access to internal confidential data"
4: "Access to PII or customer financial data"
5: "Access to regulated data (PHI, PCI, classified)"
system_access:
weight: 25
scores:
1: "No system access"
2: "Read-only access to non-production"
3: "Read/write access to non-production or read-only production"
4: "Read/write access to production systems"
5: "Privileged/admin access to production or security systems"
business_criticality:
weight: 20
scores:
1: "No operational dependency"
2: "Minor convenience; easily replaced"
3: "Moderate dependency; replacement in weeks"
4: "Significant dependency; replacement in months"
5: "Critical dependency; no viable alternative"
security_posture:
weight: 15
scores:
5: "No certifications, no formal security program"
4: "Some security controls but no external validation"
3: "SOC 2 Type I or equivalent"
2: "SOC 2 Type II within last 12 months"
1: "Multiple certifications (SOC 2 + ISO 27001), strong program"
regulatory_exposure:
weight: 10
scores:
1: "No regulatory requirements"
2: "General data protection (GDPR basic)"
3: "Industry-specific (HIPAA, PCI)"
4: "Government (FedRAMP, ITAR)"
5: "Multiple stringent regulations"
calculation:
formula: "Sum of (dimension_score * dimension_weight) / 100"
risk_levels:
low: "Score 1.0 - 2.0"
medium: "Score 2.1 - 3.0"
high: "Score 3.1 - 4.0"
critical: "Score 4.1 - 5.0"
example:
vendor: "Payment Processor X"
data_sensitivity: 5 # PCI data
system_access: 4 # Production API integration
business_criticality: 5 # No alternative
security_posture: 2 # SOC 2 Type II
regulatory_exposure: 3 # PCI DSS
score: "(5*30 + 4*25 + 5*20 + 2*15 + 3*10) / 100 = 4.1 -> Critical"vendor_registry_schema:
vendor_info:
vendor_id: "VND-NNNN"
vendor_name: ""
vendor_website: ""
primary_contact_email: ""
security_contact_email: ""
vendor_category: "" # SaaS, IaaS, Consulting, etc.
risk_assessment:
risk_tier: "" # critical, high, medium, low
risk_score: 0.0
last_assessment_date: ""
next_assessment_date: ""
assessment_status: "" # current, due, overdue
open_findings: 0
certifications:
- type: "SOC 2 Type II"
valid_until: ""
report_on_file: true
- type: "ISO 27001"
valid_until: ""
certificate_on_file: true
contract:
contract_id: ""
start_date: ""
end_date: ""
auto_renewal: true
cancellation_notice_days: 90
annual_value: 0
terms:
data_processing_agreement: true
nda: true
baa: false
right_to_audit: true
breach_notification_sla: "72 hours"
data_return_clause: true
data_destruction_clause: true
cyber_insurance_required: true
data_access:
data_types: []
data_classification: ""
data_location: []
sub_processors: []
sla_tracking:
uptime_sla: "99.9%"
actual_uptime_last_month: ""
support_response_sla: ""
sla_breaches_ytd: 0
status: "" # active, under_review, offboarding, inactive
owner: "" # Internal team/person responsible"""
Vendor SLA monitoring - Track uptime and response time commitments.
"""
import requests
from datetime import datetime, timezone
class VendorSLAMonitor:
def __init__(self, vendors_config):
self.vendors = vendors_config
def check_uptime(self, vendor):
"""Check vendor service availability."""
results = []
for endpoint in vendor.get("health_endpoints", []):
try:
resp = requests.get(
endpoint["url"],
timeout=endpoint.get("timeout", 10),
headers=endpoint.get("headers", {}),
)
results.append({
"endpoint": endpoint["url"],
"status": resp.status_code,
"response_time_ms": resp.elapsed.total_seconds() * 1000,
"healthy": resp.status_code == endpoint.get("expected_status", 200),
"timestamp": datetime.now(timezone.utc).isoformat(),
})
except requests.RequestException as e:
results.append({
"endpoint": endpoint["url"],
"status": "error",
"error": str(e),
"healthy": False,
"timestamp": datetime.now(timezone.utc).isoformat(),
})
return results
def check_status_page(self, vendor):
"""Check vendor status page for active incidents."""
status_url = vendor.get("status_page_url")
if not status_url:
return None
try:
api_url = f"{status_url}/api/v2/summary.json"
resp = requests.get(api_url, timeout=10)
data = resp.json()
return {
"vendor": vendor["name"],
"status": data.get("status", {}).get("indicator", "unknown"),
"active_incidents": len(data.get("incidents", [])),
"components": [
{"name": c["name"], "status": c["status"]}
for c in data.get("components", [])
],
}
except Exception:
return {"vendor": vendor["name"], "status": "unknown"}
def generate_sla_report(self, vendor_name, monthly_checks):
"""Calculate monthly SLA compliance."""
total = len(monthly_checks)
healthy = sum(1 for c in monthly_checks if c.get("healthy"))
uptime_pct = (healthy / total * 100) if total > 0 else 0
avg_response = (
sum(c.get("response_time_ms", 0) for c in monthly_checks if c.get("healthy"))
/ max(healthy, 1)
)
return {
"vendor": vendor_name,
"period": datetime.now(timezone.utc).strftime("%Y-%m"),
"total_checks": total,
"healthy_checks": healthy,
"uptime_percentage": round(uptime_pct, 3),
"avg_response_time_ms": round(avg_response, 1),
"sla_met": uptime_pct >= 99.9,
}Map this skill's control checklist to our current evidence and list gaps.Adapted from BagelHole/DevOps-Security-Agent-Skills (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.
© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/vendor-management of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit b84d35a
We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Vendor Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vendor Management this skillsickn33/agentic-awesome-skills | 47k | 2 repos | ~3.8k | Automated safety check: Pass | MIT | |
| Serenity Alphahaskaomni/serenity-skill | 633 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Scorecard Matrixpnp/sharepoint-skills | 133 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Oma Imagefirst-fluke/oh-my-agent | 1.3k | — | ~2k | Automated safety check: Pass | MIT | |
| Buyer Job Intent Analysiselvisun/newsjack | 1.5k | — | ~1.4k | Automated safety check: Pass | MIT | |
| Master Builderibuilder/massing | 122 | — | ~2.6k | Automated safety check: Pass | MIT |
haskaomni/serenity-skill
Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…
pnp/sharepoint-skills
Generates a polished, self-contained HTML heatmap scorecard — a weighted comparison matrix where entities (rows) are scored across dimensions (columns), with computed totals, rank badges, and a…
first-fluke/oh-my-agent
Generate raster images or reference-guided variations through the OMA image CLI.
elvisun/newsjack
Recover source-bound buyer jobs, struggling moments, desired progress, forces, workarounds, information acts, journey states, criteria, constraints, roles, locales, and authentic language.
ibuilder/massing
Reason like a master builder — one mind holding an entire built-asset project from raw land through design, construction, handover, operations, and disposition, anywhere in the world.
affaan-m/ECC
Procure electricity and natural gas for commercial and industrial facilities: tariff and rate-schedule optimization, demand-charge mitigation, supplier RFPs, fixed/index/block-and-index hedging…
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Categories
Implement vendor risk management programs. An agent skill from sickn33/agentic-awesome-skills. Vendor Management is an agent skill from sickn33/agentic-awesome-skills. Implement vendor risk management programs.
Vendor Management fits situations like: managing supplier security; tasks that involve Vendor and procurement management.
Run `npx skills add sickn33/agentic-awesome-skills --skill vendor-management -a claude-code`. Or copy the skill folder (skills/vendor-management in sickn33/agentic-awesome-skills) into .claude/skills/vendor-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill vendor-management -a codex`. Or copy the skill folder (skills/vendor-management in sickn33/agentic-awesome-skills) into .agents/skills/vendor-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill vendor-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-management, .gemini/skills/vendor-management, .github/skills/vendor-management and .opencode/skills/vendor-management in your project.
SKILL.md names no scripts, command-line tools or credentials: Vendor Management is instructions for the agent only. Our summary lists: Python 3. Compatibility (from SKILL.md): Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process..
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vendor Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vendor Management: Serenity Alpha (haskaomni/serenity-skill, 633 stars), Scorecard Matrix (pnp/sharepoint-skills, 133 stars), Oma Image (first-fluke/oh-my-agent, 1.3k stars) and Buyer Job Intent Analysis (elvisun/newsjack, 1.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.