plugins/pm-operations/skills/vendor-contract-checklist/SKILL.md
Review a vendor/SaaS contract against a practical checklist before you sign. Use when asked to review a vendor contract, check a SaaS/MSA/subscription agreement, flag risky terms, or prepare negotiation points before signing. Produces a structured review — key terms extracted, a risk-flagged checklist (commercial, legal, security, exit), questions to ask, and prioritised negotiation points. Not legal advice.
npx skillsauth add mohitagw15856/pm-claude-skills vendor-contract-checklistInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Most bad vendor deals are lost in the terms nobody read: auto-renewal, price escalators, weak SLAs, no exit, vague data rights. This skill reviews a contract against a practical checklist, extracts the terms that actually bite, flags the risks, and turns them into specific questions and negotiation points — so you sign with your eyes open.
Note: this is a practical review aid, not legal advice. For material commitments, high spend, or anything regulated, have it reviewed by qualified counsel. Flag, don't rule on, legal questions.
Given a contract (or a description of one), produce the full review anyway — extract what's present, and for standard terms that are missing or unstated, flag them as gaps to confirm rather than assuming they're fine. Never withhold the review for an incomplete document; mark what couldn't be assessed.
Ask for these only if they aren't already provided (else mark as "not found — confirm"):
1. Key terms at a glance — extracted: parties, term & renewal, total cost & escalators, payment terms, SLA, liability cap, termination, data/IP, governing law.
2. Risk-flagged checklist — by area, each marked ✅ ok / ⚠️ review / ❌ problem / ❓ not found:
| Area | Item | Status | Note | |---|---|---|---| | Commercial | auto-renewal & notice period | ⚠️ | 60-day notice, auto-renews 12 mo — calendar it | | Commercial | price increase cap | ❓ | not capped — negotiate a cap | | Legal | liability cap vs. fees | ⚠️ | capped at 3 months' fees — low for the risk | | Security/data | data deletion & portability on exit | ❌ | not addressed — add | | SLA | uptime + remedy (credits) | ⚠️ | 99.5%, credits only — check fit | | Exit | termination for convenience | ❓ | not present — request |
3. Questions to ask the vendor — the specific clarifications before signing.
4. Negotiation points — prioritised, with a suggested ask for each (what "good" looks like): the few terms worth pushing on, and the rationale.
5. Sign-off note — what's fine, what needs negotiation, and what to send to legal.
Procurement and vendor-risk practice — key-term extraction, risk-flagged review across commercial/legal/security/exit, and prioritised negotiation.
business
Analyze why deals are won and lost and turn it into an action plan. Use when asked to run a win/loss analysis, review closed-won and closed-lost deals, understand why the team is losing to a competitor, or summarize sales feedback into patterns. Produces a structured win/loss report with themes, win/loss rates by segment and competitor, representative quotes, and prioritized actions for product, marketing, and sales.
development
Route a fuzzy request to the right skill in this library. Use when the user is unsure which skill fits, asks 'which skill should I use for X', describes a task without naming a skill, or when a request could plausibly match several skills. Produces a best-fit recommendation with the inputs to gather, a runner-up with the tie-breaker, and a workflow recipe when the job spans multiple skills.
testing
Triage a vulnerability or scanner finding — assess real severity, exploitability, and how urgently to fix. Use when asked to triage a CVE, prioritize scanner/pentest findings, assess a vuln's risk, or decide what to patch first. Produces a triage verdict: CVSS-informed severity adjusted for your context, exploitability, real risk, a fix/mitigation, and an SLA — so you fix what matters, not just what's red.
development
Stand up a Voice of Customer (VoC) program that turns feedback into action. Use when asked to build a VoC program, design a customer feedback loop, consolidate feedback sources, or set up a closed-loop feedback process. Produces a VoC program design — objectives, feedback sources and channels, a taxonomy, collection and analysis cadence, closed-loop routing, ownership, and success metrics.