1kalin/afrexai-vendor-risk/SKILL.md
# Vendor Risk Assessment Score and manage third-party vendor risk across security, financial stability, compliance, operational dependency, and data handling. Built for procurement teams, CISOs, and operations leaders managing 10+ vendors. ## Usage Run this assessment for each critical vendor. Aggregate scores into a portfolio risk view. ## Assessment Framework ### 1. Vendor Risk Scorecard (5 Domains, 0-100 each) **Security Posture (0-100)** - SOC 2 Type II current? (+20) - Penetration test
npx skillsauth add openclaw/skills 1kalin/afrexai-vendor-riskInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Score and manage third-party vendor risk across security, financial stability, compliance, operational dependency, and data handling. Built for procurement teams, CISOs, and operations leaders managing 10+ vendors.
Run this assessment for each critical vendor. Aggregate scores into a portfolio risk view.
Security Posture (0-100)
Financial Stability (0-100)
Compliance & Regulatory (0-100)
Operational Dependency (0-100)
Data Handling (0-100)
| Aggregate Score | Tier | Review Cadence | Action | |----------------|------|---------------|--------| | 400-500 | Low Risk | Annual | Standard monitoring | | 300-399 | Moderate | Semi-annual | Remediation plan required | | 200-299 | High Risk | Quarterly | Executive escalation, alternatives identified | | 0-199 | Critical | Monthly | Exit plan required within 90 days |
Total vendors: ___
Critical tier: ___ (target: 0)
High risk: ___ (target: <10%)
Moderate: ___ (target: <30%)
Low risk: ___ (target: >60%)
Top 3 concentration risks:
1. [Vendor] — [function] — [% of operations dependent]
2. [Vendor] — [function] — [% of operations dependent]
3. [Vendor] — [function] — [% of operations dependent]
Annual vendor spend: $___
Spend on high/critical vendors: $___ (___%)
| Impact Area | Calculation | |------------|-------------| | Revenue loss | Daily revenue × expected downtime days | | Recovery cost | Migration estimate + emergency procurement | | Compliance penalty | Regulatory fine range for data breach via vendor | | Reputation damage | Customer churn rate × LTV × affected customers | | Operational disruption | Staff idle cost × recovery period |
| Industry | Critical Vendor Category | Specific Risk | |----------|------------------------|---------------| | Healthcare | EHR, billing, telehealth | HIPAA BAA gaps, PHI exposure | | Financial Services | Core banking, payments, KYC | PCI DSS, regulatory reporting | | Legal | Case management, ediscovery | Privilege breach, client data | | SaaS | Infrastructure, auth, payments | Cascading outages, PII | | Manufacturing | MES, supply chain, IoT | IP theft, production stoppage | | Construction | Project management, safety | Compliance documentation gaps | | Ecommerce | Payments, fulfillment, CDN | PCI, availability during peak | | Recruitment | ATS, background check, payroll | Candidate PII, bias in AI screening | | Real Estate | MLS, transaction mgmt, title | Wire fraud, closing delays | | Professional Services | CRM, billing, document mgmt | Client confidentiality breach |
tools
Use when the user wants to connect to, test, or use the McDonalds service at mcp.mcd.cn, including checking authentication, probing MCP endpoints, listing tools, or calling McDonalds MCP tools through a reusable local CLI.
development
Web scraping platform — Twitter/X data, Vinted marketplace, and general web scraping API
development
SlowMist AI Agent Security Review — comprehensive security framework for skills, repositories, URLs, on-chain addresses, and products (Claude Code version)
data-ai
去除中文文本中的 AI 写作痕迹,使其读起来自然。基于维基百科 AI 写作特征指南,检测 24 种 AI 模式。触发词:humanizer-cn、去除 AI 痕迹、去除 AI 写作痕迹、中文文本人性化。