agentsclimarketplace

VendorRiskAssessment

Skill joseruiz1571/healthcare-privacy-grc-toolkit/skills/VendorRiskAssessment

Conduct structured AI vendor risk assessments against HIPAA compliance and data privacy standards. USE WHEN assess vendor, evaluate AI tool, vendor risk check, is tool HIPAA compliant, can we use tool with PHI, vet AI vendor, vendor due diligence, review AI product, AI procurement risk, vendor security review, OR user pastes vendor documentation or privacy policy for analysis.From its SKILL.md

Install
npx -y skills add joseruiz1571/healthcare-privacy-grc-toolkit --skill VendorRiskAssessment

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

2.1 KB, 380 tokens by cl100k_base, as published. Nobody here has run it

VendorRiskAssessment

Evaluate Generative AI vendors and tools for organizational adoption in healthcare and regulated industries. Produces a completed assessment report with status findings and a clear recommendation — not a blank form.

Workflow Routing

WorkflowTriggerFile
Assess"assess vendor", "evaluate tool", "vendor risk check", "is [tool] HIPAA compliant"Workflows/Assess.md

Quick Reference

  • 5 assessment sections (22 items): BAA, Data Handling, Access Controls, Security Posture, Output Reliability
  • Hard stops: No BAA (1.1) or training on user data with no contractual opt-out (2.1) block PHI approval
  • 4 status indicators: Confirmed, Not Met, Unclear, Requires Verification
  • Output: Completed assessment tables + summary block with recommendation

Full assessment criteria: Checklist.md

Examples

Example 1: Assess a vendor by name

User: "Can we use Microsoft Azure OpenAI with PHI?"
-> Invokes Assess workflow
-> Walks through all 5 sections using available knowledge
-> Marks unverified items clearly
-> Produces assessment summary with recommendation

Example 2: Analyze vendor documentation

User: "Here's the privacy policy for [vendor], assess it"
-> Invokes Assess workflow
-> Extracts evidence from pasted documentation
-> Maps findings to checklist items
-> Flags gaps that need vendor follow-up

Example 3: URL-based assessment

User: "Evaluate this vendor: [trust page URL]"
-> Invokes Assess workflow
-> Fetches and analyzes URL content
-> Populates checklist from discovered evidence
-> Produces structured report

What ships with it: 2 files

7.9 KB alongside SKILL.md

Workflows/

Gives 0 of the 12 instructions most operations skills give in 380 tokens

Counted across 483 of the 484 authors here whose files we hold, read 2026-08-07

  • Collect monitoring data throughout the simulationin 14 of 483, across 6 files
  • Set the random seed for reproducibilityin 14 of 483, across 6 files
  • Validate simulations against analytical solutionsin 12 of 483, across 4 files
  • Clarify goals, constraints, and inputsin 11 of 483, across 2 files
  • Implement contract tests for integration pointsin 11 of 483, across 2 files
  • Implement strangler fig infrastructure with API gatewayin 11 of 483, across 2 files
  • Audit modernized components for security vulnerabilitiesin 11 of 483, across 2 files
  • Avoid Python blocking calls in processesin 10 of 483, across 3 files
  • Use resource context managers for automatic cleanupin 9 of 483, across 2 files
  • Maintain consistent time unitsin 9 of 483, across 2 files
  • Validate outcomes against success criteriain 8 of 483, across 1 file
  • Analyze the legacy codebase for technical debtin 8 of 483, across 1 file

Said here and by no other author read

  • Produce a completed assessment report
  • Do not produce a blank form
  • Include status findings
  • Walk through all five assessment sections
  • Mark unverified items clearly
  • Extract evidence from documentation

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.