Vendor assessor
Skill maxwellokumu/okaudit-claude-skills/vendor-risk/vendor-assessor
Claude-ready IT audit skills for identity, compliance, appsec, privacy, network, logging, vendor risk, and audit leadership workflows
npx -y skills add maxwellokumu/okaudit-claude-skills --skill vendor-assessorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 5 stars5 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Evaluate third-party security posture from assessment responses so Claude can explain vendor risk scores, category weaknesses, and follow-up priorities clearly.
SKILL.md
1.6 KB, as published. Nobody here has run it
Vendor Assessor
Use this skill when the user wants to score a vendor security assessment, understand category-level weaknesses, or summarize third-party risk from questionnaire responses.
Goal
Help Claude turn vendor assessment answers into a practical view of security posture, key weaknesses, and the most important follow-up actions.
Workflow
- Confirm the vendor assessment answer file and whether custom weighting is being used.
- Review the responses across the major risk categories.
- Identify weak areas, partial controls, or response patterns that materially increase vendor risk.
- Summarize the overall posture and the issues that deserve the highest follow-up priority.
- Present the result in a concise format suitable for procurement, security, or audit review.
Inputs
Expected inputs from the bundled tool metadata:
- answers: Path to the vendor assessment answers file.
- weights: Optional path to custom category weights.
- output: Optional output format such as markdown or json.
Bundled Files
- main.py contains the executable vendor scoring logic.
- README.md provides guidance and examples.
- skill.yaml captures the repo-native metadata for this skill.
- sample_input may contain representative questionnaire responses.
Guidance
Focus on material vendor risk, not just the numeric score. Explain which control areas are weakest and what follow-up evidence or remediation is most important.