Works with the AI tools you already use
Vendor Risk Assessment Automator
Review vendor security questionnaires against your own InfoSec policies, surface evidence-backed gaps, draft mitigation requests, and track vendor changes over time in local SQLite.
$5
Vendor Risk Assessment Automator
Example session with this skill installed
Review AcmeCloud-Security-Questionnaire.xlsx against our internal policies in the policies/ folder.
Normalize every questionnaire row and map the vendor's responses against our security requirements.
Do not approve or reject the vendor automatically.
For each gap, partial answer, or unknown item, show:
- the questionnaire question;
- the vendor response;
- the internal requirement;
- severity;
- why the answer is insufficient;
- the exact evidence or mitigation we should request.
Compare this review with any prior AcmeCloud assessment in the local SQLite history database.
Generate the risk summary, findings CSV, history changes, and a professional follow-up email to the vendor.
- Read your context and instructions
- Compiled the vendor risk assessment
- Generated the data export
Vendor security review complete
Vendor: AcmeCloud
Questionnaire rows processed: 327
Internal requirements loaded: 84
Mapped questionnaire rows: 311
Rows requiring manual mapping: 16
Risk index: 28.4 / 100
Critical/High unresolved findings: 7
Material changes since prior review: 5
The risk index is a review-prioritization metric only. No procurement approval or rejection was performed.
Material findings
| Severity | Status | Domain | Finding |
|---|---|---|---|
| Critical | PARTIAL | Identity & Access | MFA is described for employees but privileged production access is not explicitly covered. |
| High | UNKNOWN | Incident Response | The response confirms an IR plan but does not establish customer notification procedures. |
| High | GAP | Business Continuity | The vendor states disaster-recovery testing has not yet been completed. |
| Medium | PARTIAL | Encryption | Encryption at rest is confirmed but supporting architecture evidence is missing. |
Changes from the previous assessment
Five vendor responses changed since the prior review.
Two improved
- endpoint management coverage is now documented;
- annual penetration testing is now confirmed.
Three require review
- recovery testing moved from “completed annually” to “planned”;
- the incident notification answer is less specific than last year;
- a new subprocesser answer introduces an unreviewed hosting dependency.
Files generated
- normalized_questionnaire.csv
- policy_requirements.json
- mapping_results.json
- risk_findings.csv
- assessment_summary.md
- vendor_followup_email.md
- history_changes.csv
- run_manifest.json
Vendor follow-up draft
Subject: Security review follow-up — AcmeCloud
Hello AcmeCloud team,
Thank you for completing our security review. We have a few items that require clarification or supporting evidence before our internal review can be completed.
- Privileged access / MFA — Critical
Please confirm that MFA is enforced for all privileged production and administrative access and provide the relevant policy or control evidence.
- Incident response — High
Please provide the section of your incident response process covering customer notification and escalation.
- Business continuity — High
Please provide the planned remediation timeline for disaster-recovery testing and evidence of the next completed test.
Thank you,
Vendor Risk / Security Review Team
Review note: This assessment is decision support for your vendor-risk process and requires human review before procurement or security approval.
vendor-risk-assessment-automator.csv
CSV · data export
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Security questionnaires can contain hundreds of questions. Analysts must cross-check each answer against internal security requirements, identify weak or missing evidence, draft follow-ups, and repeat the same work every year.
This slows procurement and makes it easy to lose context between vendor reviews.
What it does
Vendor Risk Assessment Automator turns local security policies and vendor questionnaires into a structured, reviewable third-party risk package.
- Parses Excel, CSV, PDF, Markdown, and text questionnaires
- Normalizes questionnaire rows without silently dropping questions
- Maps vendor answers to your own InfoSec requirements
- Highlights PASS, PARTIAL, GAP, UNKNOWN, and REVIEW findings
- Uses deterministic severity scoring based on your internal requirements
- Generates a structured risk summary
- Drafts vendor mitigation and evidence requests
- Stores assessment history locally in SQLite
- Compares current answers with previous vendor assessments
Why this beats prompting it yourself
A generic AI prompt can summarize a questionnaire, but it can lose row-level context, miss contradictions across hundreds of questions, or apply inconsistent scoring.
This skill keeps every questionnaire row traceable, validates requirement mappings, calculates review-priority scores deterministically, and preserves vendor response history between assessment cycles.
Built for human review
The skill does not automatically approve or reject vendors.
Final vendor acceptance, compensating controls, exceptions, and contractual decisions remain with your procurement and security teams.
Privacy-first workflow
Vendor questionnaires often contain confidential security and architecture information.
The default workflow processes files locally, stores normalized assessment history in local SQLite, and does not automatically upload source documents or evidence to external services.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 13 days ago
- Passed all security checks, Safe to install