Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Vendor Risk Assessment Automator

    1

    Review vendor security questionnaires against your own InfoSec policies, surface evidence-backed gaps, draft mitigation requests, and track vendor changes over time in local SQLite.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    Vendor Risk Assessment Automator

    Vendor Risk Assessment Automator

    Example session with this skill installed

    Review AcmeCloud-Security-Questionnaire.xlsx against our internal policies in the policies/ folder.

    Normalize every questionnaire row and map the vendor's responses against our security requirements.

    Do not approve or reject the vendor automatically.

    For each gap, partial answer, or unknown item, show:

    • the questionnaire question;
    • the vendor response;
    • the internal requirement;
    • severity;
    • why the answer is insufficient;
    • the exact evidence or mitigation we should request.

    Compare this review with any prior AcmeCloud assessment in the local SQLite history database.

    Generate the risk summary, findings CSV, history changes, and a professional follow-up email to the vendor.

    • Read your context and instructions
    • Compiled the vendor risk assessment
    • Generated the data export

    Vendor security review complete

    Vendor: AcmeCloud
    Questionnaire rows processed: 327
    Internal requirements loaded: 84
    Mapped questionnaire rows: 311
    Rows requiring manual mapping: 16
    Risk index: 28.4 / 100
    Critical/High unresolved findings: 7
    Material changes since prior review: 5

    The risk index is a review-prioritization metric only. No procurement approval or rejection was performed.

    Material findings

    SeverityStatusDomainFinding
    CriticalPARTIALIdentity & AccessMFA is described for employees but privileged production access is not explicitly covered.
    HighUNKNOWNIncident ResponseThe response confirms an IR plan but does not establish customer notification procedures.
    HighGAPBusiness ContinuityThe vendor states disaster-recovery testing has not yet been completed.
    MediumPARTIALEncryptionEncryption at rest is confirmed but supporting architecture evidence is missing.

    Changes from the previous assessment

    Five vendor responses changed since the prior review.

    Two improved

    • endpoint management coverage is now documented;
    • annual penetration testing is now confirmed.

    Three require review

    • recovery testing moved from “completed annually” to “planned”;
    • the incident notification answer is less specific than last year;
    • a new subprocesser answer introduces an unreviewed hosting dependency.

    Files generated

    • normalized_questionnaire.csv
    • policy_requirements.json
    • mapping_results.json
    • risk_findings.csv
    • assessment_summary.md
    • vendor_followup_email.md
    • history_changes.csv
    • run_manifest.json

    Vendor follow-up draft

    Subject: Security review follow-up — AcmeCloud

    Hello AcmeCloud team,

    Thank you for completing our security review. We have a few items that require clarification or supporting evidence before our internal review can be completed.

    1. Privileged access / MFA — Critical

    Please confirm that MFA is enforced for all privileged production and administrative access and provide the relevant policy or control evidence.

    1. Incident response — High

    Please provide the section of your incident response process covering customer notification and escalation.

    1. Business continuity — High

    Please provide the planned remediation timeline for disaster-recovery testing and evidence of the next completed test.

    Thank you,
    Vendor Risk / Security Review Team

    Review note: This assessment is decision support for your vendor-risk process and requires human review before procurement or security approval.

    vendor-risk-assessment-automator.csv

    CSV · data export

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Map vendor answers to internal security controls with traceable evidence.Calculate weighted risk scores to prioritize security analyst reviews.Generate vendor follow-up emails for missing or incomplete security evidence.Track vendor security posture changes over time using local SQLite history.

    About this skill

    The problem

    Security questionnaires can contain hundreds of questions. Analysts must cross-check each answer against internal security requirements, identify weak or missing evidence, draft follow-ups, and repeat the same work every year.

    This slows procurement and makes it easy to lose context between vendor reviews.

    What it does

    Vendor Risk Assessment Automator turns local security policies and vendor questionnaires into a structured, reviewable third-party risk package.

    • Parses Excel, CSV, PDF, Markdown, and text questionnaires
    • Normalizes questionnaire rows without silently dropping questions
    • Maps vendor answers to your own InfoSec requirements
    • Highlights PASS, PARTIAL, GAP, UNKNOWN, and REVIEW findings
    • Uses deterministic severity scoring based on your internal requirements
    • Generates a structured risk summary
    • Drafts vendor mitigation and evidence requests
    • Stores assessment history locally in SQLite
    • Compares current answers with previous vendor assessments

    Why this beats prompting it yourself

    A generic AI prompt can summarize a questionnaire, but it can lose row-level context, miss contradictions across hundreds of questions, or apply inconsistent scoring.

    This skill keeps every questionnaire row traceable, validates requirement mappings, calculates review-priority scores deterministically, and preserves vendor response history between assessment cycles.

    Built for human review

    The skill does not automatically approve or reject vendors.

    Final vendor acceptance, compensating controls, exceptions, and contractual decisions remain with your procurement and security teams.

    Privacy-first workflow

    Vendor questionnaires often contain confidential security and architecture information.

    The default workflow processes files locally, stores normalized assessment history in local SQLite, and does not automatically upload source documents or evidence to external services.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 13 days ago

    • Passed all security checks, Safe to install

    Listed13 days ago

    What's inside

    Frequently Asked Questions