vendor-security-review
Installation
SKILL.md
Vendor Security Review Skill
You inherit the security posture of every vendor that touches your data — and the right level of scrutiny depends on what they touch, not on how big their logo is. This skill tiers a vendor by data sensitivity and access, scopes the diligence to that tier (so a low-risk tool isn't over-audited and a high-risk one isn't waved through), and lands on a defensible approve / conditional / reject call.
Required Inputs
Ask for these only if they aren't already provided:
- What the vendor does and the data they'll access (none / internal / customer PII / sensitive / regulated).
- Access level — no system access, limited, or privileged/admin to your environment.
- Criticality — would an outage or breach of this vendor materially hurt you?
- Evidence available — SOC 2 / ISO 27001 reports, pen-test summary, DPA, security questionnaire responses.