procurement-security-review
Installation
SKILL.md
Procurement Security Review
Use this skill to convert a enterprise procurement security, vendor-risk evidence, questionnaires, DPAs, policy proof, and sales/legal/security handoff question into a concrete artifact with owners, gates, metrics, and recovery paths.
Workflow
- Identify buyer type, deal stage, requested evidence, data sensitivity, contract terms, compliance status, gaps, owner teams, and response deadline.
- Read
references/procurement-security-patterns.md. - Classify request as questionnaire, evidence packet, DPA, subprocessor review, insurance, compliance report, pen test summary, AI/data-use review, or redline.
- Define evidence source, approved answer, gap wording, exception path, access control, reviewer, expiry, and sales/legal/security handoff.
- Produce procurement review plan, state machine, decision table, event schema, evidence checklist, and gap-escalation policy.
When not to use
- Do not use for generic advice the base model already handles without this skill's specific artifact contract.