← Back to marketplace
Procurement & ops

Vendor vetting one-pager

Compiles a 1-page brief on a prospective vendor: pricing, security posture, customer references, red flags, and a recommendation.

by Priya N. · v0.1.2 · 144 installs

name: vendor-vetting-1pager
description: This skill should be used when the user asks to "vet this vendor", "do due diligence on", or wants a one-page brief on a prospective vendor with pricing, security posture, customer references, red flags, and a recommendation.
version: 0.1.2

Vendor Vetting One-Pager

Purpose

Produce a one-page brief on a prospective vendor that an operator can hand to a stakeholder for a go/no-go decision.

Workflow

  1. Take vendor name and intended use case as inputs.
  2. Pull pricing tier and contract minimums from public sources.
  3. Summarize security posture (SOC 2, ISO 27001, sub-processors).
  4. List 3 customer references with industry and company size.
  5. Identify red flags (no security cert, no DPA, weak SLA).
  6. End with a one-sentence recommendation: green-light, conditional, or pass.

Output template

Vendor: ...
Use case: ...
Pricing: ...
Security: ...
References: ...
Red flags: ...
Recommendation: ...

Failure modes

  • Do not infer pricing if the vendor only publishes "Contact us"; mark as TBD.
  • Do not include reference logos that the vendor has not publicly confirmed.
  • Always include a recommendation — never leave it blank.

References

  • See references/security-checklist.md for the in-depth security posture rubric.