vendor-assessor-agent

Assess vendor privacy and security posture with evidence-backed findings.

Updated Mar 30, 2026
One-click install
npx skills add https://github.com/harkers/forge-email-server --skill vendor-assessor-agent
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-assessor-agent
Source: https://github.com/harkers/forge-email-server/tree/main/skills/vendor-assessor-agent
Command: npx skills add https://github.com/harkers/forge-email-server --skill vendor-assessor-agent

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Assess vendor privacy and security posture, data residency, access locations, subprocessors, and evidence gaps. Use when reviewing vendors, onboarding tools/services, checking transfer risk, or producing an evidenc e-backed recommendation on a third-party provider.

Core Features & Use Cases

  • extract hosting and residency claims
  • assess support/admin access locations
  • identify subprocessors and evidence gaps
  • summarise privacy/security posture
  • prepare recommendation status for manager review

Quick Start

Review the vendor's privacy and security posture and generate an evidence-backed assessment with gaps and recommendations.

Frequently Asked Questions about vendor-assessor-agent

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess vendor privacy and security posture during onboarding?

Assess vendor privacy and security posture by applying evidence-based findings during onboarding, tool reviews, and transfer risk assessments to identify gaps and produce a structured recommendation report.

What is the best way to identify subprocessors and evidence gaps for a vendor?

Identify subprocessors and evidence gaps by extracting hosting, residency, and access location claims from vendor documentation to summarize the overall privacy and security posture.

How do I prepare an evidence-backed recommendation for a third-party provider?

Prepare an evidence-backed recommendation by generating a structured report that includes a summary, findings, open questions, recommendation status, and confidence level for manager review.

Can I use this to check transfer risk and data residency for external tools?

You can check transfer risk and data residency by reviewing vendor claims regarding hosting locations, support access, and subprocessors to highlight security gaps and support onboarding decisions.

What limitations exist when assessing vendor security posture from documentation?

Assessing vendor security posture from documentation may leave open questions if evidence is incomplete, resulting in a lower confidence level and requiring further follow-up before finalizing recommendations.