vendor-management

Assess third-party vendor security and maintain risk-tiered vendor inventory.

46|4|Updated Jan 27, 2026
One-click install
npx skills add https://github.com/BagelHole/DevOps-Security-Agent-Skills --skill vendor-management-bagelhole
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-management
Source: https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/compliance/governance/vendor-management
Command: npx skills add https://github.com/BagelHole/DevOps-Security-Agent-Skills --skill vendor-management-bagelhole

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill addresses the challenge of managing risks associated with third-party vendors, ensuring that suppliers meet necessary security and operational standards.

Core Features & Use Cases

  • Vendor Risk Assessment: Implement structured processes to evaluate vendor security posture.
  • Vendor Inventory Management: Maintain a catalog of vendors, classified by risk tier.
  • Use Case: When onboarding a new software provider, use this Skill to guide the assessment process, from initial questionnaire to contract review and ongoing monitoring.

Quick Start

Use the vendor-management skill to assess a new critical vendor.

Frequently Asked Questions about vendor-management

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess third-party vendor security during supplier onboarding?

Assess third-party vendor security by implementing structured processes to evaluate security posture, guiding you from initial questionnaires to contract review and ongoing monitoring.

What is vendor risk tier classification and when do I need it?

Vendor risk tier classification is the process of categorizing suppliers by risk level. You need it to maintain an organized inventory and apply appropriate oversight during onboarding.

How do I maintain a vendor inventory for ongoing oversight?

Maintain a vendor inventory by cataloging suppliers and classifying them by risk tier, enabling structured ongoing monitoring and security reviews for your third-party providers.

Can I use this for critical software provider security reviews?

Yes, you can use this for critical software provider security reviews. It guides the assessment process, applying structured evaluation and contract security terms to manage third-party risk.

What's the best way to manage contract security terms for third-party risk?

Manage contract security terms by integrating them into your structured vendor risk assessment process, ensuring suppliers meet necessary operational and security standards before onboarding completes.

Does vendor management work without dependencies for risk assessment?

Yes, vendor management works without dependencies. It implements structured assessment processes and risk tier classification independently to evaluate third-party security and maintain vendor inventory.