vendor-risk

Assess a vendor domain's security posture and generate a risk report.

7|2|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/kkmookhey/shasta --skill vendor-risk
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-risk
Source: https://github.com/kkmookhey/shasta/tree/main/.claude/skills/vendor-risk
Command: npx skills add https://github.com/kkmookhey/shasta --skill vendor-risk

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires rainier.

What problem does it solve?

Paste a vendor's domain to get a rapid security risk assessment for third-party partnerships, enabling quick risk-aware decisions.

Core Features & Use Cases

  • Domain-based assessment triggers an automated evaluation from the vendor domain.
  • Returns a risk score, grade, and actionable findings tailored to vendor risk management.
  • Remediation guidance and next-step recommendations to inform vendor selection and monitoring.

Quick Start

Provide a vendor domain (e.g., "stripe.com") to initiate the assessment and view the resulting risk report.

Frequently Asked Questions about vendor-risk

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess a vendor's security risk from their domain?

To assess a vendor's security risk from their domain, provide the domain name to trigger an automated evaluation. The scan returns a risk score, grade, and actionable findings for third-party vendor risk reviews.

Can I generate a third-party vendor risk report for startups and SMBs?

Yes, you can generate a third-party vendor risk report tailored for startups and SMBs by inputting the vendor's domain. The assessment outputs a risk grade and remediation guidance to inform vendor selection.

Do I need a Python environment with Rainier to run a vendor security assessment?

Yes, you need a Python environment with Rainier configured to run the vendor security assessment. You also need access to shasta.config.json for the python_cmd and an optional hibp_api_key.

What is included in a domain-level vendor security risk score?

A domain-level vendor security risk score includes a risk grade, specific security findings, and remediation signals. It provides immediate risk-aware guidance for third-party vendor partnerships.

How fast can I get a third-party vendor security posture evaluation?

You can get a third-party vendor security posture evaluation in 60 seconds. By entering the vendor's domain, the automated scan quickly returns the risk score and findings.