vendor-risk

Scan a vendor domain and report risk score, grade, signals, and findings.

145|28|Updated Apr 4, 2026
One-click install
npx skills add https://github.com/transilienceai/shasta --skill vendor-risk-transilienceai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-risk
Source: https://github.com/transilienceai/shasta/tree/main/.claude/skills/vendor-risk
Command: npx skills add https://github.com/transilienceai/shasta --skill vendor-risk-transilienceai

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Paste a vendor's domain and get a concise security risk assessment in about a minute, enabling fast onboarding decisions.

Core Features & Use Cases

  • Domain-based risk scan: Evaluates a vendor's security posture from their domain and returns a risk score and grade.
  • Report-ready output: Produces a structured assessment with signals, findings, and recommended mitigations for leadership briefings.
  • Use Case: Before onboarding a new vendor (e.g., stripe.com), generate a quick risk snapshot to inform risk acceptance.

Quick Start

Provide a domain to evaluate and I will run a vendor risk assessment in about 60 seconds.

Frequently Asked Questions about vendor-risk

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a third-party vendor risk assessment by domain?

To run a third-party vendor risk assessment, provide the vendor's domain (e.g., stripe.com). The tool evaluates their security posture and returns a risk score, grade, and findings in about 60 seconds.

What is included in a vendor security risk report?

A vendor security risk report includes a risk score, risk grade, specific signal scores, identified security findings, and recommended mitigations. It produces a downloadable output suitable for leadership briefings.

Do I need an API key to evaluate a vendor's security posture?

Evaluating a vendor's security posture uses the Python interpreter and accepts an optional HIBP API key for checks. You can run a scan without it, but providing the key enhances the assessment signals.

Can I get a quick security risk snapshot before onboarding a new vendor?

Yes, you can get a quick security risk snapshot before onboarding a new vendor. Paste the vendor's domain to generate a structured assessment in a minute, enabling fast risk acceptance and onboarding decisions.

What is the best way to prepare a vendor risk assessment for leadership briefings?

The best way to prepare a vendor risk assessment for leadership briefings is to scan the vendor's domain. This generates a report-ready output with structured signals, findings, and recommended mitigations.