vet-a-vendor

Evaluate vendors with rubric-based commercial fit scoring or compliance research reports.

2|Updated May 8, 2026
One-click install
npx skills add https://github.com/akiotanaka847/qaio-desktop --skill vet-a-vendor
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vet-a-vendor
Source: https://github.com/akiotanaka847/qaio-desktop/tree/main/store/agents/operations/.agents/skills/vet-a-vendor
Command: npx skills add https://github.com/akiotanaka847/qaio-desktop --skill vet-a-vendor

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Vetting a vendor before you sign can be slow and risky when evidence is scattered across marketing pages, trust claims, and news—this skill gathers and evaluates that evidence so you can make a safer, faster decision.

Core Features & Use Cases

  • Commercial fit scoring (1-10 with risk tier): Scores a supplier against your rubric, flags risk-signals, and produces a clear recommendation and first-call questions.
  • Compliance research (framework verification): Triangulates claimed security/compliance frameworks with independent verification, identifies security leadership, and surfaces public incidents from the last 3 years.
  • Evidence-backed outputs: Produces either an evaluations/{supplier-slug}.md or compliance-reports/{company-slug}.md report with URLs for every claim and explicit insufficiency markers when evidence is missing.

Quick Start

Run the vet-a-vendor skill in compliance mode on Vercel to verify its claimed security frameworks and uncover any relevant incidents from the last three years.

Frequently Asked Questions about vet-a-vendor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run vendor due diligence with cited evidence?

Vendor due diligence with cited evidence is performed by scoring a supplier against your rubric or generating a compliance research report. The process outputs evidence-cited markdown files with URLs for every claim and explicit insufficiency markers when evidence is missing.

How does compliance research verify a vendor's security frameworks?

Compliance research verifies security frameworks by triangulating claimed security or compliance frameworks with independent verification. It identifies security leadership and surfaces public incidents from the last three years.

What do I need to provide to run a vendor risk assessment?

To run a vendor risk assessment you need to provide the operations context and have web research connectivity. This allows the skill to gather evidence from public sources, marketing pages, and news to evaluate commercial fit and compliance.

Can I use this for risk-sensitive checks on data processors and infrastructure?

Yes, you can use this for risk-sensitive checks on data processors, infrastructure, and regulated services. It applies to vendor selection, supplier scoring against internal criteria, and verifying compliance for these sensitive categories.

What format are vendor compliance reports generated in?

Vendor compliance reports are generated as evidence-cited markdown files. They are output to either an evaluations or compliance-reports directory with a supplier slug, containing URLs for every claim and explicit insufficiency markers for missing evidence.