CtrlK
BlogDocsLog inGet started
Tessl Logo

vendor-management

Use when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim flags, classifying third-party risk across 4 risk vectors, preparing a tier-1 vendor review, or auditing the SaaS portfolio. Forks context so large vendor catalogs (50-500 line items) and SLA logs don't pollute the parent thread. Triggers on "vendor SLA", "vendor scorecard", "third-party risk", "TPRM", "vendor review", "supplier performance", "vendor health check", "renewal review".

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable operational skill with executable scripts, clear five-step workflow, and verified one-level-deep bundle references. The main tightening opportunity is condensing the inline forcing-question coaching section and brief narrative padding to improve token efficiency.

Suggestions

Consider moving the Forcing-question library into its own reference file and linking it, trimming inline token weight while keeping the operational workflow front-and-center.

Add an explicit "verify outputs" checkpoint after each script step (e.g. confirm scorecard.md was written and is non-empty) to push workflow_clarity toward 5.

Tighten the Purpose narrative ("A typical mid-stage company carries 80-200 SaaS subscriptions ...") to one line so it earns its tokens.

DimensionReasoningScore

Conciseness

Mostly efficient — commands, tables, and thresholds instead of explaining what an SLA or vendor is — but the inline Forcing-question library and the "A typical mid-stage company carries ..." narrative add modest padding that could be trimmed.

4 / 5

Actionability

Provides fully executable commands with flags and I/O paths (e.g. `scripts/vendor_scorer.py --input catalog.json --profile <industry> --output scorecard.md`), explicit KEEP/REVIEW/REPLACE thresholds, a runnable `--sample` quick example, and concrete output schemas.

5 / 5

Workflow Clarity

Five clearly sequenced steps where each step's output feeds the next, ending in a synthesis digest; validation is implicit (deterministic scoring) rather than an explicit checkpoint after each step, so it sits just below 5. The workflow is read-only analysis of catalogs, so the destructive/batch validation cap does not apply.

4 / 5

Progressive Disclosure

SKILL.md is an overview with well-signaled one-level-deep references to real, verified files across `assets/`, `scripts/`, and `references/`, each labeled with its purpose — easy to navigate with no nested-reference chains.

5 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description with concrete actions, comprehensive natural trigger terms, and an explicit Use-when clause. The only weak spot is slight overlap risk with adjacent procurement/sourcing skills, which keeps distinctiveness at 4 rather than 5.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — "running a vendor scorecard with industry tuning", "tracking SLA compliance with credit-claim flags", "classifying third-party risk across 4 risk vectors", "preparing a tier-1 vendor review" — giving comprehensive coverage rather than a single action.

5 / 5

Completeness

Explicitly answers both what (reviewing/scoring/auditing vendor relationships) and when, opening with "Use when ..." and closing with concrete "Triggers on ..." phrases.

5 / 5

Trigger Term Quality

Includes natural phrases and an acronym users would actually say — "vendor SLA", "vendor scorecard", "third-party risk", "TPRM", "supplier performance", "vendor health check", "renewal review" — with no common synonym missing.

5 / 5

Distinctiveness Conflict Risk

Clear niche (operational performance review of vendors you already pay, not selection or contract drafting) with mostly-distinct triggers; minor overlap risk with the sibling procurement-optimizer keeps it just below 5.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.