CtrlK
BlogDocsLog inGet started
Tessl Logo

vendor-management

Use when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim flags, classifying third-party risk across 4 risk vectors, preparing a tier-1 vendor review, or auditing the SaaS portfolio. Forks context so large vendor catalogs (50-500 line items) and SLA logs don't pollute the parent thread. Triggers on "vendor SLA", "vendor scorecard", "third-party risk", "TPRM", "vendor review", "supplier performance", "vendor health check", "renewal review".

65

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.gemini/skills/vendor-management/SKILL.md

The canonical home for this skill is vendor-management in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-sequenced and actionable with concrete commands and schemas, but it suffers from dead bundle references (no scripts/references/assets exist), duplicated boundary sections, and an inline forcing-question library that should be externalized.

Suggestions

Bundle the referenced files: add scripts/vendor_scorer.py, scripts/sla_compliance_tracker.py, scripts/vendor_risk_classifier.py, assets/vendor_catalog_template.md, and the three references/*.md so the documented commands actually run.

Merge 'When NOT to use' and 'Distinct from' into a single boundary section to remove the duplicated sibling-skill list and recover tokens.

Move the forcing-question library (the 6 Q&A with recommended answers and canon citations) into a references file and keep only a one-line pointer in SKILL.md.

DimensionReasoningScore

Conciseness

The body is mostly information-dense and assumes competence, but the 'When NOT to use' and 'Distinct from' sections repeat the same sibling-skill boundaries, and the full forcing-question library (6 Q&A with canon citations) is inlined where it could be deferred to a reference file.

3 / 5

Actionability

Concrete, copy-paste-ready CLI commands with documented flags (--input, --output, --sample, --profile), specified input schemas, and explicit output thresholds (KEEP ≥75, REVIEW 50-74, REPLACE <50); the gap is that the referenced scripts are not actually bundled.

4 / 5

Workflow Clarity

A clearly sequenced 5-step workflow (Intake → Score → SLA → Risk → Synthesize) with per-step inputs, commands, and outputs, plus a pre-flight gating discipline ('Lock 1-3 before opening 4-6'); minor gap is the lack of explicit output validation or error-recovery feedback loops for this batch operation.

4 / 5

Progressive Disclosure

Structure is conceptually sound (References list, Scripts table, one-level-deep signaling), but every referenced bundle file — assets/vendor_catalog_template.md, three scripts/*.py, three references/*.md — is absent, so navigation is broken, and the inlined forcing-question library is content that should live in a separate file.

3 / 5

Total

14

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that explicitly states capabilities, natural trigger phrases, and use conditions, with only a minor gap around boundary distinction from neighboring skills.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'running a vendor scorecard with industry tuning', 'tracking SLA compliance with credit-claim flags', 'classifying third-party risk across 4 risk vectors', 'preparing a tier-1 vendor review' — giving comprehensive coverage rather than vague language.

5 / 5

Completeness

Opens with an explicit 'Use when...' clause stating what the skill does, then adds a 'Triggers on...' clause with concrete trigger phrases, clearly answering both what and when.

5 / 5

Trigger Term Quality

Explicit 'Triggers on' clause enumerates natural phrases a user would say — 'vendor SLA', 'vendor scorecard', 'third-party risk', 'TPRM', 'vendor review', 'supplier performance', 'vendor health check', 'renewal review' — covering synonyms and the TPRM acronym.

5 / 5

Distinctiveness Conflict Risk

The niche (third-party vendor performance / TPRM / SLA) and its triggers are clearly distinct, but the description omits the boundary against closely related sibling skills (procurement-optimizer, contract/proposal writer, general-counsel-advisor) that the body spells out, leaving minor overlap risk.

4 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

referenced_paths_exist

Referenced path issues: 12 missing

Warning

Total

14

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.