Skip to content
Security
Command

/assess-vendor

Perform vendor security assessment

From plugin
trust-center
367139 skills139 commands1 MCP
Install
$ npx -y skills add GRCEngClub/claude-grc-engineering --agent claude-code

How it fires

How this command gets triggered: by you, by Claude, or both.

  • Fires itselfClaude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/assess-vendor

Context preview

What this command does when you run it.

Perform vendor security assessment

Command definition

assess-vendor.md
description: Perform vendor security assessment

Assess Vendor

Conducts security and risk assessment of third-party vendors.

Arguments

  • `$1` - Vendor name or assessment file (required)
  • `$2` - Assessment type (optional: initial, annual, incident)

Assessment Types

  • **initial** - New vendor onboarding assessment
  • **annual** - Periodic reassessment
  • **incident** - Post-incident or breach assessment

Assessment Areas

  • Security program maturity
  • Data handling practices
  • Compliance certifications (SOC 2, ISO 27001)
  • Business continuity capabilities
  • Incident response readiness
  • Subcontractor management

Output

Generates vendor risk assessment report with:

  • Overall risk rating (Critical/High/Medium/Low)
  • Risk factors by category
  • Required contractual controls
  • Monitoring recommendations
  • Approval recommendation

Example

/grc-tprm:assess-vendor "Acme Cloud Services" initial
Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked
Stats
367
Stars
0
Views
82
Forks
Active
Maintenance
JavaScript
Language
1d ago
Last commit
7mo ago
Created

Repo: GRCEngClub/claude-grc-engineering