Vendor Management
Vendor Management is an agent skill (a SKILL.md file) from BagelHole/DevOps-Security-Agent-Skills. Implement vendor risk management programs. It works with Claude Code, Codex, Cursor and OpenCode and has 1,141 GitHub stars across a repository of 2 listed skills. Install it by copying the skill folder into your agent's skills directory.
- Multi-skill repo
- Security
- Maintained
Add this skill
Claude
Claude Code loads skills from ~/.claude/skills/ (all projects) or .claude/skills/ (one project):
git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git
cp -r DevOps-Security-Agent-Skills/compliance/governance/vendor-management ~/.claude/skills/vendor-management # personal, or .claude/skills in a projectIn the Claude apps, zip the vendor-management folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).
ChatGPT / Codex
Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:
git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git
cp -r DevOps-Security-Agent-Skills/compliance/governance/vendor-management .agents/skills/vendor-management # repo; ~/.agents/skills for all projectsStandalone skills also load in the ChatGPT desktop app.
Cursor
Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:
git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git
cp -r DevOps-Security-Agent-Skills/compliance/governance/vendor-management .cursor/skills/vendor-management # project; ~/.cursor/skills for all projectsSource (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)
What this skill does
Implement vendor risk management programs. Assess third-party security and maintain vendor inventory. Use when managing supplier security. Implement a vendor risk management program covering vendor assessment questionnaires, risk scoring, contract tracking, SLA monitoring, and ongoing oversight for compliance with SOC 2, ISO 27001, and regulatory frameworks.
When it triggers
- Use when managing supplier security.
More skills in BagelHole/DevOps-Security-Agent-Skills
2 skills are listed from this repository.
Similar skills
More security skills
Wizard
mattpocock/skills
Generate an interactive bash wizard that walks a human through steps only they can perform.
SecurityShellPostgres Patterns
affaan-m/ECC
PostgreSQL database patterns for query optimization, schema design, indexing, and security.
SecurityJavaScriptPonytail Audit
DietrichGebert/ponytail
Whole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents.
SecurityJavaScriptNext Bundle Optimizer
vercel/next.js
Audit and reduce Next.js browser initial-load work.
OfficialSecurityJavaScriptCloud
browser-use/browser-use
Documentation reference for using Browser Use Cloud — the hosted API and SDK for browser automation.
OfficialSecurityPythonSecurity And Hardening
addyosmani/agent-skills
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a…
SecurityJavaScript
What is the Vendor Management skill?
Vendor Management is an agent skill (a SKILL.md file) from BagelHole/DevOps-Security-Agent-Skills. Implement vendor risk management programs. It works with Claude Code, Codex, Cursor and OpenCode and has 1,141 GitHub stars across a repository of 2 listed skills. Install it by copying the skill folder into your agent's skills directory. Its SKILL.md lives at github.com/BagelHole/DevOps-Security-Agent-Skills/compliance/governance/vendor-management.
How do I install the Vendor Management skill?
Copy the vendor-management folder (the one containing SKILL.md) into ~/.claude/skills/ for Claude Code, .agents/skills/ for Codex or .cursor/skills/ for Cursor. The agent picks it up automatically when a task matches its description.
Is the Vendor Management skill free?
Yes. The repository is open source under the MIT license.
Is Vendor Management maintained?
The repository's most recent commit was on May 22, 2026. Its latest release is v2.0.0. appsgit only lists skills from repositories with a commit in the last six months.