trustlists-vendor-review

trustlists-vendor-review is a cursor rule for coding agents from trustlists/trustlists-plugin. It costs 0 tokens per session (459 once invoked), scanned B, original, Apache-2.0.

A set of review rules for checking third-party vendors before adding them to dependency files such as package.json, requirements.txt, or go.mod. A dependency is outside software that a project relies on.

In plain words
What is it for?
Suggesting trustlists searches when dependencies change, looking up a vendor's public record, and guiding dependency audits with context for regulated industries.
Why use it?
It helps identify supply-chain risks before a new vendor becomes part of the project.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/trustlists/trustlists-plugin/trustlists-vendor-review
Clone the repo
git clone --depth 1 https://github.com/trustlists/trustlists-plugin

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for trustlists-vendor-review

README.md
[![agentmods](https://agentmods.dev/badge/rules/trustlists/trustlists-plugin/trustlists-vendor-review.svg)](https://agentmods.dev/rules/trustlists/trustlists-plugin/trustlists-vendor-review)
Your own site
<a href="https://agentmods.dev/rules/trustlists/trustlists-plugin/trustlists-vendor-review"><img src="https://agentmods.dev/badge/rules/trustlists/trustlists-plugin/trustlists-vendor-review.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 459 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00459
Opus 5 $0.00000 $0.00230
Sonnet 5 $0.00000 $0.00092
Haiku 4.5 $0.00000 $0.00046

Measured 4d ago against content hash a4daa439d62d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

trustlists-vendor-review scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Strips warnings and disclaimersmediumAnti-refusal

Omitting safety caveats hides risk from the user and is a common jailbreak preamble.

- Don't lecture; one short note about supply chain visibility is enough
rules/trustlists-vendor-review.mdc · 36 lines

What it actually says

trustlists vendor review guidance

When editing a dependency manifest (package.json, requirements.txt, go.mod, etc.), the user may be adding a new third-party vendor to their supply chain.

Before recommending a new dependency

  • Search the package or vendor name with trustlists_search, then use trustlists_lookup with the identified domain to check its exact public trustlists record
  • If they do, mention the listed frameworks (SOC 2, ISO 27001, HIPAA documentation, PCI DSS) as directory labels, not as proof
  • If they don't, say the vendor is not in the current public directory and suggest checking the vendor's own security page before committing

When the user asks to "audit" or "review" their dependencies

  • Use the trustlists_audit_dependencies MCP tool against the workspace root
  • Follow the audit-dependencies skill for structuring the report

Compliance-sensitive contexts

If you can tell from the codebase the user works in a regulated industry, weight the analysis accordingly:

  • Healthcare (hipaa, phi, ehr, medical in code/comments) → note whether the record lists HIPAA information, then tell the user to confirm BAA and scope
  • Payments (stripe, pci, card, payment integrations) → note whether the record lists PCI DSS
  • EU customers (gdpr, dpo, EU data residency code) → treat GDPR as a listed privacy signal, not a certification
  • Government / FedRAMP (.gov deploys, fedramp) → note whether the record lists FedRAMP

Don't

  • Don't block the user from adding a dependency just because it lacks a trust center; many open-source libraries are pure code with no SaaS backend
  • Don't fabricate frameworks. Only report what the directory record lists
  • Don't lecture; one short note about supply chain visibility is enough
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 36 lines · 0 tokens per session scan B a4daa439d62d

Subscribe to this mod's changes

trustlists-vendor-review is a cursor rule published in the GitHub repository trustlists/trustlists-plugin (0 stars, last pushed 6d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 459 tokens. A static security scan graded it B with 1 finding (strips warnings and disclaimers). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.