Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add LawMotion-AI/Vibe-Lawyering --skill vendor-assessmentgit clone --depth 1 https://github.com/LawMotion-AI/Vibe-LawyeringWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/lawmotion-ai/vibe-lawyering/vendor-assessment)<a href="https://agentmods.dev/skills/lawmotion-ai/vibe-lawyering/vendor-assessment"><img src="https://agentmods.dev/badge/skills/lawmotion-ai/vibe-lawyering/vendor-assessment/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/lawmotion-ai/vibe-lawyering/vendor-assessment"><img src="https://agentmods.dev/badge/skills/lawmotion-ai/vibe-lawyering/vendor-assessment.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00190 | $0.04293 |
| Opus 5 | $0.00095 | $0.02146 |
| Sonnet 5 | $0.00038 | $0.00859 |
| Haiku 4.5 | $0.00019 | $0.00429 |
Grade A, and why
vendor-assessment scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 416 lines — stays where its author put it; the contents beside it link to each section on GitHub.
UNIVERSAL RULES (apply to every vendor task)
- NEVER classify a sole-source supplier as low risk based on spend alone -- always assess operational dependency separately from spend volume
- NEVER accept a vendor risk assessment that contains fabricated financial data -- label all estimates and flag where primary data is unavailable
- NEVER recommend a vendor exit without a qualified alternative identified or an explicit "no alternative -- managed risk" decision documented
- ALWAYS include specific recommended actions with deadlines in every output -- observations without actions are not acceptable
- FOR CHINESE SUPPLIERS: ALWAYS use QCC MCP as primary data source -- Companies House and Creditsafe have NO coverage for Chinese entities
- NEVER fabricate Chinese enterprise data -- if QCC MCP unavailable, explicitly flag as "financial visibility: NONE" and recommend manual verification
MANDATORY OUTPUT HEADER
Every output must begin with:
TASK: [e.g. Vendor Assessment -- Acme Corp]
VENDOR TIER: [Strategic / Tactical / Commodity / Bottleneck / Unclassified]
CONFIGURATION: [Loaded: supply-chain.local.md / Not configured]
DATA SOURCES: [QCC MCP / ERP / Web / Manual input]
QCC MCP INTEGRATION (Chinese Suppliers)
When to Activate QCC MCP
ALWAYS activate for Chinese suppliers (vendors with):
- Chinese company name (e.g., "华为技术有限公司", "阿里巴巴集团")
- Unified Social Credit Code (统一社会信用代码)
- Registered in mainland China
QCC MCP provides official data from:
- National Enterprise Credit Information Publicity System (国家企业信用信息公示系统)
- China Judgments Online (中国裁判文书网)
- China Execution Information (中国执行信息公开网)
- State Taxation Administration (国家税务总局)
- SAMR (国家市场监督管理总局)
18-Risk Categories for Supply Chain (供应链专用)
设计原则: 供应链评估聚焦"供应连续性风险",与法务合同审核的关注点不同
| Risk Category | QCC MCP Server | Supply Chain Focus | Priority |
|---|---|---|---|
| SUPPLY INTERRUPTION RISKS | |||
| Judicial Execution | Risk Control | 直接影响生产资金链 | 🔴 CRITICAL |
| - Dishonest (失信) | 信用崩溃,履约能力丧失 | ||
| - Executed person (被执行人) | 现金流危机,影响原材料采购 | ||
| - Limit high consumption (限高) | 法人受限,商务活动受阻 | ||
| - Final case (终本案件) | 历史债务累积,财务恶化 | ||
| - Judicial auction (司法拍卖) | 核心资产被拍卖,产能受损 | ||
| Bankruptcy Liquidation | Risk Control | 供应关系终止 | 🔴 CRITICAL |
| - Bankruptcy reorganization (破产重整) | 需立即切换供应商 | ||
| OPERATIONAL CONTINUITY RISKS | |||
| Operational Abnormal | Enterprise Base | 经营稳定性 | 🔴 HIGH |
| - Abnormal operation (经营异常) | 工商监管介入,经营不稳定 | ||
| - Serious violation (严重违法) | 可能被吊销执照,供应中断 | ||
| - Cancellation filing (注销备案) | 主动终止经营,供应中断 | ||
| Environmental Penalty | Risk Control | 可能导致停产 | 🟡 MEDIUM |
| - Environmental penalty (环保处罚) | 责令停产整改,影响交付 | ||
| FINANCIAL HEALTH RISKS | |||
| Property Restricted | Enterprise Base | 财务稳定性指标 | 🟡 MEDIUM |
| - Equity freeze (股权冻结) | 股东纠纷,控制权不稳定 | ||
| - Equity pledge (股权出质) | 融资压力,流动性风险 | ||
| - Chattel mortgage (动产抵押) | 设备抵押,影响产能扩张 | ||
| Tax Violation | Risk Control | 现金流与合规 | 🟡 MEDIUM |
| - Tax arrears (欠税公告) | 现金流危机,可能拖欠货款 | ||
| - Abnormal tax (非正常户) | 税务合规严重问题 | ||
| Administrative Penalty | Risk Control | 行业合规 | 🔵 LOW |
| - Administrative penalty (行政处罚) | 一般合规问题 |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 416 lines · 190 tokens per session scan A d889b127fa09
vendor-assessment is a skill published in the GitHub repository LawMotion-AI/Vibe-Lawyering (20 stars, last pushed 4mo ago), licensed MIT. It adds 190 tokens to every session and 4,293 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…