Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add modu-ai/moai-cowork --skill collab-vendorgit clone --depth 1 https://github.com/modu-ai/moai-coworkWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/modu-ai/moai-cowork/collab-vendor)<a href="https://agentmods.dev/skills/modu-ai/moai-cowork/collab-vendor"><img src="https://agentmods.dev/badge/skills/modu-ai/moai-cowork/collab-vendor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/modu-ai/moai-cowork/collab-vendor"><img src="https://agentmods.dev/badge/skills/modu-ai/moai-cowork/collab-vendor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00093 | $0.01881 |
| Opus 5 | $0.00046 | $0.00941 |
| Sonnet 5 | $0.00019 | $0.00376 |
| Haiku 4.5 | $0.00009 | $0.00188 |
Grade A, and why
collab-vendor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 124 lines — stays where its author put it; the contents beside it link to each section on GitHub.
벤더 관리자 (collab-vendor)
전략 가이드
| ID | 한국명 | 설명 |
|---|---|---|
| risk-register | 리스크 레지스터 | 위험 식별, 영향 평가, 대응 계획 |
| contract-management | 계약 관리 | 벤더 평가 기준, 계약 체크리스트, 하도급법 준수(대금지급기일 60일·부당 특약 금지·표준하도급계약서), 사업자등록 진위·전자세금계산서 확인 |
| supply-chain | 공급망 | 공급업체 평가 점수카드, 조달 프로세스, 재고 최적화(EOQ·안전재고), 물류 계획, 공급 리스크 완화 |
| import-export | 수출입 무역 | HS코드 분류·통관 문서, 관세/FTA, 무역금융(신용장·환어음), 환위험 관리 등 국경 간 조달·공급 |
→ 참조 파일: references/{id}.md
실행 규칙
- 사용자 요청 수신 → 해당 전략 가이드 판별
references/{id}.md로드 → 전략 가이드에 따라 실행--deepthink또는 복잡 리스크 분석 → sequential-thinking MCP가 설치돼 있으면mcp__sequential-thinking__sequentialthinking를 활용, 없으면ultrathink키워드 기반 심층 추론 또는 일반 단계 추론으로 대체- 결과물 생성 후 사용자 검토 요청
트리거 키워드
벤더, 공급업체, 리스크, 위험 관리, 계약, 평가, 리스크 레지스터
사용 예시
- "소프트웨어 공급업체 3곳을 비교 평가해줘"
- "납품 지연 리스크 레지스터를 작성해줘"
- "IT 벤더 계약 관리 체계를 만들어줘"
- "공급업체 선정 기준표를 설계해줘"
- "주요 벤더 위험 요소와 대응 계획을 정리해줘"
벤더 평가 기준 프레임워크
정량 평가 (60%)
| 평가 항목 | 배점 | 세부 기준 |
|---|---|---|
| 가격 경쟁력 | 20점 | 시장가 대비 견적 수준, 총소유비용(TCO) |
| 납기 준수율 | 15점 | 과거 납기 이행률, SLA 이력 |
| 품질 수준 | 15점 | 불량률, 인증서(ISO/KS), 샘플 품질 |
| 재무 안정성 | 10점 | 신용등급, 부채비율, 매출 규모 |
정성 평가 (40%)
| 평가 항목 | 배점 | 세부 기준 |
|---|---|---|
| 기술 역량 | 15점 | 보유 기술, R&D 투자, 특허 현황 |
| 고객 대응력 | 15점 | 응답 속도, 문제 해결 사례, 담당자 전문성 |
| ESG 준수 | 10점 | 환경 인증, 노무 이슈 이력, 사회적 책임 |
계약 관리 워크플로우
- 계약 체결 전: 벤더 평가 → 조건 협상 → 법무 검토 → 내부 결재
- 계약 체결: 표준계약서 사용 → 전자서명 또는 날인 → 계약 대장 등록
- 계약 이행 중: 납기/품질 모니터링 → 분기별 성과 평가 → 이슈 추적
- 계약 갱신/종료: 성과 기반 갱신 판단 → 종료 통보 기한 준수 → 인수인계 계획
리스크 평가 매트릭스
| 리스크 유형 | 발생 가능성 | 영향도 | 대응 전략 |
|---|---|---|---|
| 납기 지연 | 중 | 상 | 대체 공급업체 사전 확보 |
| 품질 불량 | 중 | 상 | 입고 검수 강화, 패널티 조항 |
| 가격 급등 | 하 | 중 | 장기 계약 또는 가격 고정 조항 |
| 업체 부도/폐업 | 하 | 최상 | 재무 건전성 분기 모니터링 |
| 정보 유출 | 하 | 최상 | NDA 체결, 보안 감사 실시 |
| 법규 위반 | 하 | 상 | ESG 실사, 컴플라이언스 점검 |
독립 실행 워크플로우
전략 가이드 파일 없이도 다음 단계로 실행 가능합니다:
- 요청 유형 파악: 평가/계약/리스크/현황 관리 중 파악
- 대상 벤더 정보 수집: 업체명, 제공 품목/서비스, 계약 규모 확인
- 평가 기준 설계: 업종·규모에 맞는 정량·정성 기준 구성
- 리스크 식별: 공급망 특성에 따른 주요 위험 요소 도출
- 대응 계획 수립: 각 리스크별 예방·완화·대응 방안 작성
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 124 lines · 93 tokens per session scan A 205034fb5c11
collab-vendor is a skill published in the GitHub repository modu-ai/moai-cowork (300 stars, last pushed 8d ago), licensed Apache-2.0. It adds 93 tokens to every session and 1,881 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
vendor-evaluation
Evaluate, select, and contract with vendors and SaaS tools. Use this skill when comparing alternatives, running an RFP, scoring vendors against criteria, negotiating contracts, planning a switch, or assessing a vendor's risk. Triggers on vendor evaluation, RFP, vendor selection, build vs buy, SaaS evaluation, vendor…
67-agency-vendor-brief
Dung khi thue NGUOI NGOAI lam — agency, freelancer, production house, vendor: scope of work, spec deliverable, so vong sua, quy trinh duyet, moc thanh toan, dieu khoan IP va bao mat, bang danh gia vendor sau du an. Kich hoat khi user nhac 'brief agency', 'thue freelancer', 'quan ly vendor', 'scope of work', 'agency…
n8n-prd-generator
Convert discovery call transcripts into concise n8n Automation Blueprints with interactive question flow. USE THIS SKILL WHEN user says "create a blueprint", "generate automation spec", "convert transcript to blueprint", provides discovery call transcripts or client documentation, needs an n8n automation blueprint for…
pipeline-review
Pipeline review and next-action planner. Pulls all prospects from a specified CRM pipeline stage, analyzes every email thread and meeting transcript per prospect, then delivers a concise per-prospect status summary with sales cycle recap, action items (yours and theirs), and contact details, plus a cross-pipeline…
process-interviewer
Relentless process interviewer that extracts a complete, unambiguous plan from the user's head before any building begins. Use when the user wants to plan a complex task, design a process, build a skill, create a workflow, scope a project, or says things like "I want to build", "let's plan", "help me think through"…
standards-expert
Expert-level ISO standards, quality management, compliance, and certification. Use when the user mentions ISO standards, quality management, compliance, or certification, or when the task involves Compliance & Certification, Auditing, or Continuous Improvement.