{"id":"3a399e63-8f3f-4773-9711-b32d4867efc5","entityType":"agent","slug":"clawhub-skills-1kalin-afrexai-vendor-risk","name":"afrexai-vendor-risk","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-1kalin-afrexai-vendor-risk","canonicalPath":"/agent/clawhub-skills-1kalin-afrexai-vendor-risk","generatedAt":"2026-10-10T07:55:27.463Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Vendor Risk Assessment Vendor Risk Assessment Score and manage third-party vendor risk across security, financial stability, compliance, operational dependency, and data handling. Built for procurement teams, CISOs, and operations leaders managing 10+ vendors. Usage Run this assessment for each critical vendor. Aggregate scores into a portfolio risk view. Assessment Framework 1. Vendor Risk Scorecard (5 Domains, 0-100 each) **Security Post","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:1kalin:afrexai-vendor-risk","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/1kalin/afrexai-vendor-risk","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/1kalin/afrexai-vendor-risk","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Vendor Risk Assessment Vendor Risk Assessment Score and manage third-party vendor risk across security, financial stability, compliance, operational dependency,"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T05:52:59.828Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T05:52:59.828Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T05:52:59.828Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:1kalin:afrexai-vendor-risk","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-vendor-risk/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-vendor-risk/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-vendor-risk/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-vendor-risk/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-vendor-risk/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-vendor-risk/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T07:55:27.463Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-vendor-risk/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-vendor-risk/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-vendor-risk/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-vendor-risk/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"# Vendor Risk Assessment\n\nScore and manage third-party vendor risk across security, financial stability, compliance, operational dependency, and data handling. Built for procurement teams, CISOs, and operations leaders managing 10+ vendors.\n\n## Usage\nRun this assessment for each critical vendor. Aggregate scores into a portfolio risk view.\n\n## Assessment Framework\n\n### 1. Vendor Risk Scorecard (5 Domains, 0-100 each)\n\n**Security Posture (0-100)**\n- SOC 2 Type II current? (+20)\n- Penetration test within 12 months? (+15)\n- Incident response plan documented? (+15)\n- Data encryption at rest and transit? (+15)\n- MFA enforced for all access? (+10)\n- Security questionnaire completed? (+10)\n- Subprocessor list disclosed? (+15)\n\n**Financial Stability (0-100)**\n- Revenue trend (growing +25, flat +10, declining 0)\n- Funding runway >18 months? (+20)\n- Customer concentration <20%? (+15)\n- Public financials or audited statements? (+15)\n- No material litigation? (+15)\n- Credit rating acceptable? (+10)\n\n**Compliance & Regulatory (0-100)**\n- Industry certifications current? (+20)\n- GDPR/CCPA compliant? (+20)\n- Data processing agreement signed? (+15)\n- Regulatory audit history clean? (+15)\n- Right to audit clause? (+15)\n- Data residency requirements met? (+15)\n\n**Operational Dependency (0-100)**\n- SLA with financial penalties? (+20)\n- Uptime >99.9% trailing 12 months? (+20)\n- Disaster recovery tested annually? (+15)\n- Single point of failure for your business? (-20)\n- Migration plan documented? (+15)\n- API/export capability? (+15)\n- Vendor lock-in risk assessment? (+15)\n\n**Data Handling (0-100)**\n- Data classification documented? (+20)\n- Retention/deletion policies clear? (+20)\n- Breach notification <72 hours? (+20)\n- Data portability guaranteed? (+15)\n- AI/ML training on your data? (opt-out available +15, no opt-out -10)\n- Access logging and audit trail? (+10)\n\n### 2. Risk Tier Classification\n\n| Aggregate Score | Tier | Review Cadence | Action |\n|----------------|------|---------------|--------|\n| 400-500 | Low Risk | Annual | Standard monitoring |\n| 300-399 | Moderate | Semi-annual | Remediation plan required |\n| 200-299 | High Risk | Quarterly | Executive escalation, alternatives identified |\n| 0-199 | Critical | Monthly | Exit plan required within 90 days |\n\n### 3. Portfolio Risk View\n\n```\nTotal vendors: ___\nCritical tier: ___ (target: 0)\nHigh risk: ___ (target: <10%)\nModerate: ___ (target: <30%)\nLow risk: ___ (target: >60%)\n\nTop 3 concentration risks:\n1. [Vendor] — [function] — [% of operations dependent]\n2. [Vendor] — [function] — [% of operations dependent]\n3. [Vendor] — [function] — [% of operations dependent]\n\nAnnual vendor spend: $___\nSpend on high/critical vendors: $___  (___%)\n```\n\n### 4. Cost of Vendor Failure\n\n| Impact Area | Calculation |\n|------------|-------------|\n| Revenue loss | Daily revenue × expected downtime days |\n| Recovery cost | Migration estimate + emergency procurement |\n| Compliance penalty | Regulatory fine range for data breach via vendor |\n| Reputation damage | Customer churn rate × LTV × affected customers |\n| Operational disruption | Staff idle cost × recovery period |\n\n### 5. Quarterly Review Template\n\n- Score changes since last review (flag any >10 point drops)\n- New subprocessors added by vendor\n- SLA performance vs target\n- Security incidents or near-misses\n- Contract renewal timeline and negotiation leverage\n- Alternative vendor benchmarking\n\n### 6. Red Flags (Immediate Action)\n\n- Vendor acquired by competitor\n- Key personnel departures (CISO, CTO)\n- Downtime exceeding SLA 2+ months\n- Regulatory action or investigation\n- Refusal to complete security questionnaire\n- Data breach affecting other customers\n- Sudden pricing changes >20%\n\n## Industry-Specific Vendor Risks\n\n| Industry | Critical Vendor Category | Specific Risk |\n|----------|------------------------|---------------|\n| Healthcare | EHR, billing, telehealth | HIPAA BAA gaps, PHI exposure |\n| Financial Services | Core banking, payments, KYC | PCI DSS, regulatory reporting |\n| Legal | Case management, ediscovery | Privilege breach, client data |\n| SaaS | Infrastructure, auth, payments | Cascading outages, PII |\n| Manufacturing | MES, supply chain, IoT | IP theft, production stoppage |\n| Construction | Project management, safety | Compliance documentation gaps |\n| Ecommerce | Payments, fulfillment, CDN | PCI, availability during peak |\n| Recruitment | ATS, background check, payroll | Candidate PII, bias in AI screening |\n| Real Estate | MLS, transaction mgmt, title | Wire fraud, closing delays |\n| Professional Services | CRM, billing, document mgmt | Client confidentiality breach |\n\n## Get the Full Playbook\n- [AI Revenue Leak Calculator](https://afrexai-cto.github.io/ai-revenue-calculator/) — Quantify your total automation opportunity\n- [Industry Context Packs](https://afrexai-cto.github.io/context-packs/) — $47 each, deep-dive playbooks\n- [Agent Setup Wizard](https://afrexai-cto.github.io/agent-setup/) — Build your AI agent workforce\n","readmeExcerpt":"Vendor Risk Assessment Score and manage third-party vendor risk across security, financial stability, compliance, operational dependency, and data handling. Built for procurement teams, CISOs, and operations leaders managing 10+ vendors. Usage Run this assessment for each critical vendor. Aggregate scores into a portfolio risk view. Assessment Framework 1. Vendor Risk Scorecard (5 Domains, 0-100 each) **Security Post","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"Total vendors: ___\nCritical tier: ___ (target: 0)\nHigh risk: ___ (target: <10%)\nModerate: ___ (target: <30%)\nLow risk: ___ (target: >60%)\n\nTop 3 concentration risks:\n1. [Vendor] — [function] — [% of operations dependent]\n2. [Vendor] — [function] — [% of operations dependent]\n3. [Vendor] — [function] — [% of operations dependent]\n\nAnnual vendor spend: $___\nSpend on high/critical vendors: $___  (___%)"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Vendor Risk Assessment Vendor Risk Assessment Score and manage third-party vendor risk across security, financial stability, compliance, operational dependency, and data handling. Built for procurement teams, CISOs, and operations leaders managing 10+ vendors. Usage Run this assessment for each critical vendor. Aggregate scores into a portfolio risk view. Assessment Framework 1. Vendor Risk Scorecard (5 Domains, 0-100 each) **Security Post","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":373,"uniquenessScore":67,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T07:55:27.463Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}