Skills
Vendor Due Diligence
A practice-area skill: it carries legal knowledge — a doctrine, a regime, a review standard — and applies it to your material.
What this skill does
Framework for assessing IT service providers, technology vendors, and third-party partners. Creates structured risk assessments across financial, operational, compliance, security, and reputational dimensions with regulatory checklists (GDPR, DORA, NIS2, SOX). Use when: (1) Evaluating new vendors or technology providers, (2) Conducting third-party risk assessments for procurement, (3) Performing c
- Due Diligence
- Risk Assessment
- Vendor
- Compliance
Free, and published by its author - not by HAQQ. The link leaves this site.
Where it runs, and how to install it
Agent Skills are a format, not a product feature: a folder with a SKILL.md and whatever files it needs. Nothing inside one is model-specific.
- Claude
- Drop the skill folder into ~/.claude/skills/, or upload it in Settings → Capabilities. Claude loads it when the description matches what you asked for.
- Claude Code
- Same folder, per-project instead: .claude/skills/ inside the repository, so the skill travels with the work rather than with the machine.
- Any agent that reads SKILL.md
- A skill is a folder with a SKILL.md and whatever files it needs. Nothing in the format is model-specific, so a runtime that reads the file reads the skill.
More from Patrick Munro
- Tech Contract NegotiatorGuide to negotiating technology services agreements, professional services contracts, and commercial B2B transactions. Provides three-position frameworks (provider-favorable, balanced, client-favorable), deal-size tactics, objection handling templates, and concession roadmaps. Use when: (1) Developing negotiation strategies for SaaS, cloud, or managed services agreements, (2) Preparing position pa
- Legal AI SimulatorFramework for demonstrating AI capabilities in legal contexts. Provides detailed personas across tenant law, business contracts, startup disputes, employment claims, and consumer protection with progressive complexity scenarios. Use when: (1) Demonstrating AI-powered legal triage or intake systems, (2) Showcasing responsible AI-assisted client interactions, (3) Training staff on appropriate AI use
- Red Team VerifierAdversarial verification for AI-generated legal content with systematic fact-checking, source validation, and quality control. Use when verifying legal documents, fact-checking regulatory content, performing red team review, or quality assurance before distribution to clients or stakeholders.
- Legal Test BuilderBuilds a high-fidelity interactive legal assessment as a single self-contained HTML artifact. Output includes a live countdown timer, contract review tasks with hover-annotated problem clauses, candidate answer textareas, model answers hidden behind reveal blocks, scenario-based legal memo tasks, strategy and function-building questions, and a pre-submission checklist that encodes the marking criteria. Use when the user needs to (1) assess a legal candidate with a realistic timed exercise, (2) train or onboard junior lawyers using problem sets rather than doctrine, (3) help a candidate prepare for a real take-home assessment they are facing, (4) build educational materials for law students, in-house teams, or compliance training, or (5) produce scenario-based training modules on specific legal topics. Triggers on "legal test", "take-home", "mock exam", "contract redline exercise", "candidate assessment", "legal training exercise", "practice test", or similar phrasing even when informal.
- Cross Regulatory Impact AnalyzerAnalyzes how multiple regulations interact for a specific product, service, or business model. Identifies where obligations overlap, reinforce, complement, duplicate, or conflict; builds a priority matrix; produces an integrated compliance timeline; and estimates the total compliance burden. Use when (1) scoping a new product or service against the full regulatory landscape before launch, (2) conducting M&A due diligence on a target's multi-regulation exposure, (3) building a strategic compliance roadmap where single-regulation analyses miss the interactions, (4) advising on complex situations where regulations touch the same conduct from different angles, or (5) estimating budget and resourcing for multi-regulation compliance. Primary coverage of EU digital regulation (GDPR, Data Act, AI Act, CRA, NIS2, DORA, DMA, DSA, ePrivacy) and national implementations; the framework extends to any jurisdiction where overlapping regulatory regimes apply to the same activity.
- Regulatory Deal Card GeneratorGenerates standalone interactive HTML "deal cards" that translate complex regulations into negotiation-ready reference tools, systematically distinguishing mandatory obligations from negotiable implementation choices. Use when the user needs an interactive regulatory guide for (1) contract negotiation support, (2) client education or internal training, (3) regulatory briefings for commercial stakeholders, or (4) structured comparison between required and flexible compliance paths. Primary focus on EU digital regulation (Data Act, AI Act, CRA, DORA, NIS2, GDPR) but the structural pattern transfers to any regulation where separating hard obligations from implementation choice is the point. Supports bilingual output where the jurisdiction calls for it.
Skills that do related work
- AI Governance ReviewerConduct AI governance, legal-risk, privacy, compliance, procurement, or vendor-risk reviews of internal AI use cases, AI product features, LLM workflows, or thi
- BACEN Compliance SentinelComprehensive guidance on compliance with Central Bank of Brazil regulations: CMN Resolution No. 4,893/2021 (Cybersecurity Policy), BCB Resolution No. 85/2021 (
- Contract Risk AnalyzerAnalyses contracts for risk across five critical clauses (Limitation of Liability, Indemnities, IP Ownership, Data Protection, Termination). Built for founders
- DPDPA & GDPR Compliance ReviewPerforms structured compliance review, clause redlining, and drafting suggestions for legal documents (privacy policies, data processing agreements, vendor and
- EU AI Act System ClassifierClassify an AI system under the EU AI Act (Regulation (EU) 2024/1689) and map the compliance obligations that follow. Walks Art. 2 scope exclusions, Art. 3(1) A
- EU Data Act Compliance AssessmentAssess compliance obligations under the EU Data Act (Regulation (EU) 2023/2854) for connected products, IoT devices, data sharing, cloud switching, B2B fairness