Agent Skillsmohitagw15856/pm-claude-skills › the-procurement-gauntlet

the-procurement-gauntlet

GitHub

模拟企业采购与安全审查流程,生成包含安全、法律、合规及供应商风险的评估备忘录。通过风险分级和停滞预测,提供准备清单,帮助产品在正式交易前识别并弥补漏洞,加速签约进程。

exports/openclaw/the-procurement-gauntlet/SKILL.md mohitagw15856/pm-claude-skills

Trigger Scenarios

准备企业采购审查 模拟安全审核 了解企业交易停滞原因 进行供应商评估准备

Install

npx skills add mohitagw15856/pm-claude-skills --skill the-procurement-gauntlet -g -y
More Options

Non-standard path

npx skills add https://github.com/mohitagw15856/pm-claude-skills/tree/main/exports/openclaw/the-procurement-gauntlet -g -y

Use without installing

npx skills use mohitagw15856/pm-claude-skills@the-procurement-gauntlet

指定 Agent (Claude Code)

npx skills add mohitagw15856/pm-claude-skills --skill the-procurement-gauntlet -a claude-code -g -y

安装 repo 全部 skill

npx skills add mohitagw15856/pm-claude-skills --all -g -y

预览 repo 内 skill

npx skills add mohitagw15856/pm-claude-skills --list

SKILL.md

Frontmatter
{
    "name": "the-procurement-gauntlet",
    "homepage": "https:\/\/mohitagw15856.github.io\/pm-claude-skills\/skill\/the-procurement-gauntlet.html",
    "metadata": {
        "openclaw": {
            "emoji": "🧠"
        }
    },
    "description": "Simulate enterprise procurement and security review of your product before your first big deal meets it for real — the questionnaire, the gaps, the deal-slowing findings. Use when asked to prep for enterprise procurement, simulate a security review, why do enterprise deals stall, or get ready for vendor assessment. Produces the reviewer's findings memo (security, legal, compliance, vendor-risk), the stall-risk ranking, and a debrief with the artifacts to prepare before the real gauntlet."
}

The Procurement Gauntlet Skill

The first enterprise deal doesn't die in the demo — it dies eleven weeks later in a vendor-risk spreadsheet. This skill runs the gauntlet early: security questionnaire, legal redlines, compliance checks, and procurement's favorite question ("what happens to our data when you die?") — producing the findings memo their team would write, so yours can prepare the artifacts before the clock is running on a real deal.

What This Skill Produces

  • The findings memo — security / legal / compliance / vendor-viability, graded as an enterprise reviewer grades
  • The stall-risk ranking — which findings add weeks, which add clauses, which kill
  • The debrief — the artifact checklist to build now, ordered by deals-unblocked-per-effort

Required Inputs

Ask for these if not provided:

  • The product's honest posture: hosting/architecture, auth (SSO?), data handled (PII? whose?), certifications held or in progress, backup/DR reality, team size
  • The paper on hand — security page, DPA template, terms, subprocessor list, insurance
  • The target buyer — regulated industry? company size? geography (data-residency expectations)?
  • The skeletons — the honest gaps; the simulation is only as useful as this disclosure

Framework: The Four Desks

  1. Security desk: SSO/SAML (its absence is the #1 mid-market deal-stall), encryption at rest/in transit, access controls and audit logs, pen-test recency, incident-response plan, subprocessor inventory. Certifications are graded as they actually work: attestation reports open doors; "in progress" opens conversations with a date attached.
  2. Legal desk: liability caps vs their paper, data-processing terms, breach-notification windows (they'll want faster than yours says), IP/indemnity, and the audit-rights clause your template doesn't have.
  3. Compliance desk: data residency, retention/deletion on request, regulated-data handling if applicable — answered by the buyer's industry, not in the abstract.
  4. Vendor-risk desk: the mortality questions — company viability, escrow/continuity, "what happens to our data if you shut down," insurance certificates, references at similar scale. Grading: ✅ pass · 🟡 pass-with-clause (adds negotiation) · 🟠 stall (adds weeks + an artifact) · 🔴 gate (deal waits until fixed).

Output Format

Vendor Assessment: [product] — simulated for [buyer type]

Simulation — a plausible enterprise review, not a prediction or legal advice.

Findings

# Desk Finding Grade What it does to the deal

The Stall Forecast

[Realistic procurement timeline for this posture: n–n weeks, driven by findings #…]

Debrief — out of character

Artifact to build Unblocks Effort Order
[Typically: SSO, the security one-pager, subprocessor list, DPA template, IR plan summary, continuity statement]
The honest positioning line for sales: [how to state current posture without overclaiming — overclaiming discovered in review kills deals harder than gaps do]

Quality Checks

  • Every finding traces to the disclosed posture — gaps disclosed get graded, gaps invented don't exist
  • Grades carry deal consequences, not abstract severity
  • The artifact list is ordered by deals-unblocked-per-effort
  • Certifications-in-progress are treated as dated conversations, not passes or failures
  • The positioning line lets sales tell the truth survivably

Anti-Patterns

  • Do not grade against a Fortune-50 bar for an SMB product — calibrate to the stated buyer
  • Do not treat certification as binary salvation — many deals close on posture + roadmap + honesty
  • Do not let the simulation recommend overclaiming — review teams verify, and discovered overclaims are 🔴
  • Do not omit the mortality questions — vendor-viability stalls surprise founders most
  • Do not stay in character in the debrief

Version History

  • 54fad50 Current 2026-07-19 12:36

Same Skill Collection

exports/openclaw/360-feedback-template/SKILL.md
exports/openclaw/401k-plan-decoder/SKILL.md
exports/openclaw/ab-test-planner/SKILL.md
exports/openclaw/ab-test-readout/SKILL.md
exports/openclaw/accessibility-audit/SKILL.md
exports/openclaw/account-plan/SKILL.md
exports/openclaw/acquirer-red-team/SKILL.md
exports/openclaw/ad-copy/SKILL.md
exports/openclaw/aeo-optimizer/SKILL.md
exports/openclaw/agenda-or-cancel/SKILL.md
exports/openclaw/agent-design-review/SKILL.md
exports/openclaw/agent-observability-spec/SKILL.md
exports/openclaw/agent-spec/SKILL.md
exports/openclaw/ai-ethics-review/SKILL.md
exports/openclaw/ai-eval-plan/SKILL.md
exports/openclaw/ai-feature-prd/SKILL.md
exports/openclaw/ai-product-canvas/SKILL.md
exports/openclaw/air-quality/SKILL.md
exports/openclaw/altitude-shifter/SKILL.md
exports/openclaw/ambiguity-resolver/SKILL.md
exports/openclaw/analyst-relations-brief/SKILL.md
exports/openclaw/announcement-card/SKILL.md
exports/openclaw/api-docs-writer/SKILL.md
exports/openclaw/api-test-plan/SKILL.md
exports/openclaw/api-versioning-strategy/SKILL.md
exports/openclaw/apology-letter/SKILL.md
exports/openclaw/architecture-decision-record/SKILL.md
exports/openclaw/architecture-diagram/SKILL.md
exports/openclaw/archive-strategy/SKILL.md
exports/openclaw/assumption-bounty/SKILL.md
exports/openclaw/assumption-mapper/SKILL.md
exports/openclaw/async-update-format/SKILL.md
exports/openclaw/auto-repair-estimate-decoder/SKILL.md
exports/openclaw/autopilot-charter/SKILL.md
exports/openclaw/benefits-decoder/SKILL.md
exports/openclaw/bid-tender-review/SKILL.md
exports/openclaw/board-deck-narrative/SKILL.md
exports/openclaw/board-minutes/SKILL.md
exports/openclaw/board-pre-read/SKILL.md
exports/openclaw/bom-cost-review/SKILL.md
exports/openclaw/bookkeeping-categorization/SKILL.md
exports/openclaw/boolean-search-builder/SKILL.md
exports/openclaw/brag-doc/SKILL.md
exports/openclaw/brainstorming/SKILL.md
exports/openclaw/brief-builder/SKILL.md
exports/openclaw/briefing-note/SKILL.md
exports/openclaw/budget-builder/SKILL.md
exports/openclaw/budget-variance-analysis/SKILL.md
exports/openclaw/bug-diagnosis/SKILL.md
exports/openclaw/bug-report/SKILL.md

Metadata

Files
0
Version
471c606
Hash
5e7c48a3
Indexed
2026-07-19 12:36

- 위키
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-07-30 19:25
浙ICP备14020137号-1 $방문자$