AgentStack
SKILL verified MIT Self-run

Supplier Risk

skill-lawmotion-ai-vibe-lawyering-supplier-risk · by LawMotion-AI

>

No reviews yet
0 installs
6 views
0.0% view→install

Install

$ agentstack add skill-lawmotion-ai-vibe-lawyering-supplier-risk

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Supplier Risk? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

UNIVERSAL RULES (apply to every risk task)

  • NEVER classify a sole-source supplier as low risk based on spend alone --

always assess operational dependency separately from spend volume

  • NEVER accept a vendor risk assessment that contains fabricated financial

data -- label all estimates and flag where primary data is unavailable

  • ALWAYS flag when a vendor's Tier 2 sub-supplier shows distress signals

that could affect Tier 1 supply continuity

  • ALWAYS include specific recommended actions with deadlines in every output --

observations without actions are not acceptable

  • FOR CHINESE SUPPLIERS: ALWAYS use QCC MCP as primary monitoring source --

real-time official data from SAMR, Courts, Tax authorities

  • NEVER rely on Western data sources for Chinese entities --

Companies House, Creditsafe have ZERO coverage

MANDATORY OUTPUT HEADER

TASK:          [e.g. Supplier Risk Brief -- Vendor X]
VENDOR TIER:   [Strategic / Tactical / Commodity / Bottleneck / Unclassified]
CONFIGURATION: [Loaded: supply-chain.local.md / Not configured]
DATA SOURCES:  [QCC MCP Risk Control / QCC MCP Enterprise / Web Search / ERP / Manual input]

QCC MCP RISK MONITORING (Chinese Suppliers)

Real-Time Risk Signal Monitoring (Supply Chain Focus)

QCC MCP provides continuous monitoring capabilities through 4 Server integration. Supply Chain Priority: Focus on signals that directly impact supply continuity.

| Risk Signal | QCC MCP Server | Supply Chain Impact | Alert Level | Response Time | |------------|----------------|-------------------|-------------|---------------| | SUPPLY INTERRUPTION HOT SIGNALS ||||| | Bankruptcy filing | Risk Control | Immediate supply termination | 🔴 CRITICAL | 2 within 12 months, tax arrears 5% since contract

  • GREEN LOW: Stable environment; no material currency exposure
DIMENSION 5: TIER 2 / SUB-SUPPLIER RISK

Monitor for:

  • Financial distress at critical Tier 2 suppliers (via QCC MCP if Chinese)
  • Tier 2 supplier capacity constraints affecting Tier 1 output
  • Single-geography concentration at Tier 2 level
  • Tier 2 supplier relationship with Tier 1 deteriorating

Requirement: Tier 2 mapping must exist for all Tier 1 Strategic vendors. If mapping does not exist: flag as UNASSESSED RISK; request Tier 2 data from Tier 1 supplier as priority action.

Risk Rating Change Rules

ESCALATE overall rating if ANY dimension reaches RED ELEVATE to MEDIUM-HIGH if TWO dimensions reach AMBER simultaneously REDUCE rating only after confirmed remediation (not just vendor assurance)

QCC MCP RISK BRIEF OUTPUT FORMAT

SUPPLIER RISK BRIEF: [Vendor Name]
Assessment date: [Date] | Next scheduled review: [Date]
================================================================
OVERALL RISK RATING: [GREEN LOW / AMBER MEDIUM / AMBER MEDIUM-HIGH / RED HIGH / RED CRITICAL]
Change since last review: [No change / Elevated / Reduced]

-- QCC MCP RISK SIGNALS (Last 90 Days) --
🔴 NEW CRITICAL SIGNALS:
  [Date] [Signal Type] [Description] [Source: QCC MCP]

🟡 NEW MODERATE SIGNALS:
  [Date] [Signal Type] [Description] [Source: QCC MCP]

FINANCIAL RISK:   [GREEN / AMBER / RED] [Rating]
Property Restrictions:
  - Equity Freeze:    [Active since / None]
  - Equity Pledge:    [Count in last 12 months]
  - Chattel Mortgage: [Count/Amount]
Tax Status:
  - Tax Arrears:      [Amount/Type/Date or None]
  - Abnormal Status:  [Yes - date/office / No]
Bankruptcy:
  - Proceedings:      [Yes - type/status / No]
[QCC MCP Trace: Risk Control Server, Enterprise Base Server]

OPERATIONAL RISK: [GREEN / AMBER / RED] [Rating]
[OTD trend, quality trend, lead time data from ERP]
QCC MCP Signals:
  - Abnormal Operation: [Status/Date or Clear]
  - Administrative Penalties: [Count in last 12m]
  - Environmental Penalties: [Count in last 12m]
[QCC MCP Trace: Enterprise Base Server]

COMPLIANCE RISK:  [GREEN / AMBER / RED] [Rating]
Certification status: [Details]
QCC MCP Compliance:
  - Serious Violation: [Yes/No]
  - Recent Penalties: [List]
[QCC MCP Trace: Risk Control Server]

GEOPOLITICAL RISK:[GREEN / AMBER / RED] [Rating]
[Country, currency, route findings]

TIER 2 RISK:      [GREEN / AMBER / RED / NOT MAPPED]
[Sub-supplier findings or mapping gap flag]

RECOMMENDED ACTIONS -- RANKED BY URGENCY
RED [IMMEDIATE -- this week]: [Action] -- [Owner]
AMBER [SHORT-TERM -- 30 days]: [Action] -- [Owner]
GREEN [PLANNED -- 90 days]:    [Action] -- [Owner]

QCC MCP MONITORING CONFIG
Refresh Frequency: Daily for Strategic/Bottleneck; Weekly for Tactical/Commodity
Data Sources: 企查查MCP-风控大脑, 企查查MCP-企业基座
Last QCC MCP Sync: [Timestamp]
Next Auto-Refresh: [Date]
================================================================

Executive Brief Format (for CPO weekly summary)

VENDOR RISK SUMMARY -- Week of [Date]
---------------------------------------------------------
[Vendor]    [Overall]  [Change]  [Key QCC Signal]   [Action required]
[Vendor]    [Overall]  [Change]  [Key QCC Signal]   [Action required]
---------------------------------------------------------
New alerts this week:   [N]
Escalations to CPO:     [N]
Contingency plans live: [N]
QCC MCP New Signals:    [N judicial / N operational / N financial]

HOT SIGNAL PROTOCOL

HOT SIGNALS override the review schedule

When QCC MCP detects any of the following, trigger immediate assessment:

| HOT Signal | QCC MCP Source | Action | |-----------|----------------|--------| | New equity freeze | Risk Control | Immediate escalation to CPO | | Bankruptcy filing | Risk Control | Activate contingency plan | | Abnormal tax status | Risk Control | Suspend new POs, assess exposure | | Abnormal operation added | Enterprise Base | Request immediate explanation | | New dishonest被执行人 | Risk Control | Legal review required | | Limit high consumption | Risk Control | Assess payment risk |

NEVER DO THESE

  • NEVER rate a vendor as LOW risk in any dimension without verified data --

absence of negative data does not equal low risk; label as UNASSESSED if no data

  • NEVER rely on vendor self-assessment alone for financial risk --

always cross-reference with QCC MCP independent sources

  • NEVER downgrade a risk rating based on vendor assurance alone --

require evidence (updated accounts, certification renewal, remediation proof)

  • NEVER omit the Tier 2 risk section -- mark as NOT MAPPED if absent, not LOW RISK
  • NEVER wait for the scheduled review to act on a HOT signal --

HOT signals override the review schedule

  • NEVER use Companies House/Creditsafe for Chinese suppliers --

QCC MCP is the authoritative source for Chinese entities

  • NEVER fabricate QCC MCP data -- if MCP unavailable,

flag as "QCC MCP: UNCONFIGURED - manual monitoring required"

ALL OUTPUTS REQUIRE REVIEW BY A QUALIFIED PROFESSIONAL BEFORE USE IN BUSINESS DECISIONS.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.