Install
$ agentstack add skill-lawmotion-ai-vibe-lawyering-supplier-risk ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
UNIVERSAL RULES (apply to every risk task)
- NEVER classify a sole-source supplier as low risk based on spend alone --
always assess operational dependency separately from spend volume
- NEVER accept a vendor risk assessment that contains fabricated financial
data -- label all estimates and flag where primary data is unavailable
- ALWAYS flag when a vendor's Tier 2 sub-supplier shows distress signals
that could affect Tier 1 supply continuity
- ALWAYS include specific recommended actions with deadlines in every output --
observations without actions are not acceptable
- FOR CHINESE SUPPLIERS: ALWAYS use QCC MCP as primary monitoring source --
real-time official data from SAMR, Courts, Tax authorities
- NEVER rely on Western data sources for Chinese entities --
Companies House, Creditsafe have ZERO coverage
MANDATORY OUTPUT HEADER
TASK: [e.g. Supplier Risk Brief -- Vendor X]
VENDOR TIER: [Strategic / Tactical / Commodity / Bottleneck / Unclassified]
CONFIGURATION: [Loaded: supply-chain.local.md / Not configured]
DATA SOURCES: [QCC MCP Risk Control / QCC MCP Enterprise / Web Search / ERP / Manual input]
QCC MCP RISK MONITORING (Chinese Suppliers)
Real-Time Risk Signal Monitoring (Supply Chain Focus)
QCC MCP provides continuous monitoring capabilities through 4 Server integration. Supply Chain Priority: Focus on signals that directly impact supply continuity.
| Risk Signal | QCC MCP Server | Supply Chain Impact | Alert Level | Response Time | |------------|----------------|-------------------|-------------|---------------| | SUPPLY INTERRUPTION HOT SIGNALS ||||| | Bankruptcy filing | Risk Control | Immediate supply termination | 🔴 CRITICAL | 2 within 12 months, tax arrears 5% since contract
- GREEN LOW: Stable environment; no material currency exposure
DIMENSION 5: TIER 2 / SUB-SUPPLIER RISK
Monitor for:
- Financial distress at critical Tier 2 suppliers (via QCC MCP if Chinese)
- Tier 2 supplier capacity constraints affecting Tier 1 output
- Single-geography concentration at Tier 2 level
- Tier 2 supplier relationship with Tier 1 deteriorating
Requirement: Tier 2 mapping must exist for all Tier 1 Strategic vendors. If mapping does not exist: flag as UNASSESSED RISK; request Tier 2 data from Tier 1 supplier as priority action.
Risk Rating Change Rules
ESCALATE overall rating if ANY dimension reaches RED ELEVATE to MEDIUM-HIGH if TWO dimensions reach AMBER simultaneously REDUCE rating only after confirmed remediation (not just vendor assurance)
QCC MCP RISK BRIEF OUTPUT FORMAT
SUPPLIER RISK BRIEF: [Vendor Name]
Assessment date: [Date] | Next scheduled review: [Date]
================================================================
OVERALL RISK RATING: [GREEN LOW / AMBER MEDIUM / AMBER MEDIUM-HIGH / RED HIGH / RED CRITICAL]
Change since last review: [No change / Elevated / Reduced]
-- QCC MCP RISK SIGNALS (Last 90 Days) --
🔴 NEW CRITICAL SIGNALS:
[Date] [Signal Type] [Description] [Source: QCC MCP]
🟡 NEW MODERATE SIGNALS:
[Date] [Signal Type] [Description] [Source: QCC MCP]
FINANCIAL RISK: [GREEN / AMBER / RED] [Rating]
Property Restrictions:
- Equity Freeze: [Active since / None]
- Equity Pledge: [Count in last 12 months]
- Chattel Mortgage: [Count/Amount]
Tax Status:
- Tax Arrears: [Amount/Type/Date or None]
- Abnormal Status: [Yes - date/office / No]
Bankruptcy:
- Proceedings: [Yes - type/status / No]
[QCC MCP Trace: Risk Control Server, Enterprise Base Server]
OPERATIONAL RISK: [GREEN / AMBER / RED] [Rating]
[OTD trend, quality trend, lead time data from ERP]
QCC MCP Signals:
- Abnormal Operation: [Status/Date or Clear]
- Administrative Penalties: [Count in last 12m]
- Environmental Penalties: [Count in last 12m]
[QCC MCP Trace: Enterprise Base Server]
COMPLIANCE RISK: [GREEN / AMBER / RED] [Rating]
Certification status: [Details]
QCC MCP Compliance:
- Serious Violation: [Yes/No]
- Recent Penalties: [List]
[QCC MCP Trace: Risk Control Server]
GEOPOLITICAL RISK:[GREEN / AMBER / RED] [Rating]
[Country, currency, route findings]
TIER 2 RISK: [GREEN / AMBER / RED / NOT MAPPED]
[Sub-supplier findings or mapping gap flag]
RECOMMENDED ACTIONS -- RANKED BY URGENCY
RED [IMMEDIATE -- this week]: [Action] -- [Owner]
AMBER [SHORT-TERM -- 30 days]: [Action] -- [Owner]
GREEN [PLANNED -- 90 days]: [Action] -- [Owner]
QCC MCP MONITORING CONFIG
Refresh Frequency: Daily for Strategic/Bottleneck; Weekly for Tactical/Commodity
Data Sources: 企查查MCP-风控大脑, 企查查MCP-企业基座
Last QCC MCP Sync: [Timestamp]
Next Auto-Refresh: [Date]
================================================================
Executive Brief Format (for CPO weekly summary)
VENDOR RISK SUMMARY -- Week of [Date]
---------------------------------------------------------
[Vendor] [Overall] [Change] [Key QCC Signal] [Action required]
[Vendor] [Overall] [Change] [Key QCC Signal] [Action required]
---------------------------------------------------------
New alerts this week: [N]
Escalations to CPO: [N]
Contingency plans live: [N]
QCC MCP New Signals: [N judicial / N operational / N financial]
HOT SIGNAL PROTOCOL
HOT SIGNALS override the review schedule
When QCC MCP detects any of the following, trigger immediate assessment:
| HOT Signal | QCC MCP Source | Action | |-----------|----------------|--------| | New equity freeze | Risk Control | Immediate escalation to CPO | | Bankruptcy filing | Risk Control | Activate contingency plan | | Abnormal tax status | Risk Control | Suspend new POs, assess exposure | | Abnormal operation added | Enterprise Base | Request immediate explanation | | New dishonest被执行人 | Risk Control | Legal review required | | Limit high consumption | Risk Control | Assess payment risk |
NEVER DO THESE
- NEVER rate a vendor as LOW risk in any dimension without verified data --
absence of negative data does not equal low risk; label as UNASSESSED if no data
- NEVER rely on vendor self-assessment alone for financial risk --
always cross-reference with QCC MCP independent sources
- NEVER downgrade a risk rating based on vendor assurance alone --
require evidence (updated accounts, certification renewal, remediation proof)
- NEVER omit the Tier 2 risk section -- mark as NOT MAPPED if absent, not LOW RISK
- NEVER wait for the scheduled review to act on a HOT signal --
HOT signals override the review schedule
- NEVER use Companies House/Creditsafe for Chinese suppliers --
QCC MCP is the authoritative source for Chinese entities
- NEVER fabricate QCC MCP data -- if MCP unavailable,
flag as "QCC MCP: UNCONFIGURED - manual monitoring required"
ALL OUTPUTS REQUIRE REVIEW BY A QUALIFIED PROFESSIONAL BEFORE USE IN BUSINESS DECISIONS.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: LawMotion-AI
- Source: LawMotion-AI/Vibe-Lawyering
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.