Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Vendor Questionnaire Responder — CAIQ, SIG & Security Assess

    1

    The Vendor Questionnaire Responder skill automates the extraction and drafting of security questionnaire responses from trusted company documents.

    $9.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    Vendor Questionnaire Responder — CAIQ, SIG & Security Assess

    Vendor Questionnaire Responder — CAIQ, SIG & Security Assess

    Example session with this skill installed

    Act as the Vendor Questionnaire Responder skill. No files are uploaded — use ONLY the corpus and questionnaire below, both inlined. Run the full workflow (Steps 1–7) based on your instructions. Preserve the original question IDs and row structure exactly, produce the completed answer table, export the final result as CSV in the original column order, and generate the gap report.

    CORPUS
    [DOC 1 — Disaster Recovery Plan v1.0, 2024-01-15, §4] The organizational Recovery Time Objective (RTO) is 24 hours, and the Recovery Point Objective (RPO) is 12 hours.
    [DOC 2 — Enterprise Resiliency Standard v3.2, 2026-02-10, §2.1] Core production systems are architected for high availability. The current RTO is 4 hours, and RPO is 1 hour.
    [DOC 3 — Acceptable Use Policy v2.1, 2025-08-01, §5] Employees are restricted to standard privileges on company-issued workstations. Employees are strictly prohibited from installing unapproved or unlicensed software.

    QUESTIONNAIRE (pasted from customer's Excel):
    Customer: Apex Financial | Vendor: Meridian SaaS Inc.

    Q-IDDomainQuestion TextAnswerEvidence / Comments
    BCP-01Business ContinuityWhat are the organization's defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO)?
    END-03Endpoint SecurityDoes the company technically enforce restrictions preventing the installation of unapproved software, hardware peripherals (e.g., USBs), and browser extensions?
    LEG-01Legal & PrivacyI hereby certify on behalf of my organization that we comply with all applicable local, state, and federal privacy laws regarding customer data.
    • Read your context and instructions
    • Compiled the vendor questionnaire responder
    • Generated the data export

    Step 1 — Answer Library

    No answers/ directory or library file was provided. Treating this as a fresh library — all matches will be DOC_SUPPORTED, PARTIAL, GAP, or OUT_OF_SCOPE. Nothing is a LIBRARY_HIT.

    Step 2 — Parsed Questionnaire

    {
      "questionnaire_id": "apex-financial_meridian-saas_2026-09-15",
      "questions": [
        {"q_id": "BCP-01", "control_domain": "Business Continuity", "question_text": "What are the organization's defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO)?", "response_type": "text"},
        {"q_id": "END-03", "control_domain": "Endpoint Security", "question_text": "Does the company technically enforce restrictions preventing the installation of unapproved software, hardware peripherals (e.g., USBs), and browser extensions?", "response_type": "yes_no"},
        {"q_id": "LEG-01", "control_domain": "Legal & Privacy", "question_text": "I hereby certify on behalf of my organization that we comply with all applicable local, state, and federal privacy laws regarding customer data.", "response_type": "yes_no_na"}
      ]
    }
    

    No parse errors. No prefilled cells present to verify.

    Step 3 — Classification

    Q-IDClassReason
    BCP-01DOC_SUPPORTED (with conflict flag)Two sources conflict on RTO/RPO values
    END-03PARTIALCorpus documents a policy prohibition, not technical enforcement — these are distinct claims
    LEG-01OUT_OF_SCOPEAttestation requiring human signature on behalf of the organization

    Step 4 — Draft Answers

    BCP-01: Doc 1 (Disaster Recovery Plan v1.0, 2024-01-15, §4) states one RTO/RPO; Doc 2 (Enterprise Resiliency Standard v3.2, 2026-02-10, §2.1) states a different, more current RTO/RPO for core production systems. Per guardrails, answering with the more recent/authoritative document while flagging the discrepancy.

    END-03: The Acceptable Use Policy establishes a policy-level restriction (standard user privileges, prohibition on unapproved software) but does not describe a technical enforcement mechanism (e.g., endpoint allow-listing, USB port control, browser extension management). Answering "Yes" here would conflate policy with technical control — a guardrail violation. Drafted as partial with scope limit.

    LEG-01: This is a first-person attestation ("I hereby certify... on behalf of my organization"). Per scope rules, this requires a human signature/formal certification and cannot be drafted on the organization's behalf.

    Step 5 — Assembled Outputs

    Completed Answer Table

    Q-IDDomainQuestion TextAnswerEvidence / Comments
    BCP-01Business ContinuityWhat are the organization's defined RTO and RPO?Per the most current governing document, RTO is 4 hours and RPO is 1 hour for core production systems. Note: an older document specifies RTO 24h/RPO 12h — see Gap Report for discrepancy.(Source: Enterprise Resiliency Standard v3.2, §2.1, 2026-02-10) — conflicts with Disaster Recovery Plan v1.0, §4, 2024-01-15
    END-03Endpoint SecurityDoes the company technically enforce restrictions preventing installation of unapproved software, hardware peripherals, and browser extensions?Partially supported. Policy prohibits unapproved software installation and restricts employees to standard privileges. No documentation confirms technical enforcement (e.g., device/USB control, browser extension management, allow-listing). NEEDS OWNER for the technical-enforcement portion.(Source: Acceptable Use Policy v2.1, §5, 2025-08-01) — policy-level only
    LEG-01Legal & PrivacyCertification of compliance with applicable privacy lawsHUMAN REQUIRED — attestation on behalf of the organization; requires authorized signatory, not a drafted answer.N/A

    Gap Report

    Q-IDFlag TypeIssueSuggested Owner
    BCP-01Source ConflictDR Plan v1.0 (2024) states RTO 24h/RPO 12h; Resiliency Standard v3.2 (2026) states RTO 4h/RPO 1h for core production systems. Answered using the more recent, more authoritative document per guardrails, but the older DR Plan appears stale and unreconciled.BC/DR Program Owner — should confirm DR Plan v1.0 is retired/superseded or clarify scope differences (e.g., "core production" vs. broader environment)
    END-03Partial / Terminology PrecisionCorpus supports a policy restriction, not a technical enforcement control. These are distinct security concepts per guardrails and cannot be conflated.Endpoint Security / IT Security Owner — needs to supply evidence of technical controls (MDM/EDR policy, USB blocking config, browser extension management) if they exist
    LEG-01Out of ScopeFirst-person attestation requiring authorized signature; not answerable by drafted content.Legal/Compliance — requires named signatory

    Follow-up Question Handling

    No follow-up branches (followups_if_yes) were present in the source questionnaire structure, so none apply.

    Change Log

    • BCP-01: Newly drafted (DOC_SUPPORTED with conflict) — awaiting approval.
    • END-03: Newly drafted (PARTIAL) — awaiting approval; technical-enforcement gap flagged for owner.
    • LEG-01: Marked HUMAN REQUIRED — not drafted, no library action.
    • No stale library answers (library was empty prior to this run).

    CSV Export## Step 6 — Library Update & Staleness Check

    No prior library existed, so there's nothing to mark stale. Writing 2 new draft entries (BCP-01, END-03) to a fresh library; LEG-01 is not added since it's out-of-scope, not an answerable question.

    Step 7 — Review Summary

    
    ## Review Summary
    - Total questions/rows processed: 3
    - Answered from approved library: 0
    - Newly drafted (awaiting approval): 2 (BCP-01, END-03)
    - Gaps requiring owner input: 1 partial (END-03 technical-enforcement portion) → see Gap Report
    - Out-of-scope (human/legal): 1 (LEG-01)
    - Parse errors (unrecoverable): 0
    - Stale answers flagged: 0
    - **Action required:** review and approve 2 draft answers; resolve the BCP-01 RTO/RPO document conflict; route LEG-01 to an authorized signatory; source technical-enforcement evidence for END-03 if it exists.
    

    Note on END-03: I did not answer "Yes" here even though the policy language sounds close — enforced policy and enforced technically are different claims, and only the former is documented. Answering "Yes" would be the kind of assessor-facing overstatement the guardrails exist to prevent.

    Q-ID,Domain,Question Text,Answer,Evidence / Comments
    BCP-01,Business Continuity,"What are the organization's defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO)?","Per the most current governing document, RTO is 4 hours and RPO is 1 hour for core production systems. Note: an older document specifies RTO 24h/RPO 12h -- see Gap Report for discrepancy.","(Source: Enterprise Resiliency Standard v3.2, Section 2.1, 2026-02-10) -- conflicts with Disaster Recovery Plan v1.0, Section 4, 2024-01-15"
    END-03,Endpoint Security,"Does the company technically enforce restrictions preventing the installation of unapproved software, hardware peripherals (e.g., USBs), and browser extensions?","Partially supported. Policy prohibits unapproved software installation and restricts employees to standard privileges. No documentation confirms technical enforcement (e.g., device/USB control, browser extension management, allow-listing). NEEDS OWNER for the technical-enforcement portion.","(Source: Acceptable Use Policy v2.1, Section 5, 2025-08-01) -- policy-level only"
    LEG-01,Legal & Privacy,"I hereby certify on behalf of my organization that we comply with all applicable local, state, and federal privacy laws regarding customer data.","HUMAN REQUIRED -- attestation on behalf of the organization; requires authorized signatory, not a drafted answer.","N/A"

    vendor-questionnaire-responder-caiq-sig-.csv

    CSV · data export

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Draft verifiable answers to CAIQ and SIG questionnaires with page citations.Identify security compliance gaps during enterprise sales due diligence.Maintain a reusable, versioned library of approved security responses.Verify prospect-prefilled questionnaires against actual company policies.

    About this skill

    The Vendor Questionnaire Responder skill automates the extraction and drafting of security questionnaire responses from trusted company documents. It guarantees strict compliance by refusing hallucinated claims, handling conflicting sources, flagging missing evidence for human review, and maintaining the structural integrity of exported CSV files.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 17 days ago

    • Passed all security checks, Safe to install

    Listed17 days ago

    What's inside

    Frequently Asked Questions