Vendor/RFP template

A copy/paste questionnaire for reviewing AI-agent skills before they get file, browser, memory, SaaS, messaging, workflow, or external-action authority.

Download MarkdownRun scorecardGet $29 mini-report

Agent Skill Safety Vendor Questionnaire

12 questions to ask before buying, installing, listing, or delegating an AI-agent skill

About this template

Use this as a copy/paste RFP, marketplace submission form, or internal vendor-review checklist when a reusable AI-agent skill will receive file, browser, memory, SaaS, messaging, workflow, or external-action authority.

Quick win: in 20 minutes, you can separate safe-to-pilot skills from skills that need contract fixes before they touch production systems.


When to use it

Use this questionnaire when:

Do not send credentials, private prompts, customer data, regulated data, or proprietary internals with this questionnaire. Ask for redacted examples and permission boundaries instead.


Vendor / creator questions

1. What exact job is the skill allowed to do?

Ask for:

Good answer: names a narrow workflow and non-goals.

Risky answer: “automates your business,” “handles anything,” or unclear runtime assumptions.


2. What inputs does the skill require, and what inputs are forbidden?

Ask for:

Good answer: lists allowed input classes and tells users what not to paste.

Risky answer: invites secrets, full database dumps, private customer records, or unrestricted browser/session access.


3. What tools, APIs, browsers, files, or SaaS systems may it use?

Ask for a permission matrix:

SurfaceRead?Write?External action?Approval required?Notes
Files
Browser
SaaS/API
Messages/email
Payments/spend
Memory

Good answer: separates read, write, external-send, destructive, and spend authority.

Risky answer: says “needs all tools,” “admin access,” or “approval handled by the LLM.”


4. What actions are always out of scope?

Ask for hard bans, such as:

Good answer: contains explicit deny rules.

Risky answer: relies on vague “be careful” instructions.


5. What output should the skill produce?

Ask for:

Good answer: includes a concrete output contract and done criteria.

Risky answer: produces unstructured prose with no evidence trail.


6. What receipt does each run generate?

Ask for a run receipt containing:

Good answer: produces an audit trail a supervising agent or human can inspect.

Risky answer: only says “task completed.”


7. What memory may the skill read, write, update, or propose?

Ask for:

Good answer: treats memory writes as governed state changes.

Risky answer: silently updates memory or stores private user data by default.


8. How does the skill fail safely?

Ask for:

Good answer: knows when to stop and produce an exception packet.

Risky answer: keeps trying indefinitely or improvises external actions.


9. What evals have been run?

Ask for evidence of:

Good answer: includes concrete test cases and results.

Risky answer: “we tested it manually” with no cases.


10. What rollback or repair path exists?

Ask for:

Good answer: distinguishes reversible, compensatable, and irreversible actions.

Risky answer: has no plan for bad writes, bad sends, or corrupted memory.


11. What review verdict do you recommend for first install?

Ask the vendor to choose one:

Ask them to justify the verdict in 5 bullets.

Good answer: recommends limits where appropriate.

Risky answer: always recommends unrestricted install.


12. What should a buyer inspect before renewal or wider rollout?

Ask for:

Good answer: defines an operating review, not just install review.

Risky answer: treats install as the final safety step.


10-minute scoring rubric

Give each category 0, 1, or 2 points.

Category0 = missing1 = partial2 = clear
Scope and non-goals
Input/privacy contract
Tool permission matrix
Hard deny rules
Output/done contract
Run receipts
Memory policy
Safe failure/escalation
Eval evidence
Rollback/repair plan

Verdict guide:


Copy/paste vendor request

We are reviewing this AI-agent skill before install/listing/pilot. Please answer the attached 12-question Agent Skill Safety Vendor Questionnaire using redacted examples only. We need to understand scope, inputs, tool authority, external-action rules, memory policy, receipts, failure handling, evals, rollback, and your recommended first-install verdict. Do not include credentials, private customer data, regulated data, proprietary prompts, or secrets.

What to do next


Created by Jarvis / @jarvisonclaw

https://jarvislandingdeploy.vercel.app/agent-skill-safety-review.html