Official agent skill

Vendor Agreement Review

by anthropics in anthropics/claude-for-legal

Reference: review of an inbound vendor agreement against the team playbook in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md.

OfficialApache-2.0Auto-check passedLegal & Compliance

Install Vendor Agreement Review

skills CLI
$ npx skills add anthropics/claude-for-legal --skill vendor-agreement-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anthropics/claude-for-legal vendor-agreement-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/commercial-legal/skills/vendor-agreement-review .claude/skills/vendor-agreement-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-agreement-review
GitHub stars
9.6k
Used in
1 other repo
Token cost
~5.9k tokens
SKILL.md length
2,879 words
Files
1
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reference: review of an inbound vendor agreement against the team playbook in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md.

  • Works in 6 steps: Orient → Deal-breaker check → Term-by-term comparison → …
  • Tasks that involve Contract review
  • SKILL.md covers Matter context, Destination check, Purpose and Precondition: load the playbook, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vendor Agreement Review is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Reference: review of an inbound vendor agreement against the team playbook in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md. Flags deviations, assesses risk, generates specific redline language, and routes to the right approver. Loaded by /commercial-legal:review when a vendor MSA, services agreement, or similar is detected.

Its SKILL.md is about 5.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Contract review and Agent instruction files. The repository describes itself as: A suite of plugins for legal workflows. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Contract review
  • Tasks that involve Agent instruction files

Example prompts

  • “/vendor-agreement-review”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Orient
  2. Deal-breaker check
  3. Term-by-term comparison
  4. Favorable terms and gaps
  5. Escalation routing
  6. Assemble the memo

What it can do on your machine

Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor Agreement Review loads about 5.9k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 2,879 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~5.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 2,879 words, ~5,915 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-agreement-review/SKILL.md (or your agent's skills folder).
name
vendor-agreement-review
description
Reference: review of an inbound vendor agreement against the team playbook in `~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md`. Flags deviations, assesses risk, generates specific redline language, and routes to the right approver. Loaded by /commercial-legal:review when a vendor MSA, services agreement, or similar is detected.
user-invocable
false

Vendor Agreement Review

Matter context

Matter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /commercial-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/commercial-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.


Destination check

Before producing output, check where it's going. If the user has named a destination (a channel, a distribution list, a counterparty, "everyone"), ask whether it's inside the privilege circle. Public channels, company-wide lists, counterparty/opposing counsel, vendors, and clients (for work product) waive the protection. When the destination looks outside the circle, flag it and offer (a) the privileged version for legal only, (b) a sanitized version for the broader channel, or (c) both — don't silently apply a privileged header and then help paste it somewhere the header won't protect it. See the canonical ## Shared guardrails → Destination check in this plugin's CLAUDE.md.

Purpose

Read a vendor agreement against the playbook this team actually uses (in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md), find every term that deviates, and tell the lawyer what to do about each one — with specific redline language, not vague "consider revising."

The output is a review memo the lawyer can act on in one pass. Every issue has a severity, a business-impact explanation, a proposed fix, and an escalation call if one is needed.

Precondition: load the playbook

Before reading the contract, read ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md. If it's missing or still has placeholders, surface this bounce:

I notice you haven't configured your practice profile yet — that's how I tailor playbook positions, escalation, and house style to your practice.

Two choices:

  • Run /commercial-legal:cold-start-interview (2 minutes) to configure your profile, then I'll review tailored to YOUR playbook.
  • Say "provisional" and I'll review against generic defaults — US jurisdiction, middle risk appetite, lawyer role, no playbook (flag all common vendor-contract risks from first principles) — and tag every output [PROVISIONAL — configure your profile for tailored output] so you can see what I do before committing.
Provisional mode

If the user says "provisional," run the review normally using these generic defaults: middle risk appetite, lawyer role, US jurisdiction, no playbook (flag the common vendor-side risks from first principles — unlimited liability, no data-breach carveout, uncapped indemnity, auto-renewal without notice, etc. — rather than matching to configured positions). Tag the reviewer note and every finding block with [PROVISIONAL]. At the end of the output, append:

"That was a generic run against default assumptions. Run /commercial-legal:cold-start-interview to get output calibrated to YOUR practice — your playbook, your jurisdiction, your risk appetite. 2 minutes."

Which side? Before applying the playbook, determine which side the company is on for this contract. Usually obvious: if the counterparty is a vendor/supplier providing goods or services, you're purchasing-side. If the counterparty is a customer buying your product/service, you're sales-side. If it's not obvious (a reseller agreement, a partnership, a revenue share), ask: "Which side is [company] on for this agreement — vendor or customer?" Read the matching playbook section (### Sales-side playbook or ### Purchasing-side playbook) from the config. Note which side in the output so the reviewer knows which playbook was applied. If the matching side is [Not configured], stop and tell the user to run /commercial-legal:cold-start-interview --side <side> before this review can proceed.

This skill is typically used for purchasing-side contracts (vendors supplying you), but the side check still applies — a "vendor agreement" could be your own template sent to a vendor as part of a reseller arrangement (sales-side).

The playbook in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md is the source of truth. It tells you:

  • What this team's standard positions are (not market standard — their standard)
  • What fallbacks they've accepted before
  • What they never accept
  • Who approves what
  • The one deal-breaker to check first

If the contract has the deal-breaker, flag it at the top of the memo and stop the detailed review. There's no point spending 30 minutes on liability caps if the agreement gives the vendor rights to use customer data for training.

Workflow

Step 1: Orient

Read the whole agreement once, fast. Answer:

QuestionAnswer
What kind of agreement is this?MSA / SaaS subscription / Professional services / License / Other
Who are we?Customer / Vendor (this plugin assumes customer — flag if not)
CounterpartyName, and are they a BigCo (won't negotiate) or a startup (will)?
Dollar valueAnnual / total contract value if stated
TermLength, renewal mechanics
Is there a DPA?Attached / referenced by URL / missing
Is there an order form?Separate doc or integrated

Dollar-value handling. If the main agreement does not state a dollar value (the MSA sets terms but the Order Form carries price, which is typical), stop and ask before running escalation math or applying dollar thresholds:

The MSA itself doesn't state an annual contract value. The Order Form carries the price. Your escalation threshold is $[X from the matrix]. Before I route this, I need the ACV. Options:

  1. Paste the Order Form value (preferred — I'll use it for routing and the memo).
  2. Tell me if this is above or below $[threshold] and I'll route accordingly; the memo will flag that the routing assumed [above/below threshold] without an ACV in hand.
  3. Route conservatively to the higher approver regardless — safer for a review you haven't priced.

Do NOT silently assume a value and then use the assumed value to drive routing. The assumption propagates into the approval call, which is a place the review shouldn't be guessing.

DPA-by-reference handling. If the main agreement incorporates a DPA "available at [URL]" or "as set forth at [URL]" or similar by reference, the DPA is part of the contract but is not in front of you. Note it explicitly in the Orient table and in the review memo:

This agreement incorporates a DPA by URL reference at [URL]. The DPA carries the real data terms — subprocessor rights, breach-notification timing, data-return mechanics, standard contractual clauses, audit rights. Without reading it, the data-protection analysis below is partial. Offer to route the DPA to /privacy-legal:dpa-review (if installed) for a separate review, or fetch and read it inline before completing Step 3's data-protection analysis.

If the user is installed with privacy-legal, explicitly offer:

Want me to hand the DPA URL to /privacy-legal:dpa-review once you're ready? That skill is built for the DPA work and will catch subprocessor / SCC / breach-notification issues that this skill only flags at the gate.

Do not silently proceed as if the DPA were absent when it is incorporated by reference. A missing DPA and an unread DPA are different gaps — label them differently.

Step 2: Deal-breaker check

Check the "one thing" from ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md first. If present:

markdown
## ⛔ DEAL-BREAKER PRESENT

**Section [X.X]** contains [the deal-breaker]. Per the team playbook, this is a
hard no. Recommend:

- [ ] Push back — propose [specific alternative language]
- [ ] Walk — if counterparty won't move, we don't sign

Detailed review below is provided for completeness but is moot unless this is
resolved.
Step 3: Term-by-term comparison

For each playbook category in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md, find the corresponding contract section and compare.

For each deviation, produce:

markdown
### [Section X.X]: [Issue name]

**Playbook says:** [our standard position, quoted from `~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md`]

**Contract says:**
> "[exact quote from the contract]"

**Gap:** [Missing term | Weaker than standard | Weaker than fallback | Non-standard structure | Unacceptable]

**Legal risk:** 🔴 Critical | 🟠 High | 🟡 Medium | 🟢 Low
**Business friction:** 🔴 Blocks deals | 🟠 Slows deals | 🟡 Confuses customers | 🟢 Invisible

**Why it matters:** [one or two sentences in plain English — what goes wrong
for the business if this term stays as-is]

**Proposed redline:**
> "[the specific replacement language — ready to paste into a markup]"

**If they won't move:** [the fallback from `~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md`, or "escalate to [person]"
if no fallback exists]

Severity calibration:

LevelMeans
🔴 CriticalDon't sign without fixing. A term on the team's "never accept" list in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md, or a deal-breaker.
🟠 HighStrongly push; escalate if they won't move. A term outside the playbook's stated fallback range.
🟡 MediumPush in first round; accept if it's the last open item. A term inside the fallback range but short of the standard position.
🟢 LowNote it, don't spend capital. A term the playbook explicitly tolerates, or a purely stylistic deviation.

Severity is always applied against ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md. If a term doesn't map cleanly to a playbook position, ask the user which bucket it belongs in and offer to record the answer in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md.

Liability cap decision procedure

The cap amount is the least important part of the cap. When reviewing the limitation-of-liability clause, do not produce a single "check liability cap against playbook" line item. Work through the four dimensions below and state each one explicitly in the finding:

  1. Direct vs. indirect/consequential damages. Does the cap apply to ALL liability, or only direct damages? A 12-month cap on direct damages with uncapped consequential damages is a completely different position than a 12-month aggregate cap. State both treatments explicitly.

  2. The cap base — quote it verbatim. "12-month cap" could mean: (a) fees paid in the 12 months preceding the claim, (b) fees payable in the current 12-month period, (c) fees over the last 12 months of usage, (d) fees under the current order form, (e) total fees ever paid. These can differ by an order of magnitude. Quote the exact language. If ambiguous, flag it: "Cap base is ambiguous — [the quoted language] — could mean [X] or [Y]. Confirm before signing."

  3. Cap-carveout interaction. A $100K cap with uncapped indemnity for data breach, IP, and confidentiality is functionally uncapped for the claims that actually arise in SaaS disputes. Enumerate what sits ABOVE the cap (the carveouts), what sits BELOW (what's actually capped), and assess whether the capped surface is meaningful: "The cap covers [general contract breach]. Data breach, IP indemnity, and confidentiality are carved out and uncapped. For this vendor's risk profile, the capped surface is [meaningful / nominal]."

  4. Your playbook position per dimension. The practice profile should have positions for: direct cap (multiple of fees), indirect damages (excluded / capped / uncapped), carveout list (what's acceptable above the cap), and cap base (which definition you'll accept). If the playbook has one "standard position" field, note: "Your playbook has a single cap position — consider splitting into direct/indirect/carveouts/base for more precise review."

Jurisdiction delta check

The playbook applies one governing-law preference globally. Enforceability varies materially. Check the contract's actual governing law against the top divergences before accepting playbook positions at face value:

  • Non-solicits/non-competes: Unenforceable in CA (Bus. & Prof. Code §16600). Restricted in many EU jurisdictions. Enforceable with limitations elsewhere. [jurisdiction — verify]
  • Auto-renewal: CA GBL §17600-17606, NY GBL §527-a, IL 815 ILCS 601 have specific consumer/B2B notice requirements. Other states vary. [jurisdiction — verify]
  • Liability exclusions: EU and UK unfair contract terms rules (UCTA 1977, Consumer Rights Act 2015) constrain consumer exclusions. Some US states limit exclusion of gross negligence or willful misconduct. [jurisdiction — verify]
  • Indemnification: Some states void indemnification for the indemnitee's own negligence. [jurisdiction — verify]
  • Confidentiality term: Some jurisdictions limit "perpetual" confidentiality to a reasonable period. [jurisdiction — verify]

When the playbook position conflicts with the contract's governing-law enforceability, flag: "Your playbook prefers [X], but this contract is governed by [Y] law where [X] is [unenforceable / restricted / subject to statutory override]. [jurisdiction — verify]"

Show full SKILL.md (1,159 more words)Show less
Step 4: Favorable terms and gaps

Two short lists:

Better than our standard: Terms where the vendor gave us more than we'd ask for. Note these — they're trade bait if you need to give something up elsewhere.

Missing entirely: Standard provisions that just aren't there. Most common: assignment restrictions, audit rights (if we want them), force majeure, insurance requirements.

Step 5: Escalation routing

Check the escalation matrix in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md against:

  • Contract dollar value
  • Presence of any 🔴 critical issues
  • Any automatic-escalation triggers (unlimited liability, IP assignment, etc.)

State clearly who needs to approve this:

markdown
## Approval routing

Based on [dollar value / issue severity], this agreement requires:

- [ ] **[Name/role]** approval — [reason]
- [ ] **Business owner sign-off** on [specific commercial term they should weigh in on]

**Recommended next step:** [Send redlines to counterparty | Escalate to GC before
responding | Get business input on commercial term X before legal responds]

Before proceeding to send redlines to the counterparty: Read ## Who's using this in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md. If the Role is Non-lawyer:

Sending redlines is a legal act — the counterparty will treat every edit as our negotiating position. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:

[Generate a 1-page summary: counterparty, agreement type, the specific redlines proposed, the playbook positions behind each, the fallbacks, and what to ask the attorney before the package leaves.]

If you need to find an attorney, solicitor, barrister, or other authorised legal professional: contact your professional regulator (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent) for a referral service.

Do not proceed past this gate without an explicit yes.

Redline granularity

Edit at the smallest possible granularity. A redline is a negotiation artifact, not a rewrite. Wholesale clause replacement signals "we threw out your drafting" — it's aggressive, it forces the counterparty to re-read the whole clause, and it discards the parts of their drafting that were fine. Surgical redlines — strike a word, insert a phrase, restructure a subclause — signal "we have specific asks" and are faster to read, understand, and accept.

Default to the smallest edit that achieves the playbook position:

  • Replace a word before a phrase. ("twelve (12)" → "twenty-four (24)")
  • Replace a phrase before a sentence. ("paid by the Buyer" → "paid and payable by the Buyer")
  • Restructure a subclause before replacing the sentence. (Add "(a)" and "(b)" to split a compound condition.)
  • Replace a sentence before replacing the clause.
  • Only replace a whole clause when the counterparty's version is so far from your position that surgical edits would be harder to read than a fresh draft — and when you do, say so in the transmittal: "We've replaced §8.2 rather than marking it up because the changes were extensive. Happy to walk you through the delta."

When in doubt, smaller. A client who receives a surgical redline trusts that you read carefully. A client who receives a wholesale replacement wonders whether you read at all.

Step 6: Assemble the memo

Prepend the work-product header from ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md ## Outputs (it differs by user role — see ## Who's using this).

This memo and the underlying agreement may be privileged, confidential, or both. The output inherits that status from the source. Distribute only within the privilege circle; mark and store it where privileged materials live; strip the work-product header before any external delivery (e.g., counterparty redlines, stakeholder summaries).

The playbook positions applied below reflect the jurisdiction recorded in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md → Governing law and venue. Legal rules and enforceability vary materially by jurisdiction. If this deal implicates a different governing law or a choice-of-law question, flag it in the memo — the analysis may not transfer as written.

No silent supplement. If a research query to the configured legal research tool returns few or no results for a rule the memo needs (enforceability of a limitation clause, indemnity scope, governing-law choice), report what was found and stop. Do NOT fill the gap from web search or model knowledge without asking. Say: "The search returned [N] results from [tool]. Coverage appears thin for [rule / jurisdiction]. Options: (1) broaden the search query, (2) try a different research tool, (3) search the web — results will be tagged [web search — verify] and should be checked against a primary source before relying, or (4) flag as unverified and stop. Which would you like?" A lawyer decides whether to accept lower-confidence sources.

Source attribution. Where the memo cites a statute, regulation, or case, tag the citation: [Westlaw], [statute / regulator site], or the MCP tool name for citations retrieved from a legal research connector; [web search — verify] for web-search citations; [model knowledge — verify] for citations recalled from training data; [user provided] for citations from the counterparty draft or house files. Citations tagged verify carry higher fabrication risk and should be checked first. Never strip or collapse the tags.

markdown
[WORK-PRODUCT HEADER — per plugin config ## Outputs]

# Vendor Agreement Review: [Counterparty] [Agreement Type]

**Reviewed:** [date]
**Contract value:** $[amount] / [term]
**Our role:** Customer

---

## Bottom line

[Two sentences. Can we sign this? What has to change first?]

**Issues (legal risk):** [N]🔴 [N]🟠 [N]🟡 [N]🟢
**Issues (business friction):** [N]🔴 [N]🟠 [N]🟡 [N]🟢

**Approval needed from:** [name]

---

## Deal-breaker check

[✅ Clear | ⛔ Present — see above]

---

## Issues by severity

[All the deviation blocks from Step 3, grouped Critical → Low]

---

## Favorable terms

[list]

## Missing provisions

[list]

---

## Approval routing

[from Step 5]

---

## Redline package

[If requested: consolidated markup-ready language for all proposed changes]

Integration: [CLM]

If a [CLM] MCP is connected, after the review:

  • Check if this counterparty already has agreements with us (may inform negotiating posture — "we already gave them 24-month cap on the last deal")
  • Pull the workflow template that matches this agreement type
  • Offer to create the [CLM] record with the review memo attached and approvers pre-routed

Integration: DocuSign

If DocuSign MCP is connected and the agreement is ready to sign (all greens or all issues accepted), offer to:

  • Generate the envelope
  • Route to signers in the right order per the escalation matrix

Do not send anything for signature without explicit instruction. "Ready to sign" is the lawyer's call, not yours.

Before generating a signature envelope or routing for countersignature: Read ## Who's using this in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md. If the Role is Non-lawyer:

This step has legal consequences (signing binds the company to the whole agreement). Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:

[Generate a 1-page summary: counterparty, contract value, the issues found and how they resolved, any risk the lawyer accepted, and what to ask the attorney before envelope goes out.]

If you need to find an attorney, solicitor, barrister, or other authorised legal professional: contact your professional regulator (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent) for a referral service.

Do not proceed past this gate without an explicit yes.

Output formats

Full memo (default): As above. Goes in the [CLM] record or the Drive folder from ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md house-style section.

Slack-sized summary: Two lines and a link. For when someone asks "is this okay?" in a channel.

[Counterparty] [type] — NEEDS WORK. 1🔴 (uncapped liability §8.2), 2🟠. Full review: [link]. Needs [GC] approval.

Redline doc: If the user asks for it, output a .docx with tracked changes. Use the docx skill. Comments on each change cite the playbook position.

Quality checks before delivering

  • ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md was loaded and quoted — not generic market positions
  • Deal-breaker checked first
  • Every issue has specific replacement language
  • Risk levels are calibrated (not everything is Critical)
  • Approver is named, not "escalate to legal"
  • Counterparty context considered (BigCo vs. startup — affects what's worth fighting over)

Close with the next-steps decision tree

End with the next-steps decision tree per CLAUDE.md ## Outputs. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.

© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in commercial-legal/skills/vendor-agreement-review of anthropics/claude-for-legal.

Open the folder on GitHubat commit 4a6c651

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Vendor Agreement Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor Agreement Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor Agreement Review this skillanthropics/claude-for-legal9.6k1 repos~5.9kAutomated safety check: PassApache-2.0
SEO Analiticaricneves-ai/flowgrammers-skills115—~2.3kAutomated safety check: PassMIT
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Commercial Legal Plapiotrowski-afk/commercial-legal-pl1761 repos~4.1kAutomated safety check: PassApache-2.0
Hand Drawnthreerocks/hand-drawn-styles2.2k—~398Automated safety check: PassMIT
Tw Formal WritingImbad0202/tw-formal-writing179—~1kAutomated safety check: PassMIT

Similar skills

  • SEO Analitica

    ricneves-ai/flowgrammers-skills

    Skills para otimização de SEO técnico, análise de dados, criação de dashboards e inteligência de negócio para empresas brasileiras.

    115 GitHub stars~2.3k tokensUpdated 15 days ago
    Legal & ComplianceAuto-check passed
  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Commercial Legal Pl

    apiotrowski-afk/commercial-legal-pl

    Skill do analizy i tworzenia umów według polskiego prawa, ze szczególnym uwzględnieniem umów B2B, IP i IT (body leasing, NDA, wdrożenia, SaaS, przeniesienie praw autorskich, ugody).

    176 GitHub starsUsed in 1 repo~4.1k tokens
    Legal & ComplianceAuto-check passed
  • Hand Drawn

    threerocks/hand-drawn-styles

    A skill your agent uses when users ask for a hand-drawn or illustrated image prompt, name one of the repository's 20 numbered styles or the 3.1 stable variant, or mention triggers such as…

    2.2k GitHub stars~398 tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Tw Formal Writing

    Imbad0202/tw-formal-writing

    台灣正式文件撰寫助手 — 涵蓋政府公文、政府機關其他文件、法律文件、人民對政府文書四類中文正式文件的撰寫(不含學術論文、商業文書、私人書信等,見下方排除清單)。

    179 GitHub stars~1k tokensUpdated 16 days ago
    Legal & ComplianceAuto-check passed
  • Contract Review Pro

    CSlawyer1985/contract-review-pro

    专业合同审核 Skill:7步工作流(含立场声明、框架审阅、类型路由)、5类通用门禁+16个专项门禁、终稿三件套+HTML可视化报告、8维度风险评分、修订5分类路由。完全自包含,零外部依赖。

    277 GitHub stars~2.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from anthropics/claude-for-legal

All 147 skills in this repo
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Supervisor Review Queue

    anthropics/claude-for-legal

    Official

    Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.

    9.6k GitHub starsUsed in 3 repos~1.1k tokens
    Auto-check passed
  • Tabular Document Review

    anthropics/claude-for-legal

    Official

    Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.

    9.6k GitHub starsUsed in 3 repos~4.3k tokens
    Auto-check passed
  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Auto-check passed
  • Legal Skills Registry Browser

    anthropics/claude-for-legal

    Official

    Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.

    9.6k GitHub starsUsed in 2 repos~620 tokens
    Auto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed

Questions about Vendor Agreement Review

What does Vendor Agreement Review do?

Reference: review of an inbound vendor agreement against the team playbook in ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md. Vendor Agreement Review is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization.md.

When should I use Vendor Agreement Review?

Vendor Agreement Review fits situations like: tasks that involve Contract review; tasks that involve Agent instruction files.

How do I install Vendor Agreement Review in Claude Code?

Run `npx skills add anthropics/claude-for-legal --skill vendor-agreement-review -a claude-code`. Or copy the skill folder (commercial-legal/skills/vendor-agreement-review in anthropics/claude-for-legal) into .claude/skills/vendor-agreement-review in your project. Claude Code loads it when a task matches its description.

How do I install Vendor Agreement Review in Codex?

Run `npx skills add anthropics/claude-for-legal --skill vendor-agreement-review -a codex`. Or copy the skill folder (commercial-legal/skills/vendor-agreement-review in anthropics/claude-for-legal) into .agents/skills/vendor-agreement-review in your project. Codex loads it when a task matches its description.

Can I use Vendor Agreement Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill vendor-agreement-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-agreement-review, .gemini/skills/vendor-agreement-review, .github/skills/vendor-agreement-review and .opencode/skills/vendor-agreement-review in your project.

What does Vendor Agreement Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Vendor Agreement Review is instructions for the agent only.

Does Vendor Agreement Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor Agreement Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vendor Agreement Review use?

Vendor Agreement Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor Agreement Review use?

About 5.9k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vendor Agreement Review?

Skills that share tags, products or a category with Vendor Agreement Review: SEO Analitica (ricneves-ai/flowgrammers-skills, 115 stars), Contract Review (evolsb/claude-legal-skill, 464 stars), Commercial Legal Pl (apiotrowski-afk/commercial-legal-pl, 176 stars) and Hand Drawn (threerocks/hand-drawn-styles, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor Agreement Review?

anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,633 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.

Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.