Nla Create
internet-court/internet-court-skill
Create a Natural Language Agreement escrow on-chain. An agent skill from internet-court/internet-court-skill.
Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency.
$ npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install anthropics/claude-for-legal vendor-ai-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance-legal/skills/vendor-ai-review .claude/skills/vendor-ai-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vendor-ai-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/vendor-ai-review into .claude/skills/vendor-ai-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-ai-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/vendor-ai-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install anthropics/claude-for-legal vendor-ai-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ai-governance-legal/skills/vendor-ai-review .agents/skills/vendor-ai-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vendor-ai-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/vendor-ai-review into .agents/skills/vendor-ai-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-ai-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install anthropics/claude-for-legal vendor-ai-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ai-governance-legal/skills/vendor-ai-review .cursor/skills/vendor-ai-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vendor-ai-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/vendor-ai-review into .cursor/skills/vendor-ai-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-ai-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/anthropics/claude-for-legal.git --path ai-governance-legal/skills/vendor-ai-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install anthropics/claude-for-legal vendor-ai-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ai-governance-legal/skills/vendor-ai-review .gemini/skills/vendor-ai-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vendor-ai-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/vendor-ai-review into .gemini/skills/vendor-ai-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-ai-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install anthropics/claude-for-legal vendor-ai-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .github/skills && cp -r skills-src/ai-governance-legal/skills/vendor-ai-review .github/skills/vendor-ai-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vendor-ai-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/vendor-ai-review into .github/skills/vendor-ai-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-ai-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install anthropics/claude-for-legal vendor-ai-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ai-governance-legal/skills/vendor-ai-review .opencode/skills/vendor-ai-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vendor-ai-review" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/vendor-ai-review into .opencode/skills/vendor-ai-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-ai-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vendor-ai-reviewReview vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency.
Vendor AI Review is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Use when user says "review this AI agreement", "check OpenAI terms", "what did we agree to with [vendor]", "vendor sent an AI addendum", "is this AI contract okay", or attaches vendor AI terms.
Its SKILL.md is about 5.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance. It works with OpenAI. The repository describes itself as: A suite of plugins for legal workflows. The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vendor AI Review loads about 5.2k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 2,600 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 2,600 words, ~5,177 tokens.
.claude/skills/vendor-ai-review/SKILL.md (or your agent's skills folder).~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. Confirm vendor governance positions are populated — if not, stop and direct to setup.~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md./ai-governance-legal:vendor-ai-review openai-enterprise-agreement.pdfMatter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /ai-governance-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.
Vendor AI terms are where your governance positions actually get tested. The cold-start interview captures what you want. This skill checks what you agreed to — and flags the gaps between those two things.
The direction here is always the same: we are the deployer or buyer reviewing the vendor's terms. This is the opposite posture from the DPA review controller/processor question — there's no flip.
What varies is the input:
When there's a DPA already in place, this review complements it — it's not a substitute. The DPA governs data protection obligations; the AI terms govern model-specific rights and risks. Both need to be reviewed.
Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → ## Vendor AI governance. Also read ## AI policy commitments
— vendor terms can't be consistent with a use restriction our own policy imposes if
we've agreed to something different.
If ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md contains [PLACEHOLDER], surface this bounce:
I notice you haven't configured your practice profile yet — that's how I tailor vendor governance positions to your practice.
Two choices:
- Run
/ai-governance-legal:cold-start-interview(2 minutes) to configure your profile, then I'll review tailored to YOUR positions.- Say "provisional" and I'll review against generic defaults — US jurisdiction, middle risk appetite, lawyer role, no playbook — and tag every output
[PROVISIONAL — configure your profile for tailored output]so you can see what I do before committing.
If the user says "provisional," run the vendor AI review normally using these generic defaults: middle risk appetite, lawyer role, US jurisdiction, no playbook (flag all common vendor-AI risks from first principles rather than matching to configured positions). Tag the reviewer note and every finding block with [PROVISIONAL]. At the end of the output, append:
"That was a generic run against default assumptions. Run
/ai-governance-legal:cold-start-interviewto get output calibrated to YOUR practice — your vendor governance positions, your jurisdiction, your risk appetite. 2 minutes."
If the user hasn't shared the actual vendor terms, ask:
"Can you share the vendor's AI terms? The most useful thing is the actual contract language — the AI addendum if there is one, or the main agreement with AI provisions highlighted. An acceptable use policy alone won't tell us what the vendor can do with our inputs; it only tells us what we're allowed to do."
If they share an acceptable use policy only:
"This is the acceptable use policy — it tells us what we can't do with the vendor's AI. That's useful context, but it doesn't address the commercial terms: whether the vendor can train on our data, what their liability is for AI errors, whether they notify us when the model changes. Do you have the service agreement or AI addendum?"
Review each term below. For each, extract what the vendor's contract actually says and compare it against the position in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → ## Vendor AI governance (standard / acceptable fallback / automatic no). The default positions come from the team's playbook, not from this skill.
| Term | What to look for |
|---|---|
| Training on our data | Does the vendor use our inputs to train, fine-tune, or improve models? Is there an explicit opt-out or prohibition? Is training opt-in or opt-out by default? |
| Confidentiality of inputs | Are our prompts, documents, and data confidential? Any "quality review" or human-review carveouts that would let vendor staff read inputs? |
| Model changes | Any notice obligation for material changes to the model? Version pinning available? |
| Output ownership / IP | Who owns AI-generated content? Any license-back to the vendor on outputs? Any IP indemnity? |
| Liability for outputs | Does the vendor accept any liability if the AI produces harmful, incorrect, or infringing outputs? Cap structure? Carve-outs? |
| Incident notification | How and when are we notified if the AI system fails, is compromised, or produces systematic errors affecting us? |
| Human review rights | Can we require human review of outputs in specific cases? Can we appeal or dispute an AI decision? |
| Use restrictions | What are we prohibited from doing? Does it match what we actually want to use the tool for? Any definitional terms (e.g., "automated decision-making") that could sweep in our intended uses? |
| Audit / auditability | SOC 2, third-party audits, bias testing results — any audit rights? |
| Subprocessors / model providers | Does the vendor use sub-vendors for the model? Are they disclosed? Whose terms govern? |
| Data residency | Where is our data processed? Where does it go for inference? |
| Term and termination | What happens to our data when we terminate? Deletion timelines? |
| Stacked-vendor accountability | Is this vendor the model provider (e.g., Anthropic, OpenAI, Google, Meta), or are they a deployer of someone else's model (e.g., a SaaS wrapper of Claude, ChatGPT, or Gemini) or a reseller of infrastructure-hosted foundation models (Anthropic-on-Bedrock, Claude-on-Vertex, OpenAI-on-Azure)? If the latter: there are TWO vendors' terms in play — the one you're reviewing, plus the upstream model provider's terms. Identify (a) whose terms govern training on inputs, retention, and safety, (b) who is contractually liable for model behavior, and (c) whether each upstream commitment (e.g., "no training on inputs") is flowed down to you, or remains between the vendor and the upstream provider only. Flag any clause where one party disclaims responsibility for the other (e.g., "Anthropic is not responsible for Bedrock or any other services it receives from AWS"; "Azure disclaims responsibility for OpenAI model outputs") and whether the counter-party's contract closes the gap. Do not review the two contracts in isolation. |
If ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md doesn't define a position for a term on this list, ask: "Your playbook doesn't cover [term]. What's your default position, your acceptable fallback, and your automatic no? I'll add it to ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md so the next review is consistent."
For each term above, compare what we found to the positions in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.
Output format for each term:
[Term name] 🟢 / 🟡 / 🟠 / 🔴 Vendor says: [summary of what the contract actually says] Our position: [from
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md] Gap: [specific delta — or "Aligned"] Proposed fix: [specific redline language, or "escalate — outside fallback"]
Use the severity ratings consistently (calibrated against ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md positions):
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.If the vendor has a DPA but no AI addendum:
"There's a DPA in place but no AI-specific addendum. The DPA covers data protection obligations but doesn't address: training on our data, model change notification, liability for AI outputs, or incident notification for AI system failures.
For a [Standard / Elevated / High] tier use case, this gap is [acceptable at Standard tier / a blocker at Elevated or High tier]. Recommend requesting an AI addendum or at minimum negotiating AI-specific terms into the next renewal."
If there are no AI terms at all:
"There are no AI-specific terms in this agreement. The vendor is providing an AI-powered service under general service terms — which means we have no contractual protection on the highest-risk AI governance items (training, liability, model changes). This is a 🔴 for any Elevated or High tier use case."
Cross-check the vendor's terms against our AI policy commitments in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.
Common conflicts:
Flag every mismatch. One of them has to change.
Edit at the smallest possible granularity. A redline is a negotiation artifact, not a rewrite. Wholesale clause replacement signals "we threw out your drafting" — it's aggressive, it forces the counterparty to re-read the whole clause, and it discards the parts of their drafting that were fine. Surgical redlines — strike a word, insert a phrase, restructure a subclause — signal "we have specific asks" and are faster to read, understand, and accept.
Default to the smallest edit that achieves the playbook position:
When in doubt, smaller. A client who receives a surgical redline trusts that you read carefully. A client who receives a wholesale replacement wonders whether you read at all.
Before recommending signature of a vendor AI agreement (the version the company will execute): Read ## Who's using this in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If the Role is Non-lawyer:
Signing this vendor AI agreement has legal consequences. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:
[Generate a 1-page summary: the vendor and the use case, the key terms reviewed (data use, liability, auditability, model change, human review), where vendor positions diverge from policy, what's being accepted, what could go wrong, what to ask the attorney.]
If you need to find an attorney, solicitor, barrister, or other authorised legal professional: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent).
Do not proceed past this gate without an explicit yes. Review/redline drafts for attorney consideration do not require the gate — signature does.
[WORK-PRODUCT HEADER — per plugin config ## Outputs — differs by role; see `## Who's using this`]
*This review is derived from vendor contract terms that are typically confidential under NDA, and it may itself be privileged. It inherits the source's confidentiality and privilege status. Distributing it beyond the privilege circle (e.g., forwarding to the vendor, sharing in an open channel) can waive privilege and breach the NDA. Mark, store, and route accordingly.*
# Vendor AI Review: [Vendor Name]
**Document reviewed:** [AI addendum / main agreement AI provisions / ToS]
**Reviewed:** [date]
**Use case(s):** [what we're deploying this vendor's AI for]
**Governance tier:** [Standard / Elevated / High]
---
## Bottom line
[Two sentences. Can we deploy under these terms? What has to change first?]
**Issues:** [N]🔴 [N]🟠 [N]🟡 [N]🟢
---
## Term-by-term
[For each term above — vendor position, our position, gap, severity, proposed fix]
---
## AI addendum status
[Present / Absent — and what that means for this deployment]
---
## AI policy consistency
[🟢 Consistent | 🟡 Flags: list]
---
## Recommended redlines
[Consolidated draft redlines. Review with counsel before sending externally. For critical
issues where no fallback exists, flag for escalation rather than proposing language.]
---
## If they won't move
[For each 🔴 and 🟠: the fallback from `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`, or "escalate — outside fallback"
and routing per escalation table]The training-on-data clause is the one most people miss. Vendor AI terms have historically varied widely on whether API inputs can be used to train or improve models — some vendors permit it by default, others prohibit it, and many have changed their position over time. Do not assume any particular vendor's current stance without reading the specific agreement in front of you. This is almost always the most important term for any company with confidential or sensitive data, and it must be confirmed in writing, not assumed from reputation or prior experience.
Map the AI stack. Modern AI deployments are layered. Before reviewing terms, map the layers:
Ask: "Walk me through the stack — what does [SaaS tool] use under the hood? Is it built on a cloud AI service? Does it call a model provider directly or through a gateway? Does it use a hosted knowledge base?" Then review terms at EACH layer, not just the top.
Each handoff between layers is a flow-down risk. A commitment at layer 1 ("we won't train on your data") means nothing if layer 3's terms say otherwise and layer 1 never flowed the commitment down.
Flow-down test. For each flagged stacked-vendor term — especially training-on-data, data retention, subprocessor changes, and liability — don't just flag "check upstream terms." DO THE CHECK:
"Add to §[X]: Provider shall ensure that any third-party model providers, infrastructure providers, or subprocessors used in delivering the Services are bound by obligations with respect to [Customer Data / AI training / data retention / confidentiality] no less protective than those set forth in this Agreement, and shall be responsible for any breach of this Agreement caused by such third parties."
"Escalate and check upstream" is where compliance dies. Produce the test and the redline.
Acceptable use policies flip the frame. AUPs tell you what you can't do; they don't tell you what the vendor can do. Don't let a clean AUP review substitute for reading the data use and liability terms.
Renewals are leverage points. If the current agreement is unfavorable and the vendor won't renegotiate mid-term, document the gaps now and flag them for the renewal. Flag to procurement: "This renewal should not close without AI addendum addressing [list]."
Builder context adds a layer. If the company is a builder using a vendor's model as a foundation, the vendor's terms also govern what the company can offer its own customers. Some terms prohibit certain downstream uses. Check use restrictions against the product roadmap, not just current internal workflows.
End with the next-steps decision tree per CLAUDE.md ## Outputs. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.
/privacy-legal:dpa-review, if the plugin is installed, for that.~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in ai-governance-legal/skills/vendor-ai-review of anthropics/claude-for-legal.
Open the folder on GitHubat commit 4a6c651
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.
Vendor AI Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vendor AI Review this skillanthropics/claude-for-legal | 9.6k | 2 repos | ~5.2k | Automated safety check: Pass | Apache-2.0 | |
| Nla Createinternet-court/internet-court-skill | 6.6k | 1 repos | ~915 | Automated safety check: Pass | MIT | |
| Tw Formal WritingImbad0202/tw-formal-writing | 179 | — | ~1k | Automated safety check: Pass | MIT | |
| China AI Compliance AuditjnMetaCode/shellward | 140 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Scholar Ethicsjoshzyj/open-scholar-skill | 168 | — | ~9.6k | Automated safety check: Pass | Custom licence | |
| Privilege Sentinellawve-ai/awesome-legal-skills | 847 | — | ~1.4k | Automated safety check: Pass | Custom licence |
internet-court/internet-court-skill
Create a Natural Language Agreement escrow on-chain. An agent skill from internet-court/internet-court-skill.
Imbad0202/tw-formal-writing
台灣正式文件撰寫助手 — 涵蓋政府公文、政府機關其他文件、法律文件、人民對政府文書四類中文正式文件的撰寫(不含學術論文、商業文書、私人書信等,見下方排除清單)。
jnMetaCode/shellward
按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…
joshzyj/open-scholar-skill
Research ethics toolkit for social scientists. An agent skill from joshzyj/open-scholar-skill.
lawve-ai/awesome-legal-skills
Pre-flight privilege and work-product check for legal AI prompts.
lawve-ai/awesome-legal-skills
Contract intelligence and contract operations workflow skill for Claude and Codex.
anthropics/claude-for-legal
Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.
anthropics/claude-for-legal
Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.
anthropics/claude-for-legal
Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.
anthropics/claude-for-legal
Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.
anthropics/claude-for-legal
Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.
anthropics/claude-for-legal
Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.
Works with
Categories
Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Vendor AI Review is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency.
Vendor AI Review fits situations like: user says review this AI agreement; check OpenAI terms; what did we agree to with [vendor]; vendor sent an AI addendum.
Run `npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a claude-code`. Or copy the skill folder (ai-governance-legal/skills/vendor-ai-review in anthropics/claude-for-legal) into .claude/skills/vendor-ai-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a codex`. Or copy the skill folder (ai-governance-legal/skills/vendor-ai-review in anthropics/claude-for-legal) into .agents/skills/vendor-ai-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-ai-review, .gemini/skills/vendor-ai-review, .github/skills/vendor-ai-review and .opencode/skills/vendor-ai-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Vendor AI Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vendor AI Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vendor AI Review: Nla Create (internet-court/internet-court-skill, 6.6k stars), Tw Formal Writing (Imbad0202/tw-formal-writing, 179 stars), China AI Compliance Audit (jnMetaCode/shellward, 140 stars) and Scholar Ethics (joshzyj/open-scholar-skill, 168 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,633 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.
Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.