Official agent skill

Vendor AI Review

by anthropics in anthropics/claude-for-legal

Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency.

OfficialApache-2.0Auto-check passedLegal & Compliance

Install Vendor AI Review

skills CLI
$ npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anthropics/claude-for-legal vendor-ai-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance-legal/skills/vendor-ai-review .claude/skills/vendor-ai-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-ai-review
GitHub stars
9.6k
Used in
2 other repos
Token cost
~5.2k tokens
SKILL.md length
2,600 words
Files
1
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency.

  • Works in 7 steps: Read… → Use the framework below. → Confirm document type (AI addendum /… → …
  • User says review this AI agreement
  • SKILL.md covers Matter context, Purpose, Load the playbook and Before reading the document, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vendor AI Review is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Use when user says "review this AI agreement", "check OpenAI terms", "what did we agree to with [vendor]", "vendor sent an AI addendum", "is this AI contract okay", or attaches vendor AI terms.

Its SKILL.md is about 5.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance. It works with OpenAI. The repository describes itself as: A suite of plugins for legal workflows. The licence is Apache-2.0.

When your agent uses it

  • User says review this AI agreement
  • Check OpenAI terms
  • What did we agree to with [vendor]
  • Vendor sent an AI addendum

Example prompts

  • “review this AI agreement”
  • “check OpenAI terms”
  • “what did we agree to with [vendor]”
  • “/vendor-ai-review”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. Confirm vendor governance positions are populated — if not…
  2. Use the framework below.
  3. Confirm document type (AI addendum / main agreement AI provisions / ToS). If only an AUP was provided, ask for the full terms.
  4. Term-by-term review: training on data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review…
  5. AI addendum gap check if DPA exists but no AI addendum.
  6. AI policy consistency diff vs. ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.
  7. Output: bottom line, term-by-term, recommended redlines, if-they-won't-move routing.

What it can do on your machine

Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor AI Review loads about 5.2k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 2,600 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 2,600 words, ~5,177 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-ai-review/SKILL.md (or your agent's skills folder).
name
vendor-ai-review
description
Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Use when user says "review this AI agreement", "check OpenAI terms", "what did we agree to with [vendor]", "vendor sent an AI addendum", "is this AI contract okay", or attaches vendor AI terms.
argument-hint
[vendor name, or attach the contract]

/vendor-ai-review

  1. Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. Confirm vendor governance positions are populated — if not, stop and direct to setup.
  2. Use the framework below.
  3. Confirm document type (AI addendum / main agreement AI provisions / ToS). If only an AUP was provided, ask for the full terms.
  4. Term-by-term review: training on data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review rights, use restrictions, audit rights.
  5. AI addendum gap check if DPA exists but no AI addendum.
  6. AI policy consistency diff vs. ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.
  7. Output: bottom line, term-by-term, recommended redlines, if-they-won't-move routing.
/ai-governance-legal:vendor-ai-review openai-enterprise-agreement.pdf

Matter context

Matter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /ai-governance-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.


Purpose

Vendor AI terms are where your governance positions actually get tested. The cold-start interview captures what you want. This skill checks what you agreed to — and flags the gaps between those two things.

The direction here is always the same: we are the deployer or buyer reviewing the vendor's terms. This is the opposite posture from the DPA review controller/processor question — there's no flip.

What varies is the input:

  • A standalone AI agreement or AI addendum (most structured)
  • A vendor's universal terms of service with AI provisions embedded (often buried)
  • An acceptable use policy (tells you what you can't do; says nothing about what the vendor can do with your data or outputs)
  • A combination — master agreement + DPA + AI addendum (common for serious enterprise AI vendors)

When there's a DPA already in place, this review complements it — it's not a substitute. The DPA governs data protection obligations; the AI terms govern model-specific rights and risks. Both need to be reviewed.


Load the playbook

Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → ## Vendor AI governance. Also read ## AI policy commitments — vendor terms can't be consistent with a use restriction our own policy imposes if we've agreed to something different.

If ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md contains [PLACEHOLDER], surface this bounce:

I notice you haven't configured your practice profile yet — that's how I tailor vendor governance positions to your practice.

Two choices:

  • Run /ai-governance-legal:cold-start-interview (2 minutes) to configure your profile, then I'll review tailored to YOUR positions.
  • Say "provisional" and I'll review against generic defaults — US jurisdiction, middle risk appetite, lawyer role, no playbook — and tag every output [PROVISIONAL — configure your profile for tailored output] so you can see what I do before committing.
Provisional mode

If the user says "provisional," run the vendor AI review normally using these generic defaults: middle risk appetite, lawyer role, US jurisdiction, no playbook (flag all common vendor-AI risks from first principles rather than matching to configured positions). Tag the reviewer note and every finding block with [PROVISIONAL]. At the end of the output, append:

"That was a generic run against default assumptions. Run /ai-governance-legal:cold-start-interview to get output calibrated to YOUR practice — your vendor governance positions, your jurisdiction, your risk appetite. 2 minutes."


Before reading the document

If the user hasn't shared the actual vendor terms, ask:

"Can you share the vendor's AI terms? The most useful thing is the actual contract language — the AI addendum if there is one, or the main agreement with AI provisions highlighted. An acceptable use policy alone won't tell us what the vendor can do with our inputs; it only tells us what we're allowed to do."

If they share an acceptable use policy only:

"This is the acceptable use policy — it tells us what we can't do with the vendor's AI. That's useful context, but it doesn't address the commercial terms: whether the vendor can train on our data, what their liability is for AI errors, whether they notify us when the model changes. Do you have the service agreement or AI addendum?"


The term-by-term review

Core AI-specific terms (check every vendor AI agreement)

Review each term below. For each, extract what the vendor's contract actually says and compare it against the position in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → ## Vendor AI governance (standard / acceptable fallback / automatic no). The default positions come from the team's playbook, not from this skill.

TermWhat to look for
Training on our dataDoes the vendor use our inputs to train, fine-tune, or improve models? Is there an explicit opt-out or prohibition? Is training opt-in or opt-out by default?
Confidentiality of inputsAre our prompts, documents, and data confidential? Any "quality review" or human-review carveouts that would let vendor staff read inputs?
Model changesAny notice obligation for material changes to the model? Version pinning available?
Output ownership / IPWho owns AI-generated content? Any license-back to the vendor on outputs? Any IP indemnity?
Liability for outputsDoes the vendor accept any liability if the AI produces harmful, incorrect, or infringing outputs? Cap structure? Carve-outs?
Incident notificationHow and when are we notified if the AI system fails, is compromised, or produces systematic errors affecting us?
Human review rightsCan we require human review of outputs in specific cases? Can we appeal or dispute an AI decision?
Use restrictionsWhat are we prohibited from doing? Does it match what we actually want to use the tool for? Any definitional terms (e.g., "automated decision-making") that could sweep in our intended uses?
Audit / auditabilitySOC 2, third-party audits, bias testing results — any audit rights?
Subprocessors / model providersDoes the vendor use sub-vendors for the model? Are they disclosed? Whose terms govern?
Data residencyWhere is our data processed? Where does it go for inference?
Term and terminationWhat happens to our data when we terminate? Deletion timelines?
Stacked-vendor accountabilityIs this vendor the model provider (e.g., Anthropic, OpenAI, Google, Meta), or are they a deployer of someone else's model (e.g., a SaaS wrapper of Claude, ChatGPT, or Gemini) or a reseller of infrastructure-hosted foundation models (Anthropic-on-Bedrock, Claude-on-Vertex, OpenAI-on-Azure)? If the latter: there are TWO vendors' terms in play — the one you're reviewing, plus the upstream model provider's terms. Identify (a) whose terms govern training on inputs, retention, and safety, (b) who is contractually liable for model behavior, and (c) whether each upstream commitment (e.g., "no training on inputs") is flowed down to you, or remains between the vendor and the upstream provider only. Flag any clause where one party disclaims responsibility for the other (e.g., "Anthropic is not responsible for Bedrock or any other services it receives from AWS"; "Azure disclaims responsibility for OpenAI model outputs") and whether the counter-party's contract closes the gap. Do not review the two contracts in isolation.

If ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md doesn't define a position for a term on this list, ask: "Your playbook doesn't cover [term]. What's your default position, your acceptable fallback, and your automatic no? I'll add it to ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md so the next review is consistent."


Playbook comparison

For each term above, compare what we found to the positions in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.

Output format for each term:

[Term name] 🟢 / 🟡 / 🟠 / 🔴 Vendor says: [summary of what the contract actually says] Our position: [from ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md] Gap: [specific delta — or "Aligned"] Proposed fix: [specific redline language, or "escalate — outside fallback"]

Use the severity ratings consistently (calibrated against ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md positions):

  • 🟢 Aligned — at or better than the standard position in the playbook.
  • 🟡 Note — within fallback but worse than standard; flag for awareness, not a blocker.
  • 🟠 Significant — outside standard position but within fallback; needs redline before signing.
  • 🔴 Critical — outside fallback; deployment should not proceed without resolution. Escalate per ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.

AI addendum gap check

If the vendor has a DPA but no AI addendum:

"There's a DPA in place but no AI-specific addendum. The DPA covers data protection obligations but doesn't address: training on our data, model change notification, liability for AI outputs, or incident notification for AI system failures.

For a [Standard / Elevated / High] tier use case, this gap is [acceptable at Standard tier / a blocker at Elevated or High tier]. Recommend requesting an AI addendum or at minimum negotiating AI-specific terms into the next renewal."

If there are no AI terms at all:

"There are no AI-specific terms in this agreement. The vendor is providing an AI-powered service under general service terms — which means we have no contractual protection on the highest-risk AI governance items (training, liability, model changes). This is a 🔴 for any Elevated or High tier use case."


AI policy consistency check

Cross-check the vendor's terms against our AI policy commitments in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.

Common conflicts:

  • Our policy prohibits vendor training on our data — the vendor's terms permit it by default. (Contract needs explicit prohibition or opt-out confirmation.)
  • Our policy requires human review for certain use cases — vendor's terms say AI outputs are final. (Workflow needs to impose the human step, not the vendor terms.)
  • Our approved vendor list doesn't include this vendor — or blocklist does.
  • Our policy requires disclosure to affected parties — vendor's terms impose a confidentiality obligation on AI system capabilities that would prevent disclosure.

Flag every mismatch. One of them has to change.


Show full SKILL.md (1,085 more words)Show less

Redline granularity

Edit at the smallest possible granularity. A redline is a negotiation artifact, not a rewrite. Wholesale clause replacement signals "we threw out your drafting" — it's aggressive, it forces the counterparty to re-read the whole clause, and it discards the parts of their drafting that were fine. Surgical redlines — strike a word, insert a phrase, restructure a subclause — signal "we have specific asks" and are faster to read, understand, and accept.

Default to the smallest edit that achieves the playbook position:

  • Replace a word before a phrase. ("twelve (12)" → "twenty-four (24)")
  • Replace a phrase before a sentence. ("paid by the Buyer" → "paid and payable by the Buyer")
  • Restructure a subclause before replacing the sentence. (Add "(a)" and "(b)" to split a compound condition.)
  • Replace a sentence before replacing the clause.
  • Only replace a whole clause when the counterparty's version is so far from your position that surgical edits would be harder to read than a fresh draft — and when you do, say so in the transmittal: "We've replaced §8.2 rather than marking it up because the changes were extensive. Happy to walk you through the delta."

When in doubt, smaller. A client who receives a surgical redline trusts that you read carefully. A client who receives a wholesale replacement wonders whether you read at all.

Output

Before recommending signature of a vendor AI agreement (the version the company will execute): Read ## Who's using this in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If the Role is Non-lawyer:

Signing this vendor AI agreement has legal consequences. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:

[Generate a 1-page summary: the vendor and the use case, the key terms reviewed (data use, liability, auditability, model change, human review), where vendor positions diverge from policy, what's being accepted, what could go wrong, what to ask the attorney.]

If you need to find an attorney, solicitor, barrister, or other authorised legal professional: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent).

Do not proceed past this gate without an explicit yes. Review/redline drafts for attorney consideration do not require the gate — signature does.

markdown
[WORK-PRODUCT HEADER — per plugin config ## Outputs — differs by role; see `## Who's using this`]

*This review is derived from vendor contract terms that are typically confidential under NDA, and it may itself be privileged. It inherits the source's confidentiality and privilege status. Distributing it beyond the privilege circle (e.g., forwarding to the vendor, sharing in an open channel) can waive privilege and breach the NDA. Mark, store, and route accordingly.*

# Vendor AI Review: [Vendor Name]

**Document reviewed:** [AI addendum / main agreement AI provisions / ToS]
**Reviewed:** [date]
**Use case(s):** [what we're deploying this vendor's AI for]
**Governance tier:** [Standard / Elevated / High]

---

## Bottom line

[Two sentences. Can we deploy under these terms? What has to change first?]

**Issues:** [N]🔴 [N]🟠 [N]🟡 [N]🟢

---

## Term-by-term

[For each term above — vendor position, our position, gap, severity, proposed fix]

---

## AI addendum status

[Present / Absent — and what that means for this deployment]

---

## AI policy consistency

[🟢 Consistent | 🟡 Flags: list]

---

## Recommended redlines

[Consolidated draft redlines. Review with counsel before sending externally. For critical
issues where no fallback exists, flag for escalation rather than proposing language.]

---

## If they won't move

[For each 🔴 and 🟠: the fallback from `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`, or "escalate — outside fallback"
and routing per escalation table]

Practical notes

The training-on-data clause is the one most people miss. Vendor AI terms have historically varied widely on whether API inputs can be used to train or improve models — some vendors permit it by default, others prohibit it, and many have changed their position over time. Do not assume any particular vendor's current stance without reading the specific agreement in front of you. This is almost always the most important term for any company with confidential or sensitive data, and it must be confirmed in writing, not assumed from reputation or prior experience.

Map the AI stack. Modern AI deployments are layered. Before reviewing terms, map the layers:

  1. End-user SaaS application (e.g., a legal tech tool, a CRM with AI scoring, a document assistant) — the tool your org signs up for
  2. API gateway / orchestration layer (e.g., Azure OpenAI Service, AWS Bedrock, Google Vertex, LangChain-hosted) — often invisible, always has its own terms
  3. Model provider (e.g., Anthropic, OpenAI, Google, Meta) — the LLM
  4. Hosted knowledge base / RAG source (e.g., a vector database, a third-party data corpus, a retrieval service) — the data Claude reads from
  5. Additional subprocessors — analytics, logging, fine-tuning partners

Ask: "Walk me through the stack — what does [SaaS tool] use under the hood? Is it built on a cloud AI service? Does it call a model provider directly or through a gateway? Does it use a hosted knowledge base?" Then review terms at EACH layer, not just the top.

Each handoff between layers is a flow-down risk. A commitment at layer 1 ("we won't train on your data") means nothing if layer 3's terms say otherwise and layer 1 never flowed the commitment down.

Flow-down test. For each flagged stacked-vendor term — especially training-on-data, data retention, subprocessor changes, and liability — don't just flag "check upstream terms." DO THE CHECK:

  1. Search the contract for flow-down language. Look for: "subprocessor obligations no less protective than," "flow-down of data commitments," "back-to-back terms," "Provider shall ensure that its subprocessors are bound by," "equivalent obligations."
  2. If present: Quote it, verify it covers the specific flagged term, and flag whether it's enforceable (who can enforce it — you, or only the intermediate vendor?).
  3. If absent: Produce a specific redline requiring it:

    "Add to §[X]: Provider shall ensure that any third-party model providers, infrastructure providers, or subprocessors used in delivering the Services are bound by obligations with respect to [Customer Data / AI training / data retention / confidentiality] no less protective than those set forth in this Agreement, and shall be responsible for any breach of this Agreement caused by such third parties."

  4. Flag the gap with a severity: 🔴 if the term is training-on-data or liability and there's no flow-down; 🟡 if the term is less sensitive or there's partial flow-down.

"Escalate and check upstream" is where compliance dies. Produce the test and the redline.

Acceptable use policies flip the frame. AUPs tell you what you can't do; they don't tell you what the vendor can do. Don't let a clean AUP review substitute for reading the data use and liability terms.

Renewals are leverage points. If the current agreement is unfavorable and the vendor won't renegotiate mid-term, document the gaps now and flag them for the renewal. Flag to procurement: "This renewal should not close without AI addendum addressing [list]."

Builder context adds a layer. If the company is a builder using a vendor's model as a foundation, the vendor's terms also govern what the company can offer its own customers. Some terms prohibit certain downstream uses. Check use restrictions against the product roadmap, not just current internal workflows.


Close with the next-steps decision tree

End with the next-steps decision tree per CLAUDE.md ## Outputs. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.

What this skill does not do

  • It doesn't review the DPA provisions of the same agreement — run /privacy-legal:dpa-review, if the plugin is installed, for that.
  • It doesn't decide whether to accept terms outside the fallbacks. It routes those per the escalation table in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.
  • It doesn't evaluate vendor security posture beyond what's in the agreement — that's a security team function.

© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in ai-governance-legal/skills/vendor-ai-review of anthropics/claude-for-legal.

Open the folder on GitHubat commit 4a6c651

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Vendor AI Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor AI Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor AI Review this skillanthropics/claude-for-legal9.6k2 repos~5.2kAutomated safety check: PassApache-2.0
Nla Createinternet-court/internet-court-skill6.6k1 repos~915Automated safety check: PassMIT
Tw Formal WritingImbad0202/tw-formal-writing179—~1kAutomated safety check: PassMIT
China AI Compliance AuditjnMetaCode/shellward140—~1.1kAutomated safety check: PassApache-2.0
Scholar Ethicsjoshzyj/open-scholar-skill168—~9.6kAutomated safety check: PassCustom licence
Privilege Sentinellawve-ai/awesome-legal-skills847—~1.4kAutomated safety check: PassCustom licence

Similar skills

  • Nla Create

    internet-court/internet-court-skill

    Create a Natural Language Agreement escrow on-chain. An agent skill from internet-court/internet-court-skill.

    6.6k GitHub starsUsed in 1 repo~915 tokens
    Legal & ComplianceAuto-check passed
  • Tw Formal Writing

    Imbad0202/tw-formal-writing

    台灣正式文件撰寫助手 — 涵蓋政府公文、政府機關其他文件、法律文件、人民對政府文書四類中文正式文件的撰寫(不含學術論文、商業文書、私人書信等,見下方排除清單)。

    179 GitHub stars~1k tokensUpdated 16 days ago
    Legal & ComplianceAuto-check passed
  • China AI Compliance Audit

    jnMetaCode/shellward

    按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…

    140 GitHub stars~1.1k tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Scholar Ethics

    joshzyj/open-scholar-skill

    Research ethics toolkit for social scientists. An agent skill from joshzyj/open-scholar-skill.

    168 GitHub stars~9.6k tokensUpdated 22 days ago
    Legal & ComplianceAuto-check passed
  • Privilege Sentinel

    lawve-ai/awesome-legal-skills

    Pre-flight privilege and work-product check for legal AI prompts.

    847 GitHub stars~1.4k tokensUpdated 8 days ago
    Legal & ComplianceAuto-check passed

More from anthropics/claude-for-legal

All 147 skills in this repo
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Supervisor Review Queue

    anthropics/claude-for-legal

    Official

    Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.

    9.6k GitHub starsUsed in 3 repos~1.1k tokens
    Auto-check passed
  • Tabular Document Review

    anthropics/claude-for-legal

    Official

    Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.

    9.6k GitHub starsUsed in 3 repos~4.3k tokens
    Auto-check passed
  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Auto-check passed
  • Legal Skills Registry Browser

    anthropics/claude-for-legal

    Official

    Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.

    9.6k GitHub starsUsed in 2 repos~620 tokens
    Auto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed

Works with

Questions about Vendor AI Review

What does Vendor AI Review do?

Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Vendor AI Review is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency.

When should I use Vendor AI Review?

Vendor AI Review fits situations like: user says review this AI agreement; check OpenAI terms; what did we agree to with [vendor]; vendor sent an AI addendum.

How do I install Vendor AI Review in Claude Code?

Run `npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a claude-code`. Or copy the skill folder (ai-governance-legal/skills/vendor-ai-review in anthropics/claude-for-legal) into .claude/skills/vendor-ai-review in your project. Claude Code loads it when a task matches its description.

How do I install Vendor AI Review in Codex?

Run `npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a codex`. Or copy the skill folder (ai-governance-legal/skills/vendor-ai-review in anthropics/claude-for-legal) into .agents/skills/vendor-ai-review in your project. Codex loads it when a task matches its description.

Can I use Vendor AI Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill vendor-ai-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-ai-review, .gemini/skills/vendor-ai-review, .github/skills/vendor-ai-review and .opencode/skills/vendor-ai-review in your project.

What does Vendor AI Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Vendor AI Review is instructions for the agent only.

Does Vendor AI Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor AI Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vendor AI Review use?

Vendor AI Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor AI Review use?

About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vendor AI Review?

Skills that share tags, products or a category with Vendor AI Review: Nla Create (internet-court/internet-court-skill, 6.6k stars), Tw Formal Writing (Imbad0202/tw-formal-writing, 179 stars), China AI Compliance Audit (jnMetaCode/shellward, 140 stars) and Scholar Ethics (joshzyj/open-scholar-skill, 168 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor AI Review?

anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,633 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.

Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.