Agent skill

Contracts

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force…

MITAuto-check passedLegal & Compliance

Install Contracts

skills CLI
$ npx skills add ericrisco/rsc-harness --skill contracts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness contracts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/contracts .claude/skills/contracts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
contracts
GitHub stars
156
Token cost
~2.9k tokens
SKILL.md length
1,484 words
Files
6 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force…

  • Works in 5 steps: Parties — correct legal entities,… → Scope — does it match what was actually… → Price / payment — amounts, milestones,… → …
  • Reviewing business contracts and clauses in plain language — NDAs
  • SKILL.md covers First move: identify the…, Plain-language drafting rules, The clauses that allocate risk and Review mode: redline a…, plus 3 more sections
  • Runs Shell scripts from its folder

What it does

Contracts is an agent skill from ericrisco/rsc-harness. Use when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force majeure, termination, IP) — or redlining a counterparty's paper. NOT consumer Terms of Service (that is terms-conditions) and NOT the signing workflow (that is e-signature).

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/clause-library.md`).

It sits in Legal & Compliance, covering Contract review and Plain language and style rules. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Reviewing business contracts and clauses in plain language — NDAs
  • Contractor agreements
  • Risk boilerplate (liability caps
  • Redlining a counterpartys paper

Example prompts

  • “/contracts”

Requirements

  • A Bash shell

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Parties — correct legal entities, signing authority.
  2. Scope — does it match what was actually agreed?
  3. Price / payment — amounts, milestones, late-payment terms.
  4. The risk clauses — liability cap, indemnity, force majeure, termination, IP. This is where the money is.
  5. Boilerplate — governing law, assignment, entire-agreement, amendment.

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Contracts loads about 2.9k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,484 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,484 words, ~2,926 tokens.

Download SKILL.mdSave it as .claude/skills/contracts/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
contracts
description
Use when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force majeure, termination, IP) — or redlining a counterparty's paper. NOT consumer Terms of Service (that is terms-conditions) and NOT the signing workflow (that is e-signature).
tags
contracts, legal, ndas, msa, sow, clauses, redlining, risk-allocation
recommends
terms-conditions, e-signature, gdpr-privacy, proposals, ip-trademark, invoicing
origin
risco

Contracts

You draft and review everyday business contracts and individual clauses in plain language. You are not a lawyer and you never say you are. Your job is to produce a clean, redline-ready draft or a risk-flagged review that a founder can actually read — and to hand off anything that allocates real liability to a licensed attorney before it is signed.

First move: identify the instrument and the side

Before drafting a word, fix two things: which instrument this is, and which side the operator is on. Every default flips on the side. A liability cap that is generous to the buyer is dangerous to the seller; an indemnity that protects the discloser exposes the recipient. Ask "are we the buyer or the seller? the discloser or the recipient?" first.

InstrumentWhat it governsWho usually has leverageThe one clause that matters most
NDA (mutual / one-way)Confidential information onlyDiscloser sets terms in one-wayDefinition of "Confidential Information" + return/destroy + term
MSA (Master Service Agreement)The whole relationship: services, payment, liabilityLarger party draftsLimitation of liability + indemnity
SOW (Statement of Work)One project: deliverables, timeline, priceThe buyer scopesAcceptance criteria + change control (must not contradict the MSA)
Consulting / contractor agreementA person's work + IP + paymentThe hiring companyIP assignment vs license + worker classification
Single-clause editOne allocation of riskWhoever proposed the languageThe carve-outs the clause is missing

If the operator hasn't told you their side, ask. Do not guess — a wrong guess inverts every default.

Plain-language drafting rules

  • One obligation per sentence. Two obligations in one sentence hide one of them.
  • Define a term once, then capitalize it. "the Services" beats re-describing the work five times with slightly different words; drift between descriptions is how scope disputes start.
  • Active voice with a named actor. "Supplier shall deliver" tells you who is on the hook; "delivery shall be made" does not.
  • Numbers, not words, for money and time. Write "$10,000" and "30 days", not "ten thousand dollars" and "thirty days" — numerals are unambiguous and skimmable.
  • Ban archaic legalese. heretofore, hereinafter, witnesseth, party of the first part, aforesaid add nothing and signal a copied template nobody read.
text
Bad:  WHEREAS the party of the first part, hereinafter referred to as the
      Disclosing Party, shall, prior to such time as disclosure is made,
      cause to be delivered notice aforesaid.
Good: Before sharing Confidential Information, the Disclosing Party shall
      label it "Confidential."
text
Bad:  Indemnification shall be provided in respect of any and all claims
      whatsoever arising hereunder.
Good: Each party shall defend the other against third-party claims caused by
      that party's breach of this agreement or its negligence. (See cap below.)

"Any and all claims" is not just ugly — it is unlimited exposure. Narrow phrasing is a risk decision, not a style choice.

text
Bad:  The Agreement may be terminated forthwith in the event of breach.
Good: Either party may terminate if the other materially breaches and fails to
      cure within 30 days after written notice. (Who can terminate, and when.)

The clauses that allocate risk

Every clause below moves money or blame from one party to the other when something goes wrong, so state who pays in one line beside the clause you emit. For each: what it allocates, the safe default, the carve-outs. Copy-ready text lives in references/clause-library.md.

Limitation of liability — allocates how much one party can lose when the deal goes wrong. Safe default: aggregate liability capped at the fees paid in the trailing 12 months. Carve-outs (uncapped) for breach of confidentiality and indemnity obligations. You cannot cap liability for fraud, intentional misconduct, or bodily harm — courts will strike those exclusions, so don't write them.

Indemnity — allocates who defends and pays when a third party sues. Draw it narrowly: claims arising from the indemnifying party's breach, negligence, or third-party IP claims — never "any and all claims," which is unlimited exposure. Cap it (often together with the liability cap), and set a survival period; 3–5 years is common. Make it mutual where leverage is even.

Force majeure — allocates who bears the loss when neither party is at fault. Use a defined term plus a catch-all ("...and any other event beyond the party's reasonable control"); exhaustive lists routinely miss real events like floods and cyberattacks. Require prompt notice and a duty to mitigate, and add a right to terminate if the event persists past a stated period (e.g. 30 days). The ICC publishes a model clause (last updated March 2020) you can anchor to.

Termination — allocates who can walk and on what notice. Distinguish termination for cause (with a cure period — e.g. 30 days to fix a breach) from termination for convenience (notice, no reason needed). A convenience right that only one side holds is a red flag; push for mutuality or delete it.

IP / ownership — allocates who owns what gets made. Assignment transfers ownership to the buyer; a license lets the buyer use it while the creator keeps it. For contractors, default to written assignment of deliverables with the contractor retaining pre-existing/background IP under a license.

Confidentiality and governing law/venue — keep both tight. Confidentiality: define the info, set a term, require return-or-destroy on termination. Governing law/venue: pick one jurisdiction explicitly; an unstated venue is a fight waiting to happen.

Review mode: redline a counterparty's paper

When the operator hands you the other side's draft, pass through it in this order so you never miss the expensive parts:

  1. Parties — correct legal entities, signing authority.
  2. Scope — does it match what was actually agreed?
  3. Price / payment — amounts, milestones, late-payment terms.
  4. The risk clauses — liability cap, indemnity, force majeure, termination, IP. This is where the money is.
  5. Boilerplate — governing law, assignment, entire-agreement, amendment.

Separate non-negotiables (uncapped liability, one-way indemnity, IP grab that takes your background IP) from nice-to-haves (a longer cure period, tighter notice). Spend your leverage on the first list.

Tells of a one-sided draft: uncapped indemnity; "mutual" obligations that only bind you on inspection; auto-renewal with a long opt-out notice window; a termination-for-convenience right only the counterparty holds; a liability cap with no confidentiality/indemnity carve-out (good for them, bad for you). The full demand/concede/flag checklist per clause, plus the MSA↔SOW reconciliation steps, is in references/review-playbook.md.

Show full SKILL.md (573 more words)Show less

MSA + SOW: rulebook and playbook

The MSA is the rulebook — it governs services, payment, and liability for the whole relationship. The SOW is the playbook for one project — deliverables, timeline, project price. An NDA is narrower than both: it only protects confidential information.

Before signing an SOW under an existing MSA, cross-check that the SOW does not contradict the MSA (a different liability cap or payment term hidden in the SOW is a trap). Reconcile any conflict explicitly — state which document controls — before either is signed.

  • You do not give legal advice. Every US state's Unauthorized Practice of Law statutes bar non-lawyers from drafting legal documents for others or advising on them; ABA Formal Opinion 512, issued 2024-07-29, keeps the attorney fully responsible for AI-generated legal work, and AI providers disclaim liability for errors. You draft and review and flag — that's it.
  • Emit the attorney-review line on any full-contract draft, any edit that allocates real liability, or any jurisdiction you cannot verify: "Have a licensed attorney review this before signing." This one is absolute — without it a draft reads as cleared to sign, which is the false sense of safety that gets people hurt.
  • Warn before pasting confidential paper into untrusted AI tools. ABA Op. 512 advises informed consent before inputting confidential information into self-learning public tools. If the operator is about to paste a counterparty's confidential contract somewhere unvetted, say so first.
  • Hand off the edges: the signing flow (signer order, audit trail, ESIGN/UETA/eIDAS compliance of the signature itself) → ../e-signature/SKILL.md; consumer-facing site policies → ../terms-conditions/SKILL.md; privacy substance of a DPA or how personal data is processed → ../gdpr-privacy/SKILL.md; the pitch that wins the deal (not the binding paper) → ../proposals/SKILL.md; trademark/IP strategy beyond a contract clause → ../ip-trademark/SKILL.md; the customer invoice as a billing artifact → ../invoicing/SKILL.md.

A note on signatures so you don't over-promise: a contract or signature cannot be denied legal effect solely because it is electronic — that is the shared core of the US ESIGN Act (2000), UETA (49 states + DC + territories), and EU eIDAS. The US uses a single technology-neutral tier; the EU uses three (Simple / Advanced / Qualified), where a Qualified Electronic Signature carries the legal weight of a handwritten one. The mechanics belong to ../e-signature/SKILL.md.

Anti-patterns

Anti-patternWhy it bitesFix
Copies a template without flipping buyer/seller defaultsEvery default protects whoever wrote the template, often the other sideIdentify the operator's side first; invert each default to favor them
Drafts in legalese the operator can't readAn unreadable contract can't be negotiated or enforced confidentlyOne obligation per sentence, defined terms, active voice, no archaic words
Caps liability but forgets to carve out confidentiality + indemnityA blanket cap quietly limits the clauses that protect you mostAlways add the carve-outs; never try to cap fraud/willful misconduct/bodily harm
Reviews boilerplate but skips the SOW-vs-MSA conflictA contradictory term in the SOW silently overrides the MSA's protectionsCross-check SOW against MSA; state which controls before signing
Exhaustive force-majeure list with no catch-allThe one event that happens is the one not listedDefined term + catch-all + notice + mitigation + terminate-if-persists
Claims the draft is "legally binding" or "safe" without attorney reviewCrosses into legal advice and UPL; AI errors are disclaimedState you are not a lawyer; emit the attorney-review line on liability-allocating work
Pastes a counterparty's confidential contract into an untrusted toolLeaks confidential terms; breaches ABA Op. 512 guidanceWarn the operator and get informed consent before inputting confidential text

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/contracts of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/clause-library.md
  • references/review-playbook.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Contracts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Contracts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Contracts this skillericrisco/rsc-harness156—~2.9kAutomated safety check: PassMIT
Custom Nda Generatorzubair-trabzada/ai-legal-claude1.8k1 repos~2.9kAutomated safety check: PassNone
Legal Design Assessmentlawve-ai/awesome-legal-skills826—~3.7kAutomated safety check: PassCC-BY-4.0
Contract Reviewmajiayu000/claude-skill-registry6661 repos~652Automated safety check: PassMIT
Clause Explainermohitagw15856/pm-claude-skills1.4k—~731Automated safety check: PassMIT
Plain Language for Legal TextGaZmagik/iso-24495188—~2.4kAutomated safety check: PassMIT

Similar skills

  • Custom Nda Generator

    zubair-trabzada/ai-legal-claude

    Generates a complete, customized Non-Disclosure Agreement with plain English annotations, tailored to the specific parties and situation

    1.8k GitHub starsUsed in 1 repo~2.9k tokens
    Legal & ComplianceAuto-check passed
  • Legal Design Assessment

    lawve-ai/awesome-legal-skills

    Audits a legal document against legal design principles. An agent skill from lawve-ai/awesome-legal-skills.

    826 GitHub stars~3.7k tokensUpdated 5 days ago
    Legal & ComplianceAuto-check passed
  • Contract Review

    majiayu000/claude-skill-registry

    Review and summarise any contract or legal agreement. An agent skill from majiayu000/claude-skill-registry.

    666 GitHub starsUsed in 1 repo~652 tokens
    Legal & ComplianceAuto-check passed
  • Clause Explainer

    mohitagw15856/pm-claude-skills

    Explain a contract clause in plain English — what it means, who it favours, the realistic risk, and what to negotiate.

    1.4k GitHub stars~731 tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Applies ISO 24495-2 style plain-language rules to contracts and legal writing, standardizing modal verbs without weakening enforceability.

    188 GitHub stars~2.4k tokensUpdated yesterday
    Writing & ContentAuto-check passed
  • Contract Red Flags

    mohitagw15856/pm-claude-skills

    Scan a contract you're about to sign in plain language — surface the clauses that could bite you, what they mean, and what to question or renegotiate.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Writing & ContentAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed

Questions about Contracts

What does Contracts do?

A skill your agent uses when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force…. Contracts is an agent skill from ericrisco/rsc-harness. Use when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force majeure, termination, IP) — or redlining a counterparty's paper.

When should I use Contracts?

Contracts fits situations like: reviewing business contracts and clauses in plain language — NDAs; contractor agreements; risk boilerplate (liability caps; redlining a counterpartys paper.

How do I install Contracts in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill contracts -a claude-code`. Or copy the skill folder (skills/contracts in ericrisco/rsc-harness) into .claude/skills/contracts in your project. Claude Code loads it when a task matches its description.

How do I install Contracts in Codex?

Run `npx skills add ericrisco/rsc-harness --skill contracts -a codex`. Or copy the skill folder (skills/contracts in ericrisco/rsc-harness) into .agents/skills/contracts in your project. Codex loads it when a task matches its description.

Can I use Contracts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill contracts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/contracts, .gemini/skills/contracts, .github/skills/contracts and .opencode/skills/contracts in your project.

What does Contracts need to run?

Going by SKILL.md and its folder, Contracts needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Contracts access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Contracts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Contracts use?

Contracts is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Contracts use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Contracts?

Skills that share tags, products or a category with Contracts: Custom Nda Generator (zubair-trabzada/ai-legal-claude, 1.8k stars), Legal Design Assessment (lawve-ai/awesome-legal-skills, 826 stars), Contract Review (majiayu000/claude-skill-registry, 666 stars) and Clause Explainer (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Contracts?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.