Custom Nda Generator
zubair-trabzada/ai-legal-claude
Generates a complete, customized Non-Disclosure Agreement with plain English annotations, tailored to the specific parties and situation
A skill your agent uses when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force…
$ npx skills add ericrisco/rsc-harness --skill contracts -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness contracts --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/contracts .claude/skills/contracts && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "contracts" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/contracts into .claude/skills/contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "contracts", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/contractsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill contracts -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness contracts --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/contracts .agents/skills/contracts && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "contracts" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/contracts into .agents/skills/contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "contracts", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill contracts -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness contracts --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/contracts .cursor/skills/contracts && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "contracts" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/contracts into .cursor/skills/contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "contracts", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/contracts--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill contracts -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness contracts --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/contracts .gemini/skills/contracts && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "contracts" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/contracts into .gemini/skills/contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "contracts", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness contractsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill contracts -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/contracts .github/skills/contracts && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "contracts" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/contracts into .github/skills/contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "contracts", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill contracts -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness contracts --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/contracts .opencode/skills/contracts && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "contracts" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/contracts into .opencode/skills/contracts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "contracts", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
contractsA skill your agent uses when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force…
Contracts is an agent skill from ericrisco/rsc-harness. Use when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force majeure, termination, IP) — or redlining a counterparty's paper. NOT consumer Terms of Service (that is terms-conditions) and NOT the signing workflow (that is e-signature).
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/clause-library.md`).
It sits in Legal & Compliance, covering Contract review and Plain language and style rules. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Contracts loads about 2.9k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,484 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,484 words, ~2,926 tokens.
.claude/skills/contracts/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.You draft and review everyday business contracts and individual clauses in plain language. You are not a lawyer and you never say you are. Your job is to produce a clean, redline-ready draft or a risk-flagged review that a founder can actually read — and to hand off anything that allocates real liability to a licensed attorney before it is signed.
Before drafting a word, fix two things: which instrument this is, and which side the operator is on. Every default flips on the side. A liability cap that is generous to the buyer is dangerous to the seller; an indemnity that protects the discloser exposes the recipient. Ask "are we the buyer or the seller? the discloser or the recipient?" first.
| Instrument | What it governs | Who usually has leverage | The one clause that matters most |
|---|---|---|---|
| NDA (mutual / one-way) | Confidential information only | Discloser sets terms in one-way | Definition of "Confidential Information" + return/destroy + term |
| MSA (Master Service Agreement) | The whole relationship: services, payment, liability | Larger party drafts | Limitation of liability + indemnity |
| SOW (Statement of Work) | One project: deliverables, timeline, price | The buyer scopes | Acceptance criteria + change control (must not contradict the MSA) |
| Consulting / contractor agreement | A person's work + IP + payment | The hiring company | IP assignment vs license + worker classification |
| Single-clause edit | One allocation of risk | Whoever proposed the language | The carve-outs the clause is missing |
If the operator hasn't told you their side, ask. Do not guess — a wrong guess inverts every default.
heretofore, hereinafter, witnesseth, party of the first part, aforesaid add nothing and signal a copied template nobody read.Bad: WHEREAS the party of the first part, hereinafter referred to as the
Disclosing Party, shall, prior to such time as disclosure is made,
cause to be delivered notice aforesaid.
Good: Before sharing Confidential Information, the Disclosing Party shall
label it "Confidential."Bad: Indemnification shall be provided in respect of any and all claims
whatsoever arising hereunder.
Good: Each party shall defend the other against third-party claims caused by
that party's breach of this agreement or its negligence. (See cap below.)"Any and all claims" is not just ugly — it is unlimited exposure. Narrow phrasing is a risk decision, not a style choice.
Bad: The Agreement may be terminated forthwith in the event of breach.
Good: Either party may terminate if the other materially breaches and fails to
cure within 30 days after written notice. (Who can terminate, and when.)Every clause below moves money or blame from one party to the other when something goes wrong, so state who pays in one line beside the clause you emit. For each: what it allocates, the safe default, the carve-outs. Copy-ready text lives in references/clause-library.md.
Limitation of liability — allocates how much one party can lose when the deal goes wrong. Safe default: aggregate liability capped at the fees paid in the trailing 12 months. Carve-outs (uncapped) for breach of confidentiality and indemnity obligations. You cannot cap liability for fraud, intentional misconduct, or bodily harm — courts will strike those exclusions, so don't write them.
Indemnity — allocates who defends and pays when a third party sues. Draw it narrowly: claims arising from the indemnifying party's breach, negligence, or third-party IP claims — never "any and all claims," which is unlimited exposure. Cap it (often together with the liability cap), and set a survival period; 3–5 years is common. Make it mutual where leverage is even.
Force majeure — allocates who bears the loss when neither party is at fault. Use a defined term plus a catch-all ("...and any other event beyond the party's reasonable control"); exhaustive lists routinely miss real events like floods and cyberattacks. Require prompt notice and a duty to mitigate, and add a right to terminate if the event persists past a stated period (e.g. 30 days). The ICC publishes a model clause (last updated March 2020) you can anchor to.
Termination — allocates who can walk and on what notice. Distinguish termination for cause (with a cure period — e.g. 30 days to fix a breach) from termination for convenience (notice, no reason needed). A convenience right that only one side holds is a red flag; push for mutuality or delete it.
IP / ownership — allocates who owns what gets made. Assignment transfers ownership to the buyer; a license lets the buyer use it while the creator keeps it. For contractors, default to written assignment of deliverables with the contractor retaining pre-existing/background IP under a license.
Confidentiality and governing law/venue — keep both tight. Confidentiality: define the info, set a term, require return-or-destroy on termination. Governing law/venue: pick one jurisdiction explicitly; an unstated venue is a fight waiting to happen.
When the operator hands you the other side's draft, pass through it in this order so you never miss the expensive parts:
Separate non-negotiables (uncapped liability, one-way indemnity, IP grab that takes your background IP) from nice-to-haves (a longer cure period, tighter notice). Spend your leverage on the first list.
Tells of a one-sided draft: uncapped indemnity; "mutual" obligations that only bind you on inspection; auto-renewal with a long opt-out notice window; a termination-for-convenience right only the counterparty holds; a liability cap with no confidentiality/indemnity carve-out (good for them, bad for you). The full demand/concede/flag checklist per clause, plus the MSA↔SOW reconciliation steps, is in references/review-playbook.md.
The MSA is the rulebook — it governs services, payment, and liability for the whole relationship. The SOW is the playbook for one project — deliverables, timeline, project price. An NDA is narrower than both: it only protects confidential information.
Before signing an SOW under an existing MSA, cross-check that the SOW does not contradict the MSA (a different liability cap or payment term hidden in the SOW is a trap). Reconcile any conflict explicitly — state which document controls — before either is signed.
../e-signature/SKILL.md; consumer-facing site policies → ../terms-conditions/SKILL.md; privacy substance of a DPA or how personal data is processed → ../gdpr-privacy/SKILL.md; the pitch that wins the deal (not the binding paper) → ../proposals/SKILL.md; trademark/IP strategy beyond a contract clause → ../ip-trademark/SKILL.md; the customer invoice as a billing artifact → ../invoicing/SKILL.md.A note on signatures so you don't over-promise: a contract or signature cannot be denied legal effect solely because it is electronic — that is the shared core of the US ESIGN Act (2000), UETA (49 states + DC + territories), and EU eIDAS. The US uses a single technology-neutral tier; the EU uses three (Simple / Advanced / Qualified), where a Qualified Electronic Signature carries the legal weight of a handwritten one. The mechanics belong to ../e-signature/SKILL.md.
| Anti-pattern | Why it bites | Fix |
|---|---|---|
| Copies a template without flipping buyer/seller defaults | Every default protects whoever wrote the template, often the other side | Identify the operator's side first; invert each default to favor them |
| Drafts in legalese the operator can't read | An unreadable contract can't be negotiated or enforced confidently | One obligation per sentence, defined terms, active voice, no archaic words |
| Caps liability but forgets to carve out confidentiality + indemnity | A blanket cap quietly limits the clauses that protect you most | Always add the carve-outs; never try to cap fraud/willful misconduct/bodily harm |
| Reviews boilerplate but skips the SOW-vs-MSA conflict | A contradictory term in the SOW silently overrides the MSA's protections | Cross-check SOW against MSA; state which controls before signing |
| Exhaustive force-majeure list with no catch-all | The one event that happens is the one not listed | Defined term + catch-all + notice + mitigation + terminate-if-persists |
| Claims the draft is "legally binding" or "safe" without attorney review | Crosses into legal advice and UPL; AI errors are disclaimed | State you are not a lawyer; emit the attorney-review line on liability-allocating work |
| Pastes a counterparty's confidential contract into an untrusted tool | Leaks confidential terms; breaches ABA Op. 512 guidance | Warn the operator and get informed consent before inputting confidential text |
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in skills/contracts of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
Contracts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Contracts this skillericrisco/rsc-harness | 156 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Custom Nda Generatorzubair-trabzada/ai-legal-claude | 1.8k | 1 repos | ~2.9k | Automated safety check: Pass | None | |
| Legal Design Assessmentlawve-ai/awesome-legal-skills | 826 | — | ~3.7k | Automated safety check: Pass | CC-BY-4.0 | |
| Contract Reviewmajiayu000/claude-skill-registry | 666 | 1 repos | ~652 | Automated safety check: Pass | MIT | |
| Clause Explainermohitagw15856/pm-claude-skills | 1.4k | — | ~731 | Automated safety check: Pass | MIT | |
| Plain Language for Legal TextGaZmagik/iso-24495 | 188 | — | ~2.4k | Automated safety check: Pass | MIT |
zubair-trabzada/ai-legal-claude
Generates a complete, customized Non-Disclosure Agreement with plain English annotations, tailored to the specific parties and situation
lawve-ai/awesome-legal-skills
Audits a legal document against legal design principles. An agent skill from lawve-ai/awesome-legal-skills.
majiayu000/claude-skill-registry
Review and summarise any contract or legal agreement. An agent skill from majiayu000/claude-skill-registry.
mohitagw15856/pm-claude-skills
Explain a contract clause in plain English — what it means, who it favours, the realistic risk, and what to negotiate.
GaZmagik/iso-24495
Applies ISO 24495-2 style plain-language rules to contracts and legal writing, standardizing modal verbs without weakening enforceability.
mohitagw15856/pm-claude-skills
Scan a contract you're about to sign in plain language — surface the clauses that could bite you, what they mean, and what to question or renegotiate.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Categories
A skill your agent uses when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force…. Contracts is an agent skill from ericrisco/rsc-harness. Use when drafting or reviewing business contracts and clauses in plain language — NDAs, MSAs, SOWs, contractor agreements, risk boilerplate (liability caps, indemnity, force majeure, termination, IP) — or redlining a counterparty's paper.
Contracts fits situations like: reviewing business contracts and clauses in plain language — NDAs; contractor agreements; risk boilerplate (liability caps; redlining a counterpartys paper.
Run `npx skills add ericrisco/rsc-harness --skill contracts -a claude-code`. Or copy the skill folder (skills/contracts in ericrisco/rsc-harness) into .claude/skills/contracts in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill contracts -a codex`. Or copy the skill folder (skills/contracts in ericrisco/rsc-harness) into .agents/skills/contracts in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill contracts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/contracts, .gemini/skills/contracts, .github/skills/contracts and .opencode/skills/contracts in your project.
Going by SKILL.md and its folder, Contracts needs a shell for the scripts in its folder. Our summary lists: A Bash shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Contracts is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Contracts: Custom Nda Generator (zubair-trabzada/ai-legal-claude, 1.8k stars), Legal Design Assessment (lawve-ai/awesome-legal-skills, 826 stars), Contract Review (majiayu000/claude-skill-registry, 666 stars) and Clause Explainer (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.