Agent skill

Contract Review

by shawnpang in shawnpang/startup-founder-skills

When the user needs to review an existing contract, assess risk in proposed terms, or evaluate a contract before signing.

MITAuto-check passedLegal & Compliance

Install Contract Review

skills CLI
$ npx skills add shawnpang/startup-founder-skills --skill contract-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install shawnpang/startup-founder-skills contract-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/contract-review .claude/skills/contract-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
contract-review
GitHub stars
343
Token cost
~2.2k tokens
SKILL.md length
1,156 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

When the user needs to review an existing contract, assess risk in proposed terms, or evaluate a contract before signing.

  • Works in 6 steps: Contract intake — Receive the contract… → Section-by-section analysis — Walk… → Risk flagging — Apply the… → …
  • Needs to review an existing contract
  • SKILL.md covers When to Use, Context Required, Workflow and Output Format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Contract Review is an agent skill from shawnpang/startup-founder-skills. When the user needs to review an existing contract, assess risk in proposed terms, or evaluate a contract before signing.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Contract review. The repository describes itself as: AI agent skills for tech startup founders — fundraising, sales, product, recruiting, engineering, legal, ops, and growth. Works with Claude Code, Cursor, Codex, and any Agent… The licence is MIT.

When your agent uses it

  • Needs to review an existing contract
  • Assess risk in proposed terms
  • Evaluate a contract before signing

Example prompts

  • “/contract-review”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Contract intake — Receive the contract text. Identify the contract type, parties, effective date, and term. Create a one-paragraph summary…
  2. Section-by-section analysis — Walk through each major section, summarizing what it means in plain language and flagging anything noteworthy.
  3. Risk flagging — Apply the red/yellow/green flagging system (see below) to each clause. Assign a severity and explain why.
  4. Missing protections — Identify standard protections that are absent from the contract but should be present given the contract type and…
  5. Negotiation recommendations — For each red and yellow flag, suggest specific alternative language or a negotiation strategy.
  6. Summary report — Produce a structured risk assessment with prioritized action items.

What it can do on your machine

Read from SKILL.md and the folder at commit 4ad31b4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Contract Review loads about 2.2k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 1,156 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from shawnpang/startup-founder-skills at commit 4ad31b4, republished under its MIT licence (© shawnpang). 1,156 words, ~2,210 tokens.

Download SKILL.mdSave it as .claude/skills/contract-review/SKILL.md (or your agent's skills folder).
name
contract-review
description
When the user needs to review an existing contract, assess risk in proposed terms, or evaluate a contract before signing.
related
terms-of-service, privacy-policy
reads
startup-context

Contract Review

When to Use

Activate when a founder has received a contract to sign and wants to understand the risks before proceeding. This includes vendor agreements, customer enterprise agreements, partnership deals, investment documents, employment agreements, NDAs, IP assignment agreements, and any other binding legal document. Also activate when the user says things like "review this contract," "is this agreement fair," "what should I push back on," or "flag anything concerning."

Context Required

  • From startup-context: company stage, team size, business model, fundraising status, current revenue, and any existing legal counsel.
  • From the user: the contract text (or key sections), who the counterparty is, the business relationship context (are they a customer, vendor, investor, partner), the user's negotiating leverage, and any specific concerns they have. Also helpful: whether this is a template/standard agreement or has been negotiated.

Workflow

  1. Contract intake — Receive the contract text. Identify the contract type, parties, effective date, and term. Create a one-paragraph summary of what the contract does.
  2. Section-by-section analysis — Walk through each major section, summarizing what it means in plain language and flagging anything noteworthy.
  3. Risk flagging — Apply the red/yellow/green flagging system (see below) to each clause. Assign a severity and explain why.
  4. Missing protections — Identify standard protections that are absent from the contract but should be present given the contract type and relationship.
  5. Negotiation recommendations — For each red and yellow flag, suggest specific alternative language or a negotiation strategy.
  6. Summary report — Produce a structured risk assessment with prioritized action items.

Output Format

Contract Summary (top of report)
  • Contract type: (e.g., SaaS vendor agreement, MSA, NDA)
  • Parties: Company name vs. counterparty name
  • Term: Duration, renewal mechanism
  • Total value: Financial commitment if applicable
  • Overall risk level: Red / Yellow / Green with one-sentence rationale
Clause-by-Clause Analysis Table
SectionSummaryFlagRiskRecommended Action
Liability CapCapped at fees paid in prior 6 monthsYellowLow cap for potential damagesNegotiate to 12-month cap
IP AssignmentBroad assignment of all work productRedCould capture pre-existing IPAdd carve-out for pre-existing IP
Missing Protections Checklist

Bulleted list of protections that should be present but are not.

Prioritized Action Items

Numbered list of what to do, in order of importance.

Frameworks & Best Practices

The Red/Yellow/Green Flagging System

Red Flags — Immediate concern, do not sign without modification:

  • Unlimited liability or liability cap below a reasonable threshold
  • Broad IP assignment that could capture pre-existing IP or IP unrelated to the engagement
  • Non-compete clauses that are overly broad in scope, geography, or duration
  • Unilateral termination rights without cure period for one party only
  • Automatic renewal with no opt-out window or unreasonable notice requirements
  • Indemnification obligations that are uncapped or wildly asymmetric
  • Most-favored-nation clauses that constrain your pricing with other customers
  • Exclusivity provisions that limit your ability to work with competitors
  • Audit rights with unreasonable scope or no notice requirement
  • Governing law in an unfavorable or distant jurisdiction with no negotiation

Yellow Flags — Worth negotiating, but not necessarily deal-breakers:

  • Liability caps that are low relative to the contract value
  • Warranty periods or SLA credits that are below industry standard
  • Payment terms exceeding net-60
  • Change-of-control provisions that allow termination on acquisition
  • Broad confidentiality definitions with long or indefinite survival periods
  • Assignment restrictions that prevent assignment in an acquisition scenario
  • Force majeure clauses that are overly broad or favor one party
  • Data handling terms that are vague about deletion, portability, or sub-processors

Green Flags — Standard and reasonable:

  • Mutual confidentiality obligations
  • Balanced termination rights with cure periods
  • Liability capped at 12 months of fees paid
  • Standard representations and warranties
  • Clear payment terms (net-30)
  • Reasonable non-solicitation (employees only, 12 months)
Negotiation Principles
  • Symmetry first. Any obligation imposed on one party should apply to both unless there is a clear business reason for asymmetry.
  • Cap everything. Liability, indemnification, and damages should all have explicit caps.
  • Cure periods. Both parties should have the opportunity to fix a breach before termination.
  • Specificity over breadth. Narrow definitions protect both parties. "Confidential Information means everything" protects nothing.
  • Survival clarity. Specify exactly which clauses survive termination and for how long.
  • terms-of-service — When reviewing a customer's redlines to your terms of service, use contract-review to assess their proposed modifications.
  • privacy-policy — Data processing addendums and DPAs often accompany contracts. Review these for consistency with your privacy commitments.
Show full SKILL.md (448 more words)Show less

Examples

Example 1: Reviewing a vendor SaaS agreement

User: "We're about to sign a contract with a data enrichment vendor. Here are the terms. Can you flag anything concerning?"

Good output excerpt:

Overall Risk Level: Yellow

The agreement is mostly standard but has three issues worth negotiating before signing.

SectionFlagIssue
4.2 Data RightsRedVendor claims a "perpetual, irrevocable license to use Customer Data for product improvement and benchmarking." This means they keep and use your data forever, even after termination. Negotiate to: license limited to providing the service, terminates on contract end, anonymization required for any aggregate use.
7.1 LiabilityYellowCap is set at "fees paid in the prior 3 months." For a $2K/month contract, that is a $6K cap. If they cause a data breach affecting your customers, your exposure could be much higher. Negotiate to: 12 months of fees, with a carve-out for uncapped liability on data breaches and IP infringement.
9.3 TerminationYellow90-day notice required to cancel, even on annual renewal. Combined with auto-renewal, this means you need to decide 3 months before your renewal date. Negotiate to: 30-day notice, or set a calendar reminder now.

Missing Protections:

  • No data deletion timeline after termination
  • No breach notification obligation
  • No sub-processor list or approval rights
  • No SLA or uptime commitment
Example 2: Reviewing an IP assignment in an employment agreement

User: "A new engineer's offer letter has an IP assignment clause. They're concerned about their open-source side projects. Can you review?"

Good output excerpt:

Section 8 — Invention Assignment: Red Flag

The current language reads: "Employee assigns to the Company all right, title, and interest in any invention, improvement, or work of authorship created during the term of employment."

This is overly broad. It captures the engineer's weekend open-source contributions, personal projects, and anything they create during employment regardless of whether it relates to company business.

Recommended revision: Add a carve-out: "...created during the term of employment that (a) relates to the Company's current or reasonably anticipated business, (b) was developed using Company resources, or (c) resulted from work performed for the Company."

Also add a Schedule A listing the engineer's pre-existing IP and active side projects, explicitly excluded from assignment. Note: California Labor Code Section 2870 already provides some protection, but an explicit carve-out is clearer and avoids disputes.


Disclaimer: This skill provides contract analysis for educational and planning purposes only. It does not constitute legal advice. Contract interpretation depends on jurisdiction-specific law, the full context of the business relationship, and facts that may not be apparent from the document alone. Always have a qualified attorney review contracts before signing, especially those involving significant financial commitments, IP rights, or liability exposure.

© shawnpang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/contract-review of shawnpang/startup-founder-skills.

Open the folder on GitHubat commit 4ad31b4

Compare with similar skills

Contract Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Contract Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Contract Review this skillshawnpang/startup-founder-skills343—~2.2kAutomated safety check: PassMIT
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Commercial Legal Plapiotrowski-afk/commercial-legal-pl1761 repos~4.1kAutomated safety check: PassApache-2.0
Hand Drawnthreerocks/hand-drawn-styles2.2k—~398Automated safety check: PassMIT
Tabular Document Reviewanthropics/claude-for-legal9.6k3 repos~4.3kAutomated safety check: PassApache-2.0
Tw Formal WritingImbad0202/tw-formal-writing179—~1kAutomated safety check: PassMIT

Similar skills

  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Commercial Legal Pl

    apiotrowski-afk/commercial-legal-pl

    Skill do analizy i tworzenia umów według polskiego prawa, ze szczególnym uwzględnieniem umów B2B, IP i IT (body leasing, NDA, wdrożenia, SaaS, przeniesienie praw autorskich, ugody).

    176 GitHub starsUsed in 1 repo~4.1k tokens
    Legal & ComplianceAuto-check passed
  • Hand Drawn

    threerocks/hand-drawn-styles

    A skill your agent uses when users ask for a hand-drawn or illustrated image prompt, name one of the repository's 20 numbered styles or the 3.1 stable variant, or mention triggers such as…

    2.2k GitHub stars~398 tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Tabular Document Review

    anthropics/claude-for-legal

    Official

    Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.

    9.6k GitHub starsUsed in 3 repos~4.3k tokens
    Legal & ComplianceAuto-check passed
  • Tw Formal Writing

    Imbad0202/tw-formal-writing

    台灣正式文件撰寫助手 — 涵蓋政府公文、政府機關其他文件、法律文件、人民對政府文書四類中文正式文件的撰寫(不含學術論文、商業文書、私人書信等,見下方排除清單)。

    179 GitHub stars~1k tokensUpdated 16 days ago
    Legal & ComplianceAuto-check passed
  • Contract Review Pro

    CSlawyer1985/contract-review-pro

    专业合同审核 Skill:7步工作流(含立场声明、框架审阅、类型路由)、5类通用门禁+16个专项门禁、终稿三件套+HTML可视化报告、8维度风险评分、修订5分类路由。完全自包含,零外部依赖。

    277 GitHub stars~2.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from shawnpang/startup-founder-skills

All 50 skills in this repo
  • Accelerator Application

    shawnpang/startup-founder-skills

    When the user wants to apply to startup accelerators, incubators, or fellowship programs.

    343 GitHub stars~2.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Architecture Design

    shawnpang/startup-founder-skills

    When the user needs to design or evaluate system architecture — service boundaries, data models, API contracts, infrastructure topology, database selection, or dependency analysis.

    343 GitHub stars~2.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Board Update

    shawnpang/startup-founder-skills

    When the user needs to write a monthly or quarterly investor update, prepare a board deck, or communicate company progress to stakeholders.

    343 GitHub stars~2.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Churn Analysis

    shawnpang/startup-founder-skills

    When the user needs to identify at-risk accounts, understand why customers are leaving, reduce churn rate, build health scores, design save plays, or create win-back campaigns.

    343 GitHub stars~2.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Cicd Setup

    shawnpang/startup-founder-skills

    When the user needs to set up or improve CI/CD pipelines — GitHub Actions, GitLab CI, deployment automation, or says "set up CI", "automate deployment", "add tests to pipeline", "fix my build".

    343 GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Code Review

    shawnpang/startup-founder-skills

    When the user asks for a code review, shares code for feedback, or says "review this", "check my code", "what's wrong with this".

    343 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Contract Review

What does Contract Review do?

When the user needs to review an existing contract, assess risk in proposed terms, or evaluate a contract before signing. Contract Review is an agent skill from shawnpang/startup-founder-skills. When the user needs to review an existing contract, assess risk in proposed terms, or evaluate a contract before signing.

When should I use Contract Review?

Contract Review fits situations like: needs to review an existing contract; assess risk in proposed terms; evaluate a contract before signing.

How do I install Contract Review in Claude Code?

Run `npx skills add shawnpang/startup-founder-skills --skill contract-review -a claude-code`. Or copy the skill folder (skills/contract-review in shawnpang/startup-founder-skills) into .claude/skills/contract-review in your project. Claude Code loads it when a task matches its description.

How do I install Contract Review in Codex?

Run `npx skills add shawnpang/startup-founder-skills --skill contract-review -a codex`. Or copy the skill folder (skills/contract-review in shawnpang/startup-founder-skills) into .agents/skills/contract-review in your project. Codex loads it when a task matches its description.

Can I use Contract Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shawnpang/startup-founder-skills --skill contract-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/contract-review, .gemini/skills/contract-review, .github/skills/contract-review and .opencode/skills/contract-review in your project.

What does Contract Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Contract Review is instructions for the agent only.

Does Contract Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Contract Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Contract Review use?

Contract Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Contract Review use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Contract Review?

Skills that share tags, products or a category with Contract Review: Contract Review (evolsb/claude-legal-skill, 464 stars), Commercial Legal Pl (apiotrowski-afk/commercial-legal-pl, 176 stars), Hand Drawn (threerocks/hand-drawn-styles, 2.2k stars) and Tabular Document Review (anthropics/claude-for-legal, 9.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Contract Review?

shawnpang (a GitHub user) maintains it in shawnpang/startup-founder-skills, which has 343 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on March 16, 2026.

Source: shawnpang/startup-founder-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.