Agent skill

Tos Clause Scanner

by zebbern in zebbern/claude-code-guide

Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues.

MITAuto-check passedLegal & Compliance

Install Tos Clause Scanner

skills CLI
$ npx skills add zebbern/claude-code-guide --skill tos-clause-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zebbern/claude-code-guide tos-clause-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tos-clause-scanner .claude/skills/tos-clause-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tos-clause-scanner
GitHub stars
4.7k
Used in
1 other repo
Token cost
~3.3k tokens
SKILL.md length
1,500 words
Files
2
Skills in repo
46
Repo updated
First seen
Licence
MIT

At a glance

Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues.

  • Works in 6 steps: Audit Framework → Audit Workflow → Output Format: Audit Report → …
  • A user asks to review
  • SKILL.md covers Quick Start, 1. Audit Framework, 2. Audit Workflow and 3. Output Format: Audit Report, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Tos Clause Scanner is an agent skill from zebbern/claude-code-guide. Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues. Trigger when a user asks to review, audit, or analyze a ToS, privacy policy, or user agreement, or mentions specific concerns like auto-renewal or data authorization.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It sits in Legal & Compliance, covering Privacy and GDPR, Policy and terms drafting and Authorization and RBAC. The repository describes itself as: Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user! The licence is MIT.

When your agent uses it

  • A user asks to review
  • Mentions specific concerns like auto-renewal
  • Data authorization

Example prompts

  • “/tos-clause-scanner”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Audit Framework
  2. Audit Workflow
  3. Output Format: Audit Report
  4. Regulatory Reference Framework
  5. Common Industry-Specific Risks
  6. Agent Behavior Guidelines

What it can do on your machine

Read from SKILL.md and the folder at commit 9cde898. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tos Clause Scanner loads about 3.3k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 1,500 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zebbern/claude-code-guide at commit 9cde898, republished under its MIT licence (© zebbern). 1,500 words, ~3,253 tokens.

Download SKILL.mdSave it as .claude/skills/tos-clause-scanner/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
tos-clause-scanner
description
Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues. Trigger when a user asks to review, audit, or analyze a ToS, privacy policy, or user agreement, or mentions specific concerns like auto-renewal or data authorization.
license
MIT

Terms of Service Auditor (Consumer Perspective)

Systematically audit the Terms of Service, User Agreements, and Privacy Policies of apps, SaaS products, and platforms from an ordinary consumer's standpoint. Identify clauses that may harm consumer rights and produce an actionable audit report.

Quick Start

Paste the terms text directly to the Agent or provide a file path. The Agent will automatically complete the audit and output a structured report.

Example prompts:

  • "Review this user agreement for any unfair or one-sided clauses"
  • "Analyze this app's privacy policy and flag any covert data authorizations"
  • "Does this ToS have auto-renewal traps?"

1. Audit Framework

1.1 Risk Category Definitions

The audit covers seven major risk categories, each with common problem patterns:

IDRisk CategorySeverityDescription
R1Unfair Clauses🔴 HighClauses that exclude or restrict consumers' statutory rights
R2Covert Data Authorization🔴 HighData collection, sharing, or sale beyond what the service requires
R3Auto-Renewal Traps🟠 Medium-HighOpaque auto-renewal mechanisms and cancellation barriers
R4Unilateral Amendment Rights🟠 Medium-HighPlatform reserves the right to modify terms without notice
R5Excessive Liability Disclaimers🟠 Medium-HighOverbroad disclaimers and low liability caps
R6Dispute Resolution Restrictions🟡 MediumMandatory arbitration, class-action waivers, jurisdiction constraints
R7IP Overreach🟡 MediumExcessive rights claimed over user-generated content
1.2 Typical Problem Patterns per Category
R1 Unfair Clauses

Look for these patterns:

  • Unilateral termination rights: Platform may terminate a user's account at any time without cause
  • Asymmetric breach liability: Users face heavy penalties for violations, but the platform's only remedy is a refund—or nothing at all
  • Irrevocable authorizations: Requiring "irrevocable," "perpetual," "worldwide" broad-scope grants from the user
  • Deemed consent: Continued use is treated as agreement to all terms with no option-by-option consent
  • "Final interpretation right" reserved by the platform

Review checklist:

  • Do the terms contain one-sided language such as "we reserve the right" or "we may at our sole discretion"?
  • Are the user's obligations proportionate to the platform's obligations?
  • Are there catch-all "blanket consent" clauses?
R2 Covert Data Authorization

Look for these patterns:

  • Excessive data collection: Collecting data unrelated to the core service (e.g., a calculator app requesting contacts access)
  • Vague third-party sharing: Using terms like "partners," "affiliates," or "third-party service providers" without specifying recipients
  • Opt-out-by-default data collection: Personalized ads and behavioral tracking enabled by default rather than opt-in
  • High opt-out friction: Difficult to disable data collection, or requires toggling off settings one by one
  • Vague data retention periods: No clear retention timeframe, or use of phrases like "as long as necessary"
  • Cross-border data transfers: Inadequate disclosure of where data is stored and transferred

Review checklist:

  • Does the policy follow the principle of data minimization?
  • Are third-party data recipients and purposes specifically listed?
  • Does the user have a meaningful opt-out option?
  • Is the data deletion process clear and actionable?
R3 Auto-Renewal Traps

Look for these patterns:

  • Trial-to-paid auto-conversion: Automatic charges after a free trial ends, with no reminder before the trial expires
  • Complex cancellation process: Canceling requires a phone call, email, or multi-step process, while subscribing takes a single click
  • Early billing window: Renewal is locked in well before expiration (e.g., 24–72 hours ahead)
  • No pro-rata refunds: No partial refund after an auto-renewal charge
  • Silent price changes: Renewal price may change without prior notice

Review checklist:

  • Is auto-renewal prominently disclosed during sign-up or purchase?
  • Is canceling as easy as subscribing?
  • Is there a pre-renewal reminder?
  • Is the refund policy reasonable?
R4 Unilateral Amendment Rights

Look for these patterns:

  • No-notice modifications: Platform reserves the right to change terms at any time without notifying users
  • Continued use equals consent: Continued use after changes is treated as acceptance of the new terms
  • Retroactive effect: New terms apply retroactively to past transactions or behavior

Review checklist:

  • Is there a reasonable notification mechanism for changes (email, in-app message, push notification)?
  • Is there a grace period for users to decide whether to continue using the service?
  • Do material changes require fresh, explicit consent from users?
R5 Excessive Liability Disclaimers

Look for these patterns:

  • Blanket disclaimers: "Under no circumstances shall we be liable for any direct, indirect, incidental, special, or consequential damages"
  • Extremely low liability caps: Caps set at a trivially small amount (e.g., "fees paid in the past 12 months" or a fixed small sum)
  • Core obligation exclusions: Disclaiming liability for defects in the service's core functionality
  • Overbroad force majeure: Classifying system failures or cyberattacks as force majeure events

Review checklist:

  • Is the scope of the disclaimer reasonable?
  • Is the liability cap proportionate to the service fees?
  • Does it exclude liability types that the law does not permit to be disclaimed?
R6 Dispute Resolution Restrictions

Look for these patterns:

  • Mandatory arbitration: All disputes must be resolved through arbitration, with court litigation excluded
  • Class-action waivers: Users are prohibited from joining class actions or class arbitrations
  • Jurisdiction restrictions: Specifying a forum disadvantageous to consumers (e.g., the company's place of incorporation or a foreign court)

Review checklist:

  • Does the consumer retain the right to sue in a local court?
  • Who bears the arbitration costs?
  • Is there a small-claims exception?
R7 IP Overreach

Look for these patterns:

  • Broad content licenses: Requiring users to grant a "worldwide, perpetual, irrevocable, sublicensable" license to their content
  • Uses beyond the service: Platform may use user content for advertising, AI training, or other purposes unrelated to the service itself
  • Rights asymmetry: Platform retains usage rights even after the user deletes content

Review checklist:

  • Is the content license limited to what is necessary to provide the service?
  • Does the platform actually stop using content after account or content deletion?
  • Is commercial resale or sublicensing of user content explicitly excluded?

Show full SKILL.md (582 more words)Show less

2. Audit Workflow

2.1 Input Processing

After receiving the terms text submitted by the user, follow these steps:

  1. Identify document type: Determine whether it is a Terms of Service, Privacy Policy, or a combined agreement
  2. Extract key clauses: Categorize and extract relevant passages under the seven risk categories
  3. Analyze each clause: Assess the risk of every extracted clause
  4. Cross-check: Look for contradictions or conflicts between different clauses
2.2 Evaluation Criteria

For each identified risky clause, evaluate three dimensions:

DimensionDescription
SeverityPotential harm to consumer rights (High / Medium / Low)
ConcealmentWhether the clause disguises its true intent through wording or placement (High / Medium / Low)
ActionabilityWhether the consumer has practical means to mitigate the risk (Yes / Limited / None)

3. Output Format: Audit Report

3.1 Report Structure
markdown
# Terms of Service Audit Report

## Basic Information
- **Subject**: [Platform / App name]
- **Document Type**: [Terms of Service / Privacy Policy / Combined Agreement]
- **Audit Date**: [Date]

## Overall Rating

[⭐⭐⭐⭐⭐ to ⭐ — five-tier scale]

| Metric | Rating |
|--------|--------|
| Overall Consumer-Friendliness | ⭐⭐⭐ |
| Data Privacy Protection | ⭐⭐ |
| Fee Transparency | ⭐⭐⭐⭐ |
| Clause Fairness | ⭐⭐ |

## Risk Findings

### 🔴 High-Risk (Requires Immediate Attention)

#### Finding 1: [Risk Title]
- **Risk Category**: R1 Unfair Clauses / R2 Covert Data Authorization / ...
- **Original Text**: > [Direct quote from the terms]
- **Risk Analysis**: [Plain-language explanation of why this clause is harmful to consumers]
- **Severity**: High | **Concealment**: High | **Actionability**: None
- **Recommendation**: [Actions the consumer can take]

### 🟠 Medium-High Risk

...(same structure as above)

### 🟡 Medium Risk

...(same structure as above)

## Consumer Action Items

1. [Specific action recommendations, ordered by priority]
2. ...

## Comparison with Industry Peers (if applicable)

[Brief note on whether the clause is standard industry practice]
3.2 Plain-Language Explanation Principles

When analyzing each risk, follow these principles so that ordinary consumers can understand:

  • Lead with the conclusion: What does this clause actually mean for the consumer?
  • Use an analogy: Compare it to an everyday scenario (e.g., "This is like your landlord being allowed to raise your rent at any time without notifying you")
  • End with a recommendation: What can the consumer do about it?

4. Regulatory Reference Framework

The audit references the following regulations (this does not constitute legal advice):

4.1 Chinese Regulations
  • Consumer Protection Law: Focus on fair-trade rights, right to know, right to choose
  • Personal Information Protection Law (PIPL): Data minimization, separate consent, cross-border transfers
  • E-Commerce Law: Auto-renewal disclosure obligations
  • Cybersecurity Law: Data storage and security safeguards
  • SAMR Rules on Regulating Auto-Renewals
4.2 International Regulations (for comparative reference)
  • GDPR (EU): Lawful bases for data processing, data-subject rights
  • CCPA / CPRA (California, US): Consumer privacy rights
  • FTC Consumer Protection Guidelines

5. Common Industry-Specific Risks

5.1 Social Media / UGC Platforms
  • Overbroad user-content licensing
  • Authorization for AI training on user data
  • Content-moderation transparency and the right to appeal
5.2 SaaS / Cloud Services
  • Data export rights and supported formats
  • Compensation mechanisms for service outages
  • Actual handling of data after deletion
5.3 E-Commerce / Subscription Services
  • Auto-renewal and price-change practices
  • Symmetry of return and refund policies
  • Unilateral reduction of membership benefits
5.4 Finance / Payments
  • Account-freeze conditions and the appeals process
  • Notice obligations for fee adjustments
  • Burden of proof in transaction disputes
5.5 Smart Hardware / IoT
  • Scope of device data collection (audio, video, location, etc.)
  • Whether the device remains usable after cloud-service discontinuation
  • Mandatory firmware-update clauses

6. Agent Behavior Guidelines

6.1 Audit Principles
  • Clear stance: Always advocate for the consumer; protecting consumer rights is the top priority
  • Objective citations: Every risk finding must quote the original text—no unsupported speculation
  • Plain language: Write for ordinary consumers; avoid legal jargon, and use everyday analogies when needed
  • Not legal advice: Explicitly state that the audit is for reference only and does not constitute legal counsel
6.2 Workflow
  1. After receiving the terms text, read it in full to understand the overall structure
  2. Scan systematically across all seven risk categories and flag suspicious clauses
  3. Perform an in-depth analysis of each flagged clause, evaluating the three dimensions
  4. Sort findings by severity and produce the structured report
  5. Append consumer action items at the end of the report
6.3 Boundaries and Limitations
  • Do not make final determinations on the legal enforceability of any clause
  • Do not directly advise users to take legal action (but may suggest consulting a lawyer)
  • If the terms text is incomplete or appears to have gaps, note this explicitly in the report
  • Do not over-interpret industry-standard reasonable clauses (e.g., reasonable disclaimers) as risks

© zebbern, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/tos-clause-scanner of zebbern/claude-code-guide.

  • SKILL.md
  • LICENSE

Open the folder on GitHubat commit 9cde898

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in zebbern/claude-code-guide, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Tos Clause Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tos Clause Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tos Clause Scanner this skillzebbern/claude-code-guide4.7k1 repos~3.3kAutomated safety check: PassMIT
Pii Contract Analyzegregmos/PII-Shield149—~8.9kAutomated safety check: NotesMIT
Privacy Eukimlawtech/korean-privacy-terms586—~968Automated safety check: PassApache-2.0
Age Gating Servicesmukul975/Privacy-Data-Protection-Skills297—~3.7kAutomated safety check: PassApache-2.0
Terms Of Service Generatorzubair-trabzada/ai-legal-claude1.8k—~2.9kAutomated safety check: PassNone
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~4.2kAutomated safety check: PassMIT

Similar skills

  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Privacy Eu

    kimlawtech/korean-privacy-terms

    EU 사용자 대상 서비스용 Privacy Notice·Terms of Service·Consent Modal·Cookie Banner 자동 생성.

    586 GitHub stars~968 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Terms Of Service Generator

    zubair-trabzada/ai-legal-claude

    Generates complete, GDPR/CCPA-compliant Terms of Service for a website or SaaS product, with plain English summaries for each section

    1.8k GitHub stars~2.9k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    943 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…

    276k GitHub starsUsed in 1 repo~1.4k tokens
    Legal & ComplianceAuto-check passed

More from zebbern/claude-code-guide

All 46 skills in this repo
  • Localization Toolkit

    zebbern/claude-code-guide

    This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or similar, JSON locales), including installing/configuring the…

    4.7k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Audit Flow

    zebbern/claude-code-guide

    Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

    4.7k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Chart Image

    zebbern/claude-code-guide

    Generate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts.

    4.7k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Code To Diagram

    zebbern/claude-code-guide

    Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.

    4.7k GitHub stars~972 tokensUpdated today
    Auto-check passed
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.7k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Idor Testing

    zebbern/claude-code-guide

    This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

    4.7k GitHub starsUsed in 8 repos~3.1k tokens
    Auto-check passed

Questions about Tos Clause Scanner

What does Tos Clause Scanner do?

Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues. Tos Clause Scanner is an agent skill from zebbern/claude-code-guide. Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues.

When should I use Tos Clause Scanner?

Tos Clause Scanner fits situations like: A user asks to review; mentions specific concerns like auto-renewal; data authorization.

How do I install Tos Clause Scanner in Claude Code?

Run `npx skills add zebbern/claude-code-guide --skill tos-clause-scanner -a claude-code`. Or copy the skill folder (skills/tos-clause-scanner in zebbern/claude-code-guide) into .claude/skills/tos-clause-scanner in your project. Claude Code loads it when a task matches its description.

How do I install Tos Clause Scanner in Codex?

Run `npx skills add zebbern/claude-code-guide --skill tos-clause-scanner -a codex`. Or copy the skill folder (skills/tos-clause-scanner in zebbern/claude-code-guide) into .agents/skills/tos-clause-scanner in your project. Codex loads it when a task matches its description.

Can I use Tos Clause Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zebbern/claude-code-guide --skill tos-clause-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tos-clause-scanner, .gemini/skills/tos-clause-scanner, .github/skills/tos-clause-scanner and .opencode/skills/tos-clause-scanner in your project.

What does Tos Clause Scanner need to run?

SKILL.md names no scripts, command-line tools or credentials: Tos Clause Scanner is instructions for the agent only.

Does Tos Clause Scanner access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Tos Clause Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tos Clause Scanner use?

Tos Clause Scanner is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tos Clause Scanner use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tos Clause Scanner?

Skills that share tags, products or a category with Tos Clause Scanner: Pii Contract Analyze (gregmos/PII-Shield, 149 stars), Privacy Eu (kimlawtech/korean-privacy-terms, 586 stars), Age Gating Services (mukul975/Privacy-Data-Protection-Skills, 297 stars) and Terms Of Service Generator (zubair-trabzada/ai-legal-claude, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tos Clause Scanner?

zebbern (a GitHub user) maintains it in zebbern/claude-code-guide, which has 4,652 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 9, 2026.

Source: zebbern/claude-code-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.