Agent skill

Vendor AI Review

by zhou210712 in zhou210712/claude-for-legal-ZH

审查AI供应商条款——重点核查训练数据来源合规性、责任分配、 模型变更通知、合规义务向下传导。适用于审查AI SaaS协议、 AI模型授权、AI API服务条款,或采购团队提出"这个AI供应商 合同有问题吗"时使用。

Apache-2.0Auto-check passedLegal & Compliance

Install Vendor AI Review

skills CLI
$ npx skills add zhou210712/claude-for-legal-ZH --skill vendor-ai-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zhou210712/claude-for-legal-ZH vendor-ai-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance-legal/skills/vendor-ai-review .claude/skills/vendor-ai-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-ai-review
GitHub stars
225
Token cost
~1.1k tokens
SKILL.md length
184 words
Files
1
Skills in repo
122
Repo updated
First seen
Licence
Apache-2.0

At a glance

审查AI供应商条款——重点核查训练数据来源合规性、责任分配、 模型变更通知、合规义务向下传导。适用于审查AI SaaS协议、 AI模型授权、AI API服务条款,或采购团队提出"这个AI供应商 合同有问题吗"时使用。

  • Works in 4 steps: 读取… → 运行以下工作流。 → 逐项核查AI特定风险——训练数据→责任→模型变更→合规传导。 → …
  • Legal & Compliance work in your project
  • SKILL.md covers 事务上下文, 目的, 加载当前状态 and 审查框架, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vendor AI Review is an agent skill from zhou210712/claude-for-legal-ZH. 审查AI供应商条款——重点核查训练数据来源合规性、责任分配、 模型变更通知、合规义务向下传导。适用于审查AI SaaS协议、 AI模型授权、AI API服务条款,或采购团队提出"这个AI供应商 合同有问题吗"时使用。

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance. The licence is Apache-2.0.

When your agent uses it

  • Legal & Compliance work in your project

Example prompts

  • “这个AI供应商 合同有问题吗”
  • “/vendor-ai-review”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 读取 ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → 合同审查立场、可接受风险阈值、红线条款。
  2. 运行以下工作流。
  3. 逐项核查AI特定风险——训练数据→责任→模型变更→合规传导。
  4. 输出:风险总结 + 红线标记 + 谈判立场(经核准/附条件/阻止)。

What it can do on your machine

Read from SKILL.md and the folder at commit 2f01c92. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor AI Review loads about 1.1k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 184 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zhou210712/claude-for-legal-ZH at commit 2f01c92, republished under its Apache-2.0 licence (© zhou210712). 184 words, ~1,148 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-ai-review/SKILL.md (or your agent's skills folder).
name
vendor-ai-review
description
审查AI供应商条款——重点核查训练数据来源合规性、责任分配、 模型变更通知、合规义务向下传导。适用于审查AI SaaS协议、 AI模型授权、AI API服务条款,或采购团队提出"这个AI供应商 合同有问题吗"时使用。
argument-hint
[粘贴AI供应商合同条款]

/vendor-ai-review

  1. 读取 ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → 合同审查立场、可接受风险阈值、红线条款。
  2. 运行以下工作流。
  3. 逐项核查AI特定风险——训练数据→责任→模型变更→合规传导。
  4. 输出:风险总结 + 红线标记 + 谈判立场(经核准/附条件/阻止)。
/ai-governance-legal:vendor-ai-review
[paste the vendor AI terms]

AI供应商合同审查

事务上下文

事务上下文。 检查实践级 CLAUDE.md 中的 ## 事务工作区。如果 已启用 为 ✗,跳过本段其余部分。如果已启用且无活跃事务,询问事务归属。加载活跃事务的 matter.md。除非 跨事务上下文 为 开,否则绝不读取其他事务的文件。


目的

AI供应商合同引入了传统技术合同没有的风险维度——供应商是否使用你的数据训练模型、模型变更时你会不会得到通知、如果AI产生了侵权内容谁承担风险、供应商是否完成了法定的算法备案和安全评估(《生成式人工智能服务管理办法》第17条 [法条原文])。此技能系统性地审查这些风险。

加载当前状态

读取 ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md:

  • ## 合同审查配置 — 公司立场、风险偏好、红线
  • ## 监管注册表 — 适用的法规框架
  • ## 已批准的供应商 — 既有关系和已通过审查的条款

审查框架

第1步:服务定性

首先明确供应商提供的是什么:

模型提供方式说明关键风险
API接口通过云端API调用模型数据传输安全、数据是否被记录用于训练
本地部署模型部署在自有服务器安全可控性高,但更新和升级依赖供应商
SaaS产品使用供应商的AI功能产品使用条款可能不清晰,数据用途条款需特别关注
模型授权/定制授权基础模型进行微调知识产权归属、模型更新的兼容性
第2步:训练数据检查

这是AI合同审查中最重要的部分。

核心问题链
  1. 供应商是否使用客户数据训练模型?
  2. 如果是,客户是否知情并同意?
  3. 训练数据中是否包含个人信息或敏感个人信息?
  4. 客户数据流出后是否可以追回("遗忘权"的实操可行性)?
审查清单
检查项理想状态风险标记
训练数据条款明确约定不将客户数据用于模型训练,或经客户明确书面同意🔴 合同沉默、或条款笼统声称供应商可"使用数据进行服务改进"
个人信息训练不将包含个人信息的数据用于训练,或已取得个人单独同意(《个人信息保护法》第23条 [法条原文])🔴 未区分数据类型,一刀切授权
训练数据合法性保证供应商保证其训练数据来源合法,不侵犯第三方知识产权(《生成式人工智能服务管理办法》第7条 [法条原文])🟠 供应商仅提供"尽力"保证或不提供保证
数据删除合同终止后供应商删除客户数据并销毁包含客户数据的模型副本🟠 仅承诺"停止使用"而不承诺删除
知识产权归属明确约定微调模型的权属(客户拥有/供应商拥有/共享)🟠 合同沉默
训练数据条款的红线
  • 供应商单方面保留"为改进服务目的"使用客户全部数据的权利,且不可协商
  • 供应商拒绝就训练数据的合法来源提供任何保证
  • 涉及个人信息且供应商拒绝签署数据处理协议(参照《个人信息保护法》第21条 [法条原文])
第3步:责任分配

AI产出的特殊性使得传统的责任条款可能无法直接适用。需要特别关注:

责任场景供应商理想立场风险
AI产出侵权(知识产权)供应商承担因其训练数据或模型本身导致的侵权责任🔴 供应商将全部侵权风险转嫁客户
AI产出违法/不良内容供应商基于《生成式人工智能服务管理办法》承担内容安全责任🔴 供应商声称仅为"技术中立工具"
AI产出错误导致商业损失责任分配合理,特殊或间接损失合理排除🟠 供应商完全免责且客户承担全部损失
模型停机/服务中断SLA明确,有可用性承诺和服务积分/赔偿机制🟡 SLA模糊或缺失
模型性能退化供应商保证模型输出质量不实质性下降🟠 供应商保留单方修改模型的权利且无通知义务

中国法特别关注:《生成式人工智能服务管理办法》第9条要求提供者承担生成内容的生产者责任 [法条原文]——如果供应商声称自己仅提供"技术工具"而不对AI产出负责,该立场在法规层面的支撑较弱。但实践中,供应商可能通过合同条款将部分风险转移给使用者,需逐案分析。

第4步:模型变更通知
  • 供应商是否可以单方修改模型?(通常可以——关键在于通知和影响评估)
  • 模型变更需要提前多久通知?(行业惯例:30-90天)
  • 如果变更实质性降低性能或合规性,客户是否有终止权?
  • 如果供应商停止支持某个模型版本,是否有合理的退出机制?
检查项最低可接受标准
实质性变更通知至少30天提前书面通知
性能退化补救如变更导致性能退化>X%,供应商需在合理期限内补救
终止权如供应商无法补救或变更影响合规状态,客户有权终止
合规影响评估供应商应在变更前提供合规影响摘要(至少概要说明)
第5步:合规义务传导

作为AI服务使用者,需要确保供应商有能力支持你的合规义务:

法规合规要求供应商应尽的义务合同核查点
算法备案(《互联网信息服务算法推荐管理规定》第24条 [法条原文])供应商已完成备案并提供备案号合同是否明确供应商的算法备案状态?是否有持续合规保证?
安全评估(《生成式人工智能服务管理办法》第17条 [法条原文])供应商已进行安全评估是否可以获取评估结论摘要(不要求完整报告,但需要确认已完成)
科技伦理审查(《科技伦理审查办法(试行)》[法条原文])供应商已完成伦理审查(如适用)是否涉及需伦理审查的场景?
个人信息保护(《个人信息保护法》[法条原文])如涉及数据处理,应签署数据处理协议数据处理协议的充分性
安全措施(《个人信息保护法》第51条 [法条原文])供应商承诺采取必要的安全措施SOC2/等保报告、安全事件通知时限、数据泄露通知义务
审计权供应商应接受审计或提供第三方审计报告审计权的范围和频率
内容安全供应商应有违法和不良信息识别和处置机制信息安全管理能力描述或认证
第6步:评估和输出
风险汇总表
类别法律风险商业摩擦关键风险点
训练数据🔴🟠🟡⚪🔴🟠🟡⚪[要点]
责任分配🔴🟠🟡⚪🔴🟠🟡⚪[要点]
模型变更🔴🟠🟡⚪🔴🟠🟡⚪[要点]
合规传导🔴🟠🟡⚪🔴🟠🟡⚪[要点]
输出格式
markdown
[工作成果头 — 按照插件配置 ## 输出]

# AI供应商合同审查:[供应商名称] — [服务类型]

**日期:** [日期]
**供应商:** [名称]
**服务:** [API / SaaS / 本地部署 / 模型授权]
**总体结论:** [经核准 / 附条件核准 / 不适合当前条款]

---

## 一、服务概况

[一段话]

## 二、训练数据风险

### 发现
[具体条款语言及风险分析]

### 建议
[谈判立场 + 备选条款语言]

## 三、责任分配风险

### 发现
[参照第3步清单]

### 建议
[谈判立场 + 备选条款语言]

## 四、模型变更风险

### 发现
[参照第4步清单]

### 建议
[谈判立场 + 备选条款语言]

## 五、合规传导风险

### 发现
供应商是否具备支持客户合规义务的能力:[描述]

### 建议
[需要供应商补充的材料、条款修订建议]

## 六、谈判立场

| 条款 | 当前 | 我方立场 | 最低接受标准 | 谈判优先级 |
|------|------|----------|-------------|-----------|
| [条款] | [现状] | [理想] | [底线] | 致命/高/中/低 |

## 七、红线标记

[列出触发红线的条款——需升级法律顾问]

收尾

以 CLAUDE.md ## 输出 规定的下一步决策树收尾。定制选项:按审查意见与供应商谈判、升级红线条款至法律顾问决策、接受当前条款(如无红线)、获取更多供应商信息。


本技能不做的事

  • 不覆盖通用的合同审查要素(管辖法、争议解决、保密条款等)——仅聚焦AI特定风险
  • 不评估模型的技术性能——这是一个法律和合规审查,不是技术尽职调查
  • 不替代算法备案核查——本技能检查供应商的备案承诺,但不验证备案信息的真实性(应通过网信办公开渠道或供应商的备案号自行验证)

© zhou210712, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in ai-governance-legal/skills/vendor-ai-review of zhou210712/claude-for-legal-ZH.

Open the folder on GitHubat commit 2f01c92

Compare with similar skills

Vendor AI Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor AI Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor AI Review this skillzhou210712/claude-for-legal-ZH225—~1.1kAutomated safety check: PassApache-2.0
Paper to Chinese Patent DrafterYuan1z0825/nature-skills47k1 repos~1.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Legal Clinic Client Intakeanthropics/claude-for-legal9.6k3 repos~3.2kAutomated safety check: PassApache-2.0
Paper To Cn Patentsnipp-zha/Paper-to-patent-Skill1071 repos~959Automated safety check: PassNone

Similar skills

  • Paper to Chinese Patent Drafter

    Yuan1z0825/nature-skills

    Drafts Chinese invention patent applications and technical disclosures from research papers or inventor materials, tying each claim feature to source evidence.

    47k GitHub starsUsed in 1 repo~1.1k tokens
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Legal & ComplianceAuto-check passed
  • Paper To Cn Patent

    snipp-zha/Paper-to-patent-Skill

    Convert scientific papers, theses, technical reports, source code, figures, or research manuscripts into evidence-grounded Chinese invention patent drafts.

    107 GitHub starsUsed in 1 repo~959 tokens
    Legal & ComplianceAuto-check passed
  • Employment Contract Templates

    ynulihao/AgentSkillOS

    Create employment contracts, offer letters, and HR policy documents following legal best practices.

    618 GitHub starsUsed in 12 repos~4.1k tokens
    Legal & ComplianceAuto-check passed

More from zhou210712/claude-for-legal-ZH

All 122 skills in this repo
  • Claim Chart

    zhou210712/claude-for-legal-ZH

    构建或审查要件分析表——专利权利要求对照表(侵权、无效或审查)或 民事构成要件分析表(任何诉讼请求或抗辩),每个单元格附精确引用, 缺口检测为优先输出。当用户要求要件分析表、权利要求对照表、 证据对照表、侵权或无效主张、逐要件映射,或问"我们证明[主张]还缺什么"时使用。

    225 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Client Intake

    zhou210712/claude-for-legal-ZH

    结构化接待——实践领域模板、跨领域考点识别、利益冲突标记、分流分类. An agent skill from zhou210712/claude-for-legal-ZH.

    225 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Gap Surfacer

    zhou210712/claude-for-legal-ZH

    参考资料:支持 /regulatory-legal:gaps 和 /regulatory-legal:comments 的共享差距和意见征集跟踪框架。跟踪未关闭的政策差距及其整改状态, 从 policy-diff 中获取差距,呈现开放和即将到期的事项,路由给负责人, 并通过企业通讯工具通知差距负责人,每次发送前需确认。

    225 GitHub stars~757 tokensUpdated 4 mo ago
    Auto-check passed
  • Launch Review

    zhou210712/claude-for-legal-ZH

    对照您的框架和风险校准进行全面产品上线审查。当用户说"审查这个上线" "[功能]法务审查""我们能上线吗""[产品]有什么法律问题"或引用了需要 逐类审查备忘录的产品需求文档或上线追踪工单时使用。

    225 GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check passed
  • Reg Feed Watcher

    zhou210712/claude-for-legal-ZH

    检查法规动态源,报告自上次检查以来的新事项,按重要度阈值过滤。适用于用户说"检查法规动态"、"有什么新规定"、"法规更新"、从定时任务触发执行,或手动粘贴法规动态进行分类和差异分析时。

    225 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Renewal Tracker

    zhou210712/claude-for-legal-ZH

    展示具有即将到来的取消截止日期的合同,在通知窗口关闭前发出预警, 基于维护的续约登记册运行。当用户询问"什么即将续约""哪些续约即将到期" "我们是否错过了取消窗口""将此添加到续约追踪器"时使用,或按计划运行。

    225 GitHub stars~681 tokensUpdated 4 mo ago
    Auto-check passed

Questions about Vendor AI Review

What does Vendor AI Review do?

审查AI供应商条款——重点核查训练数据来源合规性、责任分配、 模型变更通知、合规义务向下传导。适用于审查AI SaaS协议、 AI模型授权、AI API服务条款,或采购团队提出"这个AI供应商 合同有问题吗"时使用。. Vendor AI Review is an agent skill from zhou210712/claude-for-legal-ZH.

When should I use Vendor AI Review?

Vendor AI Review fits situations like: legal & Compliance work in your project.

How do I install Vendor AI Review in Claude Code?

Run `npx skills add zhou210712/claude-for-legal-ZH --skill vendor-ai-review -a claude-code`. Or copy the skill folder (ai-governance-legal/skills/vendor-ai-review in zhou210712/claude-for-legal-ZH) into .claude/skills/vendor-ai-review in your project. Claude Code loads it when a task matches its description.

How do I install Vendor AI Review in Codex?

Run `npx skills add zhou210712/claude-for-legal-ZH --skill vendor-ai-review -a codex`. Or copy the skill folder (ai-governance-legal/skills/vendor-ai-review in zhou210712/claude-for-legal-ZH) into .agents/skills/vendor-ai-review in your project. Codex loads it when a task matches its description.

Can I use Vendor AI Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhou210712/claude-for-legal-ZH --skill vendor-ai-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-ai-review, .gemini/skills/vendor-ai-review, .github/skills/vendor-ai-review and .opencode/skills/vendor-ai-review in your project.

What does Vendor AI Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Vendor AI Review is instructions for the agent only.

Does Vendor AI Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor AI Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vendor AI Review use?

Vendor AI Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor AI Review use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vendor AI Review?

Skills that share tags, products or a category with Vendor AI Review: Paper to Chinese Patent Drafter (Yuan1z0825/nature-skills, 47k stars), C15t (c15t/c15t, 1.9k stars), Contract Review (evolsb/claude-legal-skill, 464 stars) and Legal Clinic Client Intake (anthropics/claude-for-legal, 9.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor AI Review?

zhou210712 (a GitHub user) maintains it in zhou210712/claude-for-legal-ZH, which has 225 GitHub stars. The repository holds 122 skills in this directory. The repository was last updated on May 15, 2026.

Source: zhou210712/claude-for-legal-ZH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.