vendor-agreement-review

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFE
Full Analysis
  • Internal Configuration Management: The skill retrieves practice-specific standards, escalation matrices, and playbooks from a centralized configuration file located at ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md, ensuring that the AI's review aligns with the user's established legal standards.
  • Privilege and Confidentiality Guardrails: It incorporates a mandatory 'Destination check' workflow to prevent the accidental waiver of legal privilege when distributing work product, requiring users to confirm whether the recipient is within the privilege circle.
  • External Data Ingestion: The skill is designed to process untrusted data from vendor agreements and associated Data Protection Agreements (DPAs) referenced by URL. While this creates a surface for indirect prompt injection, the risk is managed through a structured review process that requires human validation of the output.
  • Integrated Tool Capabilities: It utilizes Model Context Protocol (MCP) integrations for Contract Lifecycle Management (CLM) and DocuSign, featuring mandatory gates that require confirmation of attorney review before generating signature envelopes or distributing redline packages.
  • Surgical Redlining Logic: The skill emphasizes minimal, targeted edits to contracts rather than wholesale clause replacements, which is a professional negotiation practice that reduces friction and ensures precise adherence to the playbook positions.
  • Source Attribution and Verification: It implements a tagging system for legal citations (e.g., [Westlaw], [model knowledge — verify]) to ensure the user can distinguish between high-confidence legal research and potentially unverified AI-recalled information.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 12:40 AM