vendor-agreement-review
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFE
Full Analysis
- Internal Configuration Management: The skill retrieves practice-specific standards, escalation matrices, and playbooks from a centralized configuration file located at
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md, ensuring that the AI's review aligns with the user's established legal standards. - Privilege and Confidentiality Guardrails: It incorporates a mandatory 'Destination check' workflow to prevent the accidental waiver of legal privilege when distributing work product, requiring users to confirm whether the recipient is within the privilege circle.
- External Data Ingestion: The skill is designed to process untrusted data from vendor agreements and associated Data Protection Agreements (DPAs) referenced by URL. While this creates a surface for indirect prompt injection, the risk is managed through a structured review process that requires human validation of the output.
- Integrated Tool Capabilities: It utilizes Model Context Protocol (MCP) integrations for Contract Lifecycle Management (CLM) and DocuSign, featuring mandatory gates that require confirmation of attorney review before generating signature envelopes or distributing redline packages.
- Surgical Redlining Logic: The skill emphasizes minimal, targeted edits to contracts rather than wholesale clause replacements, which is a professional negotiation practice that reduces friction and ensures precise adherence to the playbook positions.
- Source Attribution and Verification: It implements a tagging system for legal citations (e.g.,
[Westlaw],[model knowledge — verify]) to ensure the user can distinguish between high-confidence legal research and potentially unverified AI-recalled information.
Audit Metadata