vendor-ai-review

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • File System Access: The skill reads and writes to specific paths within the ~/.claude/plugins/config/claude-for-legal/ directory. This is used for accessing governance playbooks (CLAUDE.md) and saving matter-specific review outputs, which is consistent with its purpose as a legal review tool.
  • Vendor-Specific Logic: It includes specialized logic for analyzing common AI model providers (e.g., Anthropic, OpenAI, Google) and their enterprise terms. This is standard functionality for comparing different vendor contract structures.
  • Human-in-the-Loop Safeguards: The skill incorporates a mandatory check for non-lawyer users, requiring them to confirm they have consulted with an attorney before proceeding with execution-ready documents. This is a best-practice safety feature for legal-adjacent tools.
  • Data Handling: It explicitly warns users that the content being reviewed is often under NDA and emphasizes maintaining attorney-client privilege. It does not perform unexpected network operations or data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 09:46 PM
Security Audit — agent-trust-hub — vendor-ai-review