vendor-ai-review
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFE
Full Analysis
- File System Access: The skill reads and writes to specific paths within the
~/.claude/plugins/config/claude-for-legal/directory. This is used for accessing governance playbooks (CLAUDE.md) and saving matter-specific review outputs, which is consistent with its purpose as a legal review tool. - Vendor-Specific Logic: It includes specialized logic for analyzing common AI model providers (e.g., Anthropic, OpenAI, Google) and their enterprise terms. This is standard functionality for comparing different vendor contract structures.
- Human-in-the-Loop Safeguards: The skill incorporates a mandatory check for non-lawyer users, requiring them to confirm they have consulted with an attorney before proceeding with execution-ready documents. This is a best-practice safety feature for legal-adjacent tools.
- Data Handling: It explicitly warns users that the content being reviewed is often under NDA and emphasizes maintaining attorney-client privilege. It does not perform unexpected network operations or data exfiltration.
Audit Metadata