vendor-agreement-review
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill relies on a local configuration file at
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.mdto define standard legal positions and escalation rules, ensuring the agent follows pre-approved practice guidelines rather than untrusted external data. - [PROMPT_INJECTION]: While the skill processes untrusted vendor agreements (a potential surface for indirect prompt injection), it mitigates this risk by enforcing a highly structured, multi-step comparison workflow. The agent is required to quote contract language verbatim and check it against the local playbook, which acts as a robust boundary against adversarial instructions embedded in documents.
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to identify and fetch content from URLs found within agreements, such as Data Processing Agreements (DPAs). This capability is restricted to document analysis and the skill includes instructions to surface these external references to the user for validation rather than executing code from them.
- [COMMAND_EXECUTION]: The skill integrates with external contract management and signature platforms (CLM and DocuSign). These integrations include mandatory 'non-lawyer' warning gates that block automated execution and require the user to explicitly confirm they have consulted with an attorney before signature envelopes are generated or redlines are finalized.
Audit Metadata