ai-inventory
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Full launch review against your framework and risk calibration. Use when the user says "review this launch", "legal review for [feature]", "can we ship this", "what are the legal issues with [product]", or references a launch tracker ticket or PRD that needs a
$ npx -y skills add anthropics/claude-for-legal --skill launch-review --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/launch-reviewContext preview
The summary Claude sees to decide when to auto-load this skill.
Full launch review against your framework and risk calibration. Use when the user says "review this launch", "legal review for [feature]", "can we ship this", "what are the legal issues with [product]", or references a launch tracker ticket or PRD that needs a
name: launch-review description: > Full launch review against your framework and risk calibration. Use when the user says "review this launch", "legal review for [feature]", "can we ship this", "what are the legal issues with [product]", or references a launch tracker ticket or PRD that needs a category-by-category review memo. argument-hint: "[PRD file | Drive link | tracker ticket ID]"
1. Load `~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md` → framework + calibration. Stop if placeholders. 2. Get PRD + related docs. If tracker connected, pull ticket and comments. 3. Walk every framework category using the workflow below. 4. Calibrate each finding against the table. Novel = flag explicitly. 5. Output review memo in house format. Post summary to ticket if connected. 6. Hand off: marketing-claims-review if substantial marketing; feature-risk-assessment if a finding needs depth.
/product-legal:launch-review PROJ-1234
---
**Matter context.** Check `## Matter workspaces` in the practice-level CLAUDE.md. If `Enabled` is `✗` (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run `/product-legal:matter-workspace switch <slug>` or say `practice-level`." Load the active matter's `matter.md` for matter-specific context and overrides. Write outputs to the matter folder at `~/.claude/plugins/config/claude-for-legal/product-legal/matters/<matter-slug>/`. Never read another matter's files unless `Cross-matter context` is `on`.
---
Before producing output, check where it's going. If the user has named a destination (a channel, a distribution list, a counterparty, "everyone"), ask whether it's inside the privilege circle. Public channels, company-wide lists, counterparty/opposing counsel, vendors, and clients (for work product) waive the protection. When the destination looks outside the circle, flag it and offer (a) the privileged version for legal only, (b) a sanitized version for the broader channel, or (c) both — don't silently apply a privileged header and then help paste it somewhere the header won't protect it. See the canonical `## Shared guardrails → Destination check` in this plugin's CLAUDE.md.
Read the PRD, check every category in this team's framework, calibrate against what actually blocks here (per `~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md`), and output a review in house format. Goal: a PM reads it and knows exactly what has to happen before they ship.
Read `~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md`:
The calibration table is the difference between this skill and a generic checklist. If the table says "new data collection → PIA, ships in 1-2 days," don't write "this might require a full DPIA and regulatory consultation." Match the team's actual practice.
If Jira/Linear MCP is connected, pull the ticket history — often there's context in earlier comments that the PRD doesn't capture.
Before the checklist, answer in plain English:
**AI detection — run before the framework walk.** Check whether this launch uses AI in any form: a third-party model, an internally built model, an AI-powered vendor feature, automated scoring or classification, generative content, recommendations, predictions. Look for this even if the PRD doesn't label it "AI" — words like "intelligent", "automated", "personalized", "generated", "suggested" are tells.
If AI component detected → flag it, then run `/ai-governance-legal:use-case-triage [feature]` alongside the framework walk. Category 8 below handles the detail; this flag ensures it's never skipped even if the PRD is vague.
For each category in `~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md` → Review framework. If the team doesn't have one, use the 8-category default below. The categories are stable framing concepts; within each category, research the regulatory regimes applicable to the product's sector, audience, and jurisdictions before calibrating severity. What blocks in one jurisdiction or sector may be routine in another — `~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md` captures the team's calibration.
| # | Category | Key question | Auto-skip if | |---|---|---|---| | 1 | **Contractual commitments** | Does this conflict with any customer-facing promise (ToS, SLA, marketing)? | No customer-facing changes | | 2 | **Privacy** | New data collection, new purpose, new sharing? | No data changes | | 3 | **Security** | New attack surface, new data at rest, new access patterns? | UI-only, no backend change | | 4 | **IP** | Third-party code/content? Open-source license check? Outputs that could infringe? | No new dependencies, no user-generated content | | 5 | **Third-party** | New vendor, partner, or integration? | No new external parties | | 6 | **Regulatory** | Does this touch a regulated sector, audience, or jurisdiction? Research the applicabl
Reference agents, skills, and data connectors for the legal workflows we see most — in-house commercial, privacy, product, corporate, employment, litigation, regulatory, AI governance, IP, and the learning side of the practice (law school clinics and
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Run an AI impact assessment — structured intake, risk analysis, regulatory classification per…
Run the cold-start interview — learns your AI governance practice and writes…
Guided customization of your AI governance practice profile — change one thing without…
Manage matter workspaces — new, list, switch, close, or detach (practice-level).…
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and…