Skip to content
Legal
Skill

/vendor-ai-review

Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Use when user says "review this AI agreement", "check OpenAI terms", "what did we agree to with

BOOST
From plugin
claude-for-legal
9.6k117 skills10 agents17 MCP
Install
$ npx -y skills add anthropics/claude-for-legal --skill vendor-ai-review --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/vendor-ai-review

Context preview

The summary Claude sees to decide when to auto-load this skill.

Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Use when user says "review this AI agreement", "check OpenAI terms", "what did we agree to with

SKILL.md

vendor-ai-review.SKILL.md
name: vendor-ai-review
description: >
  Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your
  governance positions; flag training-on-data, liability, model changes, and AI policy
  consistency. Use when user says "review this AI agreement", "check OpenAI terms",
  "what did we agree to with [vendor]", "vendor sent an AI addendum", "is this AI
  contract okay", or attaches vendor AI terms.
argument-hint: "[vendor name, or attach the contract]"

/vendor-ai-review

1. Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`. Confirm vendor governance positions are populated — if not, stop and direct to setup. 2. Use the framework below. 3. Confirm document type (AI addendum / main agreement AI provisions / ToS). If only an AUP was provided, ask for the full terms. 4. Term-by-term review: training on data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review rights, use restrictions, audit rights. 5. AI addendum gap check if DPA exists but no AI addendum. 6. AI policy consistency diff vs. `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`. 7. Output: bottom line, term-by-term, recommended redlines, if-they-won't-move routing.

/ai-governance-legal:vendor-ai-review openai-enterprise-agreement.pdf

---

Matter context

**Matter context.** Check `## Matter workspaces` in the practice-level CLAUDE.md. If `Enabled` is `✗` (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run `/ai-governance-legal:matter-workspace switch <slug>` or say `practice-level`." Load the active matter's `matter.md` for matter-specific context and overrides. Write outputs to the matter folder at `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/`. Never read another matter's files unless `Cross-matter context` is `on`.

---

Purpose

Vendor AI terms are where your governance positions actually get tested. The cold-start interview captures what you *want*. This skill checks what you *agreed to* — and flags the gaps between those two things.

The direction here is always the same: we are the deployer or buyer reviewing the vendor's terms. This is the opposite posture from the DPA review controller/processor question — there's no flip.

What varies is the *input*:

  • A standalone AI agreement or AI addendum (most structured)
  • A vendor's universal terms of service with AI provisions embedded (often buried)
  • An acceptable use policy (tells you what you can't do; says nothing about what

the vendor can do with your data or outputs)

  • A combination — master agreement + DPA + AI addendum (common for serious enterprise

AI vendors)

When there's a DPA already in place, this review complements it — it's not a substitute. The DPA governs data protection obligations; the AI terms govern model-specific rights and risks. Both need to be reviewed.

---

Load the playbook

Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` → `## Vendor AI governance`. Also read `## AI policy commitments` — vendor terms can't be consistent with a use restriction our own policy imposes if we've agreed to something different.

If `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` contains `[PLACEHOLDER]`, surface this bounce:

> I notice you haven't configured your practice profile yet — that's how I tailor vendor governance positions to your practice. > > **Two choices:** > - Run `/ai-governance-legal:cold-start-interview` (2 minutes) to configure your profile, then I'll review tailored to YOUR positions. > - Say **"provisional"** and I'll review against generic defaults — US jurisdiction, middle risk appetite, lawyer role, no playbook — and tag every output `[PROVISIONAL — configure your profile for tailored output]` so you can see what I do before committing.

Provisional mode

If the user says "provisional," run the vendor AI review normally using these generic defaults: middle risk appetite, lawyer role, US jurisdiction, no playbook (flag all common vendor-AI risks from first principles rather than matching to configured positions). Tag the reviewer note and every finding block with `[PROVISIONAL]`. At the end of the output, append:

> "That was a generic run against default assumptions. Run `/ai-governance-legal:cold-start-interview` to get output calibrated to YOUR practice — your vendor governance positions, your jurisdiction, your risk appetite. 2 minutes."

---

Before reading the document

If the user hasn't shared the actual vendor terms, ask:

> "Can you share the vendor's AI terms? The most useful thing is the actual contract > language — the AI addendum if there is one, or the main agreement with AI provisions > highlighted. An acceptable use policy alone won't tell us what the vendor can do > with our inputs; it only tells us what we're allowed to do."

If they share an acceptable use policy only: > "This is the acceptable use policy — it tells us what we can't do with the vendor's > AI. That's useful context, but it doesn't address the commercial terms: whether > the vendor can train on our data, what their liability is for AI errors, whether > they notify us when the model changes. Do you have the service agreement or AI > addendum?"

---

The term-by-term review

Core AI-specific terms (check every vendor AI agreement)

Review each term below. For each, extract what the vendor's contract actually says and compare it against the position in `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` → `## Vendor AI governance` (standard / acceptable fallback / automatic no). The default positions come from the team's playbook, not from this skill.

| Term | What to look for | |---|---| | **Training on our data** | Doe

Read more
Ships withclaude-for-legal

Reference agents, skills, and data connectors for the legal workflows we see most — in-house commercial, privacy, product, corporate, employment, litigation, regulatory, AI governance, IP, and the learning side of the practice (law school clinics and

Get the whole plugin

Other skills on claude-for-legal.