is-this-a-problem

is-this-a-problem is a skill for Claude Code from zhou210712/claude-for-legal-ZH. It costs 94 tokens per session (2,419 once invoked), scanned A, original, Apache-2.0.

A quick legal triage workflow for deciding whether a product or business question is harmless, needs review, or should be paused.

In plain words
What is it for?
Screening questions such as whether a proposed use of a customer logo needs legal review.
Why use it?
It gives product teams a short first answer instead of requiring a full legal memo for every question.

Skill for Claude Code

Written for Claude Code: argument-hint in frontmatter. Also seen: reads .claude/ paths; mentions CLAUDE.md.

Part of the product-legal plugin — 4 skills, 1 agent shipped together

Good fit Screening questions such as whether a proposed use of a customer logo needs legal review.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/zhou210712/claude-for-legal-zh/is-this-a-problem
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add zhou210712/claude-for-legal-ZH --skill is-this-a-problem
Clone the repo
git clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZH

Made for: Claude Code.

Or install product-legal, the plugin that ships this one along with the rest of its 4 skills, 1 agent.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for is-this-a-problem

README.md
[![agentmods](https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/is-this-a-problem/github.svg)](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/is-this-a-problem)
Your own site
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/is-this-a-problem"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/is-this-a-problem/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for is-this-a-problem

Your own site · 80×15
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/is-this-a-problem"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/is-this-a-problem.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 94 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,419 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00094 $0.02419
Opus 5 $0.00047 $0.01210
Sonnet 5 $0.00019 $0.00484
Haiku 4.5 $0.00009 $0.00242

Measured 9d ago against content hash b761b371c67c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

is-this-a-problem scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

product-legal/skills/is-this-a-problem/SKILL.md · 137 lines

How it starts

The opening of the file, as written. The whole thing — 137 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/is-this-a-problem

  1. 加载 ~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md → 风险校准。
  2. 执行以下分流工作流。
  3. 模式匹配。检查常见陷阱。
  4. 一分钟内回答:✅ 没问题 / ⚠️ 需要审查 / 🛑 暂停。一句话说明理由。
  5. 如为 ⚠️ 或 🛑:指明下一步。
/product-legal:is-this-a-problem "我们能在定价页用客户的logo吗?"

事项上下文

事项上下文。 检查实务级 CLAUDE.md 中的 ## 事项工作空间。如果 Enabled(企业法务用户的默认值),跳过本段其余内容——技能使用实务级上下文,事项机制不可见。如果已启用且无活跃事项,询问:"这是哪个事项?运行 /product-legal:matter-workspace switch <事项简称> 或说 实务级。"加载活跃事项的 matter.md 获取事项特定上下文和覆盖规则。输出写入事项文件夹 ~/.claude/plugins/config/claude-for-legal/product-legal/matters/<事项简称>/。除非 跨事项上下文,否则绝不读取其他事项的文件。


发送目的地检查

在产出输出前,检查其去向。如果用户指定了目的地(频道、分发列表、对方、"所有人"),询问是否在保密范围内。公共频道、全公司列表、对方/对方律师、供应商和客户(对于工作成果)将导致保护丧失。当目的地显示在保密范围外时,予以标记并提供 (a) 仅供法务的保密版本,(b) 适合更广泛频道的净化版本,或 (c) 两者——不要默不作声地加上保密页眉,然后帮助粘贴到页眉无法保护的地方。参见本插件 CLAUDE.md 中的 ## 共享安全机制 → 发送目的地检查

目的

大多数"快速法务问题"飞书消息属于以下三种之一:(a) 不是问题,快速告知,(b) 确实需要认真审查,转交处理,(c) 看起来没问题但有陷阱,捕捉陷阱。本技能使用校准表在一分钟内完成分流。

目标是速度。产品经理在下午4:47提问。他们想要答案,不是备忘录。

加载校准

读取 ~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md## 风险校准。本技能的核心目的就是对照该表进行模式匹配。

分流

对照校准匹配

该问题是否匹配校准表中的某一模式?

匹配"通常仅FYI告知": → 告知。一句话。"没问题——[模式]。可以上线。"

匹配"通常需付出工作量": → 指明所需工作量。"需要[个人信息保护影响评估/供应商审查/宣传检查]。需要[表中时限]。需要我启动吗?"

匹配"通常阻断上线": → 阻止他们。"暂停——[模式]。这在任何人承诺日期前需要认真审查。我们来谈。"

不匹配任何模式: → 也说明。"这与我在这里见过的任何模式都不匹配。需要人工审查——[您的名字]还是我明天处理?"

陷阱检查

有些问题表面上没问题但有陷阱。识别事实模式,提出捕捉问题,然后针对具体事实模式检索适用规则,再判断是否构成问题。

问题听起来像 为何可能不简单 通过询问捕捉
"我们能接入[供应商]吗?" 供应商接触新的数据类别——标记为可能涉及个人信息保护和供应商风险制度,转研究 "哪些数据流向他们?"
"我们能对定价页做A/B测试吗?" 按人群差异化定价可能涉及消费者保护和歧视相关制度——标记并转研究 "两个版本看到的价格一样吗?用户如何分配到不同版本的?"
"我们能自动为用户注册新功能吗?" 对先前已选择退出的用户默认开启可能涉及同意和消费者保护规则——标记并转研究 "这尊重了用户既有偏好吗?"
"我们能在网站上用客户的logo吗?" Logo使用是合同关系以外的单独授权——标记为可能涉及公开权/推荐权规则和客户自身合同条款 "合同关于公开宣传怎么说?我们有书面授权吗?"
"我们能拿这些数据训练模型吗?" 原始采集目的的使用权可能不涵盖模型训练——标记并检索采集时向用户作出的告知/同意 "采集时我们告诉用户什么了?用户在哪些法域?"
"这只是一个内部工具" 内部工具仍处理个人信息——标记为可能涉及个人信息保护制度,转研究 "它处理谁的数据?员工、客户还是第三方?"
"我们已经做过类似的了" "类似"一词承载了很多内容——差异所在通常就是问题所在 "怎么类似?实际有什么不同?"
"我们能使用[AI供应商/大模型]吗?" 供应商AI条款可能允许对输入进行训练;用例可能需要算法备案——标记并转 /ai-governance-legal:use-case-triage "有AI附录吗?什么数据输入了模型?"
"我们能给这个功能加上AI吗?" 可能是登记册中未包含的新用例;可能触发算法备案要求——标记并转 /ai-governance-legal:use-case-triage "AI做什么——辅助型还是自动化型?它作用于谁?"
"模型自动决定就行" 无人工介入的自动化决策在某些法域受监管——标记并检索受影响用户所在法域的适用规则 "谁受影响?流程中有人工吗?受影响用户在哪里?"
"这是AI生成的内容" 输出IP和披露义务因法域和供应商条款而异——标记并转研究 "内容类型是什么?供应商服务条款是否涉及输出所有权?受众是谁?"
"我们只是用自己的数据微调" 训练数据权利、输出IP和供应商义务都变了——标记并转 /ai-governance-legal:vendor-ai-review "训练数据里有什么?有没有客户或员工的数据?"

Read the full file on GitHub · 137 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 137 lines · 94 tokens per session scan A b761b371c67c

Subscribe to this mod's changes

is-this-a-problem is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 94 tokens to every session and 2,419 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

specification-writing

A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.

wanshuiyin/Auto-claude-code-research-in-sleep · 49 tokens

regulatory-research-fallback

Fallback workflow for regulatory research when web extraction tools fail on government PDFs.

HKUDS/OpenSpace · 20 tokens

x-scorecard

OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.

x-cmd/x-cmd · 57 tokens

gesellschaftsrechtliche-satzungen-agb

Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.

Klotzkette/claude-fuer-deutsches-recht · 69 tokens

memstack-business-gdpr

Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…

cwinvestments/memstack · 121 tokens

nda-review

Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…

LegalQuants/lq-ai · 79 tokens