Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zhou210712/claude-for-legal-ZH --skill nda-reviewgit clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZHWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/nda-review)<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/nda-review"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/nda-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/nda-review"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/nda-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00073 | $0.04817 |
| Opus 5 | $0.00036 | $0.02409 |
| Sonnet 5 | $0.00015 | $0.00963 |
| Haiku 4.5 | $0.00007 | $0.00482 |
Grade A, and why
nda-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 282 lines — stays where its author put it; the contents beside it link to each section on GitHub.
保密协议审查
事项上下文
事项上下文。 检查业务领域级 CLAUDE.md 中的 ## 事项工作区。如果 Enabled 为 ✗(法务用户的默认值),跳过本段其余内容——技能使用业务领域级上下文,事项机制不可见。如果已启用且没有活动事项,询问:"这是哪个事项的?运行 /commercial-legal:matter-workspace switch <slug> 或说 practice-level。"加载活动事项的 matter.md 获取事项特定上下文和覆盖设置。将输出写入事项文件夹 ~/.claude/plugins/config/claude-for-legal/commercial-legal/matters/<matter-slug>/。除非 跨事项上下文 为 on,否则绝不读取其他事项的文件。
发送对象检查
生成输出前,检查发送对象。如果用户指定了发送对象(频道、分发列表、对方当事人、"所有人"),询问是否在保密特权范围内。公共频道、全公司列表、对方当事人/对方律师、供应商和客户(就工作成果而言)均放弃保护。当发送对象在圈外时,标注并给出 (a) 仅限法务查看的保密版本,(b) 适用于更广泛渠道的脱敏版本,或 (c) 两者——不要默默加上保密文件头,然后协助将文件粘贴到文件头无法保护的地方。参见本插件 CLAUDE.md 中的规范 ## 共享安全机制 → 发送目的地检查。
目的
大多数接收方保密协议都没问题。少数有陷阱。本技能在一分钟内完成分类,使法务只阅读真正需要关注的协议。
目标: 绿色保密协议应当只需要签字即可。黄色需要律师就一两项具体事项过目。红色在浪费任何人时间之前即行停止。
首先加载审查指引
哪一方? 在适用审查指引之前,确定公司在此保密协议中处于哪一方。通常从上下文即可明显判断:如果对方是评估你产品的供应商或合作伙伴,你是销售方;如果你在评估对方的产品,你是采购方。相互保密协议仍然有方向——用的是谁的模板,评估方向是什么。如果不明显,询问。从配置中读取匹配的审查指引部分(### 销售方审查指引 或 ### 采购方审查指引)。在输出中注明适用方向,以便审查者知道适用的是哪个审查指引。如果匹配方向为 [未配置],停止并告知用户在进行此分类前运行 /commercial-legal:cold-start-interview --side <side>。
在进行任何分类前,阅读 ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md → ## 审查指引 → 匹配方向 → 保密协议分类标准。 该部分是关于对本团队在本方向下,什么使保密协议成为绿色、黄色或红色的真实来源。本技能不附带关于保密协议条款的默认立场——法律、市场和每个团队的风险容忍度差异太大,无法安全使用硬编码默认值。
如果 ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md 尚无 保密协议分类标准 部分,或在你审查的保密协议中遇到该部分未涉及的条款,询问用户:
你的审查指引未涵盖 [条款——如"残留信息条款""保密期限""你作为接收方的单方保密协议"]。你的默认立场是什么——何时应为绿色,何时黄色,何时红色?我会将其添加到
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md中,以便下次审查保持一致。
然后将答案记录到 ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md 中,并使用新立场继续分类。
范围检查
在审查保密协议特定条款之前,检查文件是否超出其名称所暗示的范围。 相互商业保密协议可能隐藏:禁止交易条款、许可授权、排他性、禁止招揽、竞业限制、知识产权转让、优先购买权、最惠国条款,以及管辖范围远超保密争议的仲裁/管辖条款。中国法下,这些条款受《民法典》合同编(第463条及以下 [法条原文])调整,保密协议中植入超范围的实质性权利义务可能被法院认定为格式条款(《民法典》第496-498条 [法条原文])。
如果保密协议包含超出保密范围的义务:自动标黄,不论保密协议条款分析结果如何。 标注非保密协议条款:
本文件标注为保密协议,但包含 [禁止交易 / 许可授权 / 禁止招揽 / 排他性 / 知识产权转让 / 优先购买权 / 最惠国 / 宽泛仲裁条款]。这不仅是保密协议。转律师审查。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 282 lines · 73 tokens per session scan A 73b7f1e7e1c8
nda-review is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 73 tokens to every session and 4,817 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…