saas-msa-review

saas-msa-review is a skill for Claude Code from zhou210712/claude-for-legal-ZH. It costs 75 tokens per session (1,926 once invoked), scanned A, original, Apache-2.0.

A review workflow for software-as-a-service subscription contracts. SaaS means software accessed online, usually through a recurring subscription, rather than installed once.

In plain words
What is it for?
It helps review renewal terms, price changes, data export and deletion, uptime promises and remedies, and the supplier’s use of other data processors.
Why use it?
It focuses attention on risks that grow over time, such as automatic renewal, price increases, accumulated data, service outages, and difficulty leaving the service.

Skill for Claude Code

Written for Claude Code: user-invocable in frontmatter. Also seen: mentions CLAUDE.md.

Part of the commercial-legal plugin — 9 skills, 3 agents shipped together

Good fit It helps review renewal terms, price changes, data export and deletion, uptime promises and remedies, and the supplier’s use of other data processors.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/zhou210712/claude-for-legal-zh/saas-msa-review
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add zhou210712/claude-for-legal-ZH --skill saas-msa-review
Clone the repo
git clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZH

Made for: Claude Code.

Or install commercial-legal, the plugin that ships this one along with the rest of its 9 skills, 3 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for saas-msa-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/saas-msa-review/github.svg)](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/saas-msa-review)
Your own site
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/saas-msa-review"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/saas-msa-review/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for saas-msa-review

Your own site · 80×15
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/saas-msa-review"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/saas-msa-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 75 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,926 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00075 $0.01926
Opus 5 $0.00037 $0.00963
Sonnet 5 $0.00015 $0.00385
Haiku 4.5 $0.00007 $0.00193

Measured 12d ago against content hash b3e1281fe1fe, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

saas-msa-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commercial-legal/skills/saas-msa-review/SKILL.md · 145 lines

How it starts

The opening of the file, as written. The whole thing — 145 lines — stays where its author put it; the contents beside it link to each section on GitHub.

SaaS / 订阅协议审查

事项上下文

事项上下文。 检查业务领域级 CLAUDE.md 中的 ## 事项工作区。如果 Enabled(法务用户的默认值),跳过本段其余内容——技能使用业务领域级上下文,事项机制不可见。如果已启用且没有活动事项,询问:"这是哪个事项的?"加载活动事项的 matter.md 获取事项特定上下文和覆盖设置。


目的

SaaS协议的风险画像与一次性供应商合同不同。金额随续约累积,数据不断积累,切换成本每月都在增长。本技能以此为核心进行审查。运行标准审查指引检查并叠加SaaS专项审查层。

管辖假设

SaaS条款对法域敏感。中国法下,SaaS服务协议受《民法典》合同编(第463条以下 [法条原文])调整,数据安全问题受《个人信息保护法》《数据安全法》《网络安全法》三部法律共同规制 [法条原文]。如果协议选择不同的管辖法律,或交易跨越有法定优先规则的法域,请标注——分析可能不能照搬。

不得无声补全。 研究查询返回结果很少时,报告查询到的情况并停止。不要未经询问就从网络搜索或模型知识填补空白。由律师决定是否接受较低置信度的来源。

来源归属。 引用法规、规章或案例时标注来源:[北大法宝]/[yuandian检索][网络搜索 — 需核实][模型知识 — 需核实][用户提供]

加载审查指引

哪一方? 在适用审查指引之前,确定公司在此SaaS协议中处于哪一方。通常很明显:如果对方是向你销售其平台的SaaS供应商,你是采购方。先阅读审查指引,运行来自供应商协议审查技能的所有标准检查。然后查找 SaaS立场 部分。

SaaS专项审查层

对于以下每个类别,列出合同中找到的内容并与团队立场进行对比。不要使用硬编码阈值。

1. 自动续约机制

检查:续约期限长度、取消通知窗口、通知方式、续约价格。提取并记录确切的续约日期和通知窗口,为续约追踪器提供数据。

2. 价格调整

检查:年度调价幅度、超量使用价格、"费用"的范围。参照《民法典》第470条关于合同内容的规定 [法条原文]

3. 数据可迁移性和退出

检查:导出格式、导出可用性、终止后访问、导出成本、删除证明。中国法下,《个人信息保护法》第47条规定了个人信息处理者应在特定情形下主动删除个人信息 [法条原文]

4. 运行时间和SLA

仅当业务真正依赖该服务保持运行时检查。检查:运行时间承诺、测量周期、补救措施、计划维护排除、服务积分与责任上限的互动。

5. 再处理者

根据《个人信息保护法》第21条、第23条,委托处理个人信息需告知并取得同意,向第三方提供需单独同意 [法条原文]。检查:当前列表、变更通知、反对权。

6. 服务变更和功能弃用

检查:重大不利变更、功能弃用通知期、替换功能的对等功能。

AI和机器学习权利

AI/ML数据权利判定流程。 逐一排查七个维度:

  1. 明确授权。 合同是否明确授予供应商AI训练权利?采购方通常是拒绝项。
  2. 通过政策隐含授权。 合同是否通过引用纳入隐私政策?能否通过单方政策更新增加训练权利?
  3. 匿名化标准。 供应商声称的"匿名化"标准是什么?参照GB/T 35273-2020关于匿名化和去标识化的技术标准。
  4. 竞争污染。 供应商是否为竞争对手服务?是否有竞争隔离承诺?
  5. 退出范围和持久性。 退出选项是否涵盖所有AI使用?是否在续约后仍有效?
  6. 输出所有权。 谁拥有AI生成的输出?供应商能否将输出用作训练示例?
  7. 下游监管链。 供应商使用你的数据训练AI是否为你带来监管风险?中国法下参照《生成式人工智能服务管理办法》。

将每项与审查指引立场匹配。如果协议对全部七项都没有规定,这仍然是一个发现。

责任上限判定流程

逐一排查四个维度:直接损害 vs. 间接/附带损害、上限基数(逐字引用)、上限与例外排除的互动、审查指引在每个维度上的立场。

法域差异检查

中国法下核心规则:

  • 《民法典》第506条明确无效的免责条款 [法条原文]
  • 《民法典》第584条可预见规则和第591条减损规则 [法条原文]
  • 竞业限制适用《劳动合同法》第23-24条 [法条原文]

修订粒度

默认选择能达到审查指引立场的最小编辑。替换一个词语优先于一个短语,替换一个短语优先于一句话。有疑问时,选更小的。

输出

使用供应商协议审查备忘录结构,在标准审查指引检查之后增加SaaS特定部分。

Read the full file on GitHub · 145 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 145 lines · 75 tokens per session scan A b3e1281fe1fe

Subscribe to this mod's changes

saas-msa-review is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 75 tokens to every session and 1,926 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

specification-writing

A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.

wanshuiyin/Auto-claude-code-research-in-sleep · 49 tokens

regulatory-research-fallback

Fallback workflow for regulatory research when web extraction tools fail on government PDFs.

HKUDS/OpenSpace · 20 tokens

x-scorecard

OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.

x-cmd/x-cmd · 57 tokens

gesellschaftsrechtliche-satzungen-agb

Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.

Klotzkette/claude-fuer-deutsches-recht · 69 tokens

memstack-business-gdpr

Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…

cwinvestments/memstack · 121 tokens

nda-review

Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…

LegalQuants/lq-ai · 79 tokens