Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zhou210712/claude-for-legal-ZH --skill vendor-agreement-reviewgit clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZHWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/vendor-agreement-review)<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/vendor-agreement-review"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/vendor-agreement-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/vendor-agreement-review"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/vendor-agreement-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00070 | $0.03133 |
| Opus 5 | $0.00035 | $0.01566 |
| Sonnet 5 | $0.00014 | $0.00627 |
| Haiku 4.5 | $0.00007 | $0.00313 |
Grade A, and why
vendor-agreement-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 246 lines — stays where its author put it; the contents beside it link to each section on GitHub.
供应商协议审查
事项上下文
事项上下文。 检查业务领域级 CLAUDE.md 中的 ## 事项工作区。如果 Enabled 为 ✗(法务用户的默认值),跳过本段其余内容——技能使用业务领域级上下文,事项机制不可见。如果已启用且没有活动事项,询问:"这是哪个事项的?运行 /commercial-legal:matter-workspace switch <slug> 或说 practice-level。"加载活动事项的 matter.md 获取事项特定上下文和覆盖设置。将输出写入事项文件夹。除非 跨事项上下文 为 on,否则绝不读取其他事项的文件。
发送对象检查
生成输出前,检查发送对象。如果用户指定了发送对象(频道、分发列表、对方当事人、"所有人"),询问是否在保密特权范围内。公共频道、全公司列表、对方当事人/对方律师、供应商和客户均放弃保护。当发送对象在圈外时,标注并给出 (a) 仅限法务查看的保密版本,(b) 适用于更广泛渠道的脱敏版本,或 (c) 两者。参见本插件 CLAUDE.md 中的 ## 共享安全机制 → 发送目的地检查。
目的
根据本团队实际使用的审查指引阅读供应商协议,找出每项偏离条款,并告诉律师每项如何处理——附带具体修订语言,而非模糊的"可考虑修改"。输出为律师可以一次性操作的审查备忘录。
前提条件:加载审查指引
在阅读合同之前,阅读 ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md。 如果文件缺失或仍有占位符,弹出以下提示:
我注意到你尚未配置业务领域配置。运行
/commercial-legal:cold-start-interview(2分钟)配置你的业务领域。或说 "临时模式" 我将按通用默认值审查——中国法管辖、中等风险偏好、律师角色、无审查指引。每个输出标注[临时模式]。
哪一方? 在适用审查指引之前,确定公司在此合同中处于哪一方。通常很明显:如果对方是提供产品或服务的供应商,你是采购方。如果对方是购买你产品的客户,你是销售方。如果不明显,询问。如果匹配方向为 [未配置],停止并告知用户先运行 /commercial-legal:cold-start-interview --side <side>。
本技能通常用于采购方合同(供应商向你提供),但方向检查仍然适用。
~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md 中的审查指引是真实来源。它告诉你本团队的标准立场、曾经接受的让步、从不接受的内容、审批权限以及需要首先检查的deal-breaker。
工作流
步骤1:定位
快速通读一遍整个协议。回答:
| 问题 | 答案 |
|---|---|
| 这是哪种协议? | 主协议 / SaaS订阅 / 专业服务 / 许可 / 其他 |
| 我们是谁? | 客户 / 供应商(本插件默认客户——如不是,标注) |
| 对方当事人 | 名称,且是大型企业(不谈判)还是初创企业(会谈)? |
| 金额 | 年度/总合同价值(如有说明) |
| 期限 | 期限长度、续约机制 |
| 是否有数据处理协议? | 附带 / 通过URL引用 / 缺失 |
| 是否有订单? | 单独文件或集成在内 |
金额处理。 如果主协议未说明金额(订单载明价格,这是典型情况),停止并询问:
主协议本身未说明年度合同价值。订单载明价格。我需要年度合同价值进行路由。选项:(1) 粘贴订单价值,(2) 告诉我是高于还是低于阈值,(3) 保守路由至更高审批人。
通过引用纳入的数据处理协议处理。 如果主协议通过引用纳入数据处理协议("可在 [URL] 获取"),明确注明数据保护分析不完整,建议路由数据处理协议进行单独审查。
步骤2:deal-breaker检查
首先检查审查指引中的"那一件事"。如存在:
## ⛔ 存在DEAL-BREAKER
**第 [X.X] 条** 包含 [deal-breaker]。根据团队审查指引,这是硬性拒绝。建议:
- [ ] 驳回——提出具体替代语言
- [ ] 退出——如果对方不让步,我们不签
以下详细审查仅为完整性提供,但除非此项解决,否则没有实际意义。
步骤3:逐条对比
对于审查指引中的每个类别,找到对应的合同条款并进行比较。
对每项偏离,生成:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 246 lines · 70 tokens per session scan A 5087ab1edd82
vendor-agreement-review is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 70 tokens to every session and 3,133 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…