vendor-ai-review

vendor-ai-review is a skill for Claude Code from zhou210712/claude-for-legal-ZH. It costs 78 tokens per session (2,835 once invoked), scanned A, original, Apache-2.0.

A contract review guide for agreements with AI suppliers, such as AI software subscriptions, model licences, or application programming interface (API) services. It checks issues including training on customer data, liability, model-change notices, and compliance responsibilities.

In plain words
What is it for?
Use it when evaluating an AI vendor’s terms. It helps classify the service, examine training-data practices, mark unacceptable provisions, and produce a negotiating position.
Why use it?
AI supplier contracts can create risks that ordinary technology agreements do not clearly address. A systematic review helps identify who controls data, who bears responsibility, and what happens when the model or law changes.

Skill for Claude Code

Written for Claude Code: argument-hint in frontmatter. Also seen: reads .claude/ paths; mentions CLAUDE.md.

Part of the ai-governance-legal plugin — 10 skills, 3 MCP servers shipped together

Good fit Use it when evaluating an AI vendor’s terms. It helps classify the service, examine training-data practices, mark unacceptable provisions, and produce a negotiating position.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/zhou210712/claude-for-legal-zh/vendor-ai-review
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add zhou210712/claude-for-legal-ZH --skill vendor-ai-review
Clone the repo
git clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZH

Made for: Claude Code.

Or install ai-governance-legal, the plugin that ships this one along with the rest of its 10 skills, 3 MCP servers.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for vendor-ai-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/vendor-ai-review/github.svg)](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/vendor-ai-review)
Your own site
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/vendor-ai-review"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/vendor-ai-review/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for vendor-ai-review

Your own site · 80×15
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/vendor-ai-review"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/vendor-ai-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 78 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,835 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00078 $0.02835
Opus 5 $0.00039 $0.01418
Sonnet 5 $0.00016 $0.00567
Haiku 4.5 $0.00008 $0.00283

Measured 12d ago against content hash 6ff4bc77202b, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

vendor-ai-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

ai-governance-legal/skills/vendor-ai-review/SKILL.md · 209 lines

How it starts

The opening of the file, as written. The whole thing — 209 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/vendor-ai-review

  1. 读取 ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → 合同审查立场、可接受风险阈值、红线条款。
  2. 运行以下工作流。
  3. 逐项核查AI特定风险——训练数据→责任→模型变更→合规传导。
  4. 输出:风险总结 + 红线标记 + 谈判立场(经核准/附条件/阻止)。
/ai-governance-legal:vendor-ai-review
[paste the vendor AI terms]

AI供应商合同审查

事务上下文

事务上下文。 检查实践级 CLAUDE.md 中的 ## 事务工作区。如果 已启用,跳过本段其余部分。如果已启用且无活跃事务,询问事务归属。加载活跃事务的 matter.md。除非 跨事务上下文,否则绝不读取其他事务的文件。


目的

AI供应商合同引入了传统技术合同没有的风险维度——供应商是否使用你的数据训练模型、模型变更时你会不会得到通知、如果AI产生了侵权内容谁承担风险、供应商是否完成了法定的算法备案和安全评估(《生成式人工智能服务管理办法》第17条 [法条原文])。此技能系统性地审查这些风险。

加载当前状态

读取 ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md

  • ## 合同审查配置 — 公司立场、风险偏好、红线
  • ## 监管注册表 — 适用的法规框架
  • ## 已批准的供应商 — 既有关系和已通过审查的条款

审查框架

第1步:服务定性

首先明确供应商提供的是什么:

模型提供方式 说明 关键风险
API接口 通过云端API调用模型 数据传输安全、数据是否被记录用于训练
本地部署 模型部署在自有服务器 安全可控性高,但更新和升级依赖供应商
SaaS产品 使用供应商的AI功能产品 使用条款可能不清晰,数据用途条款需特别关注
模型授权/定制 授权基础模型进行微调 知识产权归属、模型更新的兼容性

第2步:训练数据检查

这是AI合同审查中最重要的部分。

核心问题链
  1. 供应商是否使用客户数据训练模型?
  2. 如果是,客户是否知情并同意?
  3. 训练数据中是否包含个人信息或敏感个人信息?
  4. 客户数据流出后是否可以追回("遗忘权"的实操可行性)?
审查清单
检查项 理想状态 风险标记
训练数据条款 明确约定不将客户数据用于模型训练,或经客户明确书面同意 🔴 合同沉默、或条款笼统声称供应商可"使用数据进行服务改进"
个人信息训练 不将包含个人信息的数据用于训练,或已取得个人单独同意(《个人信息保护法》第23条 [法条原文] 🔴 未区分数据类型,一刀切授权
训练数据合法性保证 供应商保证其训练数据来源合法,不侵犯第三方知识产权(《生成式人工智能服务管理办法》第7条 [法条原文] 🟠 供应商仅提供"尽力"保证或不提供保证
数据删除 合同终止后供应商删除客户数据并销毁包含客户数据的模型副本 🟠 仅承诺"停止使用"而不承诺删除
知识产权归属 明确约定微调模型的权属(客户拥有/供应商拥有/共享) 🟠 合同沉默
训练数据条款的红线
  • 供应商单方面保留"为改进服务目的"使用客户全部数据的权利,且不可协商
  • 供应商拒绝就训练数据的合法来源提供任何保证
  • 涉及个人信息且供应商拒绝签署数据处理协议(参照《个人信息保护法》第21条 [法条原文]

第3步:责任分配

AI产出的特殊性使得传统的责任条款可能无法直接适用。需要特别关注:

责任场景 供应商理想立场 风险
AI产出侵权(知识产权) 供应商承担因其训练数据或模型本身导致的侵权责任 🔴 供应商将全部侵权风险转嫁客户
AI产出违法/不良内容 供应商基于《生成式人工智能服务管理办法》承担内容安全责任 🔴 供应商声称仅为"技术中立工具"
AI产出错误导致商业损失 责任分配合理,特殊或间接损失合理排除 🟠 供应商完全免责且客户承担全部损失
模型停机/服务中断 SLA明确,有可用性承诺和服务积分/赔偿机制 🟡 SLA模糊或缺失
模型性能退化 供应商保证模型输出质量不实质性下降 🟠 供应商保留单方修改模型的权利且无通知义务

Read the full file on GitHub · 209 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 209 lines · 78 tokens per session scan A 6ff4bc77202b

Subscribe to this mod's changes

vendor-ai-review is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 78 tokens to every session and 2,835 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

specification-writing

A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.

wanshuiyin/Auto-claude-code-research-in-sleep · 49 tokens

regulatory-research-fallback

Fallback workflow for regulatory research when web extraction tools fail on government PDFs.

HKUDS/OpenSpace · 20 tokens

x-scorecard

OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.

x-cmd/x-cmd · 57 tokens

gesellschaftsrechtliche-satzungen-agb

Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.

Klotzkette/claude-fuer-deutsches-recht · 69 tokens

memstack-business-gdpr

Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…

cwinvestments/memstack · 121 tokens

nda-review

Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…

LegalQuants/lq-ai · 79 tokens