legal-review
Review legal documents (NDA, contracts, agreements) for sensitive clauses, risks, and red flags
What this skill does
# Legal Document Review
> Analyze legal documents for sensitive clauses, risks, unfavorable terms, and red flags. Provides structured review with risk assessment and recommendations.
## When to use
- User asks to review an NDA, contract, or legal agreement
- User wants to find sensitive or risky clauses in a legal document
- User needs to understand implications of a legal document before signing
- User asks to compare document terms against standard/fair practices
## Dependencies
- External: python3 (for DOCX extraction via python-docx)
## How to execute
### Step 1: Extract document text
If the document is a DOCX file, extract text:
```python
from docx import Document
doc = Document('path/to/file.docx')
# Handle both paragraph-based and table-based layouts
text_parts = []
for p in doc.paragraphs:
if p.text.strip():
text_parts.append(p.text)
for table in doc.tables:
for row in table.rows:
for cell in row.cells:
if cell.text.strip():
text_parts.append(cell.text)
```
If PDF, use the Read tool directly (it supports PDFs).
### Step 2: Analyze document
Perform structured analysis covering ALL of the following areas:
#### A. Document Overview
- Type of document (NDA, MSA, SoW, etc.)
- Parties involved and their roles
- Effective date and duration
- Governing law and jurisdiction
#### B. Sensitive Clauses Detection
Scan for and flag these categories with severity levels:
| Category | What to look for | Severity |
|----------|-----------------|----------|
| **Non-compete / Non-solicitation** | Restrictions on working with competitors, hiring employees | HIGH |
| **Unlimited liability** | No cap on damages, indemnification without limits | HIGH |
| **Unilateral termination** | One party can terminate freely, other cannot | HIGH |
| **IP assignment** | Broad IP transfer clauses, work-for-hire beyond scope | HIGH |
| **Penalty clauses** | Financial penalties for breach, liquidated damages | HIGH |
| **Governing law mismatch** | Law of unfamiliar jurisdiction, unfavorable forum | MEDIUM |
| **Confidentiality duration** | Unusually long (>5 years) or perpetual obligations | MEDIUM |
| **Auto-renewal / Lock-in** | Automatic extension, difficult exit terms | MEDIUM |
| **Data processing** | Personal data obligations, GDPR/privacy compliance | MEDIUM |
| **Audit rights** | Right to audit your systems, records, premises | MEDIUM |
| **Force majeure** | Missing or one-sided force majeure clause | LOW |
| **Notice requirements** | Unreasonable notice periods, specific delivery methods | LOW |
| **Amendment process** | Unilateral right to modify terms | MEDIUM |
| **Waiver of jury trial** | Waiving right to jury trial or class action | LOW |
| **Survival clauses** | Obligations that survive termination and their duration | LOW |
#### C. Asymmetry Analysis
Check whether obligations are mutual or one-sided:
- Are confidentiality obligations symmetric?
- Are termination rights equal?
- Are liability and indemnification balanced?
- Who bears more risk?
#### D. Missing Clauses
Flag important clauses that are ABSENT:
- Limitation of liability
- Dispute resolution mechanism
- Data protection / GDPR
- Force majeure
- Warranty disclaimers
- Return/destruction of materials timeline
#### E. Language Red Flags
Flag vague or overly broad language:
- "including but not limited to" with open-ended lists
- "sole discretion" granted to one party
- "reasonable" without defined criteria
- "best efforts" vs "commercially reasonable efforts"
- "any and all" sweeping language
- Undefined key terms
### Step 3: Generate report
Output a structured report:
```
## LEGAL DOCUMENT REVIEW
### Document Info
- Type: [NDA/Contract/etc.]
- Parties: [Party A] <-> [Party B]
- Date: [effective date]
- Duration: [term]
- Governing Law: [jurisdiction]
### Risk Summary
- Overall Risk Level: [LOW / MEDIUM / HIGH / CRITICAL]
- HIGH risks found: [count]
- MEDIUM risks found: [count]
### Sensitive Clauses Found
#### [HIGH] [Category Name]
- Clause: [quote or reference]
- Risk: [what this means for you]
- Recommendation: [what to negotiate or change]
#### [MEDIUM] [Category Name]
...
### Asymmetry Issues
- [list of imbalanced terms]
### Missing Protections
- [list of absent but recommended clauses]
### Recommendations
1. [Prioritized list of changes to request before signing]
```
## Parameters
| Parameter | Description | Default |
|-----------|-------------|---------|
| `file_path` | Path to the document (DOCX, PDF, or TXT) | required |
| `party` | Which party you represent (for perspective) | auto-detect from context |
| `focus` | Specific areas to focus on (e.g., "IP", "liability") | all areas |
## Examples
### Example 1: Review NDA before signing
User: "Review this NDA from Client G"
-> Extract DOCX, run full analysis, output structured report
### Example 2: Focus on specific concerns
User: "Check this contract for IP risks"
-> Run analysis with focus on IP assignment, work-for-hire, licensing clauses
## Limitations
- This is AI-assisted analysis, NOT legal advice
- Always consult a qualified lawyer for important agreements
- May miss jurisdiction-specific legal nuances
- Cannot verify factual claims (e.g., company registration codes)
## Related skills
- `invoice-generator-agent` — for creating invoices referenced in contracts
- `email-send-bulk` — for sending signed documents back
Related in Code Review
gstack
IncludedFast headless browser for QA testing and site dogfooding. Navigate pages, interact with elements, verify state, diff before/after, take annotated screenshots, test responsive layouts, forms, uploads, dialogs, and capture bug evidence. Use when asked to open or test a site, verify a deployment, dogfood a user flow, or file a bug with screenshots. (gstack)
startup-due-diligence
IncludedLegal due diligence review for seed-stage and Series A startups (US, Delaware C-Corp focus). Supports both investor and founder perspectives. Capabilities include: (1) Interactive document review and issue spotting; (2) Document request list generation; (3) Cap table and SAFE/convertible note analysis; (4) Red flag identification with severity ratings; (5) Diligence report generation. TRIGGERS: due diligence, DD, startup investment, cap table review, Series A, seed round, investor diligence, legal review startup, SAFE analysis, convertible note, 409A, founder vesting.
interview-master
IncludedThis skill should be used when the user asks to "generate interview questions", "prepare for interview", "optimize resume", "conduct mock interview", "analyze git commits for resume", "generate resume from code", "review my resume", or mentions interview preparation, career assistance, or extracting project experience from git history. Provides comprehensive interview and career development guidance for both job seekers and interviewers.
fix-issue
IncludedFixes GitHub issues using parallel analysis agents for root cause investigation, code exploration, and regression detection. Reads issue context from gh CLI, searches codebase and memory for related patterns, generates a fix with tests, and links the resolution back to the issue via PR. Includes prevention analysis to avoid recurrence. Use when debugging errors, resolving regressions, fixing bugs, or triaging issues.
sf-apex
IncludedGenerates and reviews Salesforce Apex code with 150-point scoring. TRIGGER when: user writes, reviews, or fixes Apex classes, triggers, test classes, batch/queueable/schedulable jobs, or touches .cls/.trigger files. DO NOT TRIGGER when: LWC JavaScript (use sf-lwc), Flow XML (use sf-flow), SOQL-only queries (use sf-soql), or non-Salesforce code.
swift-development
IncludedComprehensive Swift development for building, testing, and deploying iOS/macOS applications. Use when Claude needs to: (1) Build Swift packages or Xcode projects from command line, (2) Run tests with XCTest or Swift Testing framework, (3) Manage iOS simulators with simctl, (4) Handle code signing, provisioning profiles, and app distribution, (5) Format or lint Swift code with SwiftFormat/SwiftLint, (6) Work with Swift Package Manager (SPM), (7) Implement Swift 6 concurrency patterns (async/await, actors, Sendable), (8) Create SwiftUI views with MVVM architecture, (9) Set up Core Data or SwiftData persistence, or any other Swift/iOS/macOS development tasks.