nda-review-jamie-tso
Guide to review incoming one-way (unilateral) commercial NDAs in a jurisdiction-agnostic way, from either a Recipient or Discloser perspective (user-selected), producing a clause-by-clause issue log with preferred redlines, fallbacks, rationales, owners, and deadlines.
What this skill does
# NDA Review Playbook (Commercial, Jurisdiction-Agnostic) ## Overview | What this skill does | What it does not do | |---|---| | Reviews an NDA and outputs issues, risks, and suggested redlines | Provide jurisdiction-specific legal conclusions | | Supports *Recipient* or *Discloser* perspectives (user-chosen) | Guarantee enforceability | | Produces an executive summary + clause-by-clause markup guidance | Replace counsel for complex deals | **Scope limitation (important):** this playbook supports **one-way (unilateral) commercial NDAs only**. If the NDA is **mutual**, stop: this playbook is **out of scope** and you should escalate to counsel or use a separate mutual-NDA review approach. > **Variation callouts** appear throughout: > - **M&A / Due diligence** > - **Employment / contractor** > - **Investor / VC** ## LEGAL DISCLAIMER **THIS IS NOT LEGAL ADVICE.** This skill is provided for informational and educational purposes only. Laws vary by jurisdiction and individual circumstances, and only a licensed attorney can provide advice tailored to your specific situation. When the NDA is high-risk, high-value, cross-border, or otherwise sensitive, escalate to qualified counsel. **Remember:** All outputs from this skill must be reviewed by a qualified legal professional before being used for any legal purposes. --- ## Inputs to collect (ask before reviewing) ### A. Role and deal context (required) - [ ] Are we reviewing as **Recipient** (we receive confidential info) or **Discloser** (we disclose confidential info)? - [ ] Confirm the NDA is **one-way (unilateral)**. If it is **mutual**, stop: this playbook cannot be used. - [ ] What is the **purpose** / permitted use (e.g., evaluation of partnership, vendor RFP, diligence)? - [ ] What are the **parties** (legal names) and any **affiliates** that should be covered? - [ ] What information types are expected (tech, pricing, customer data, product roadmap, source code)? - [ ] Desired **timeline**: when do we need to sign? ### B. Practical constraints (recommended) - [ ] Do we need to share with **affiliates**, advisors, contractors, auditors, or potential acquirers? - [ ] Will we need to **export** data across borders or store in cloud tools? - [ ] Will any **personal data** be shared? If yes, are there separate data-processing terms? > **Jurisdiction-agnostic note:** avoid asserting “this clause is invalid” without the governing law details; focus on *commercial risk*, *operational feasibility*, and *market norms*. ## Deliverables (output format) ### Quick start (default output template) ALWAYS output: 1) **Executive summary** 2) **Clause-by-clause issue log** (single table) ### A. Executive summary (1 page) - [ ] Party role (Recipient or Discloser) and confirmation it is one-way (unilateral) - [ ] Top 5 negotiation points (ranked) - [ ] “Sign as-is” / “Sign with changes” / “Escalate” recommendation ### B. Clause-by-clause issue log (lawyer-style, thorough) Use a single table so counsel and business owners can track issues, owners, and deadlines. | Clause | Issue (1 line) | Risk (H/M/L) | Preferred redline | Fallback | Rationale (1–2 sentences) | Owner | Deadline | |---|---|---:|---|---|---|---|---| | Definition | Overbroad; includes unmarked info with no reasonableness | | | | | | | | Term & survival | Perpetual confidentiality for all information | | | | | | | | Use restriction | Purpose too broad; blocks internal evaluation | | | | | | | | Disclosures | Representatives undefined; strict liability | | | | | | | | Return/destruction | No backup carve-out | | | | | | | | Remedies | One-way fees + automatic injunction | | | | | | | | Liability | Indemnity + unlimited consequential damages | | | | | | | | Boilerplate | Assignment prohibits change of control | | | | | | | ### Example (compact) **Executive summary (example skeleton):** - Role: Recipient (one-way NDA) - Recommendation: Sign with changes - Top 5 points: definition scope; term/survival; representatives; backup carve-out; remedies/fees **Issue log (example rows):** | Clause | Issue (1 line) | Risk (H/M/L) | Preferred redline | Fallback | Rationale (1–2 sentences) | Owner | Deadline | |---|---|---:|---|---|---|---|---| | Term & survival | Perpetual confidentiality for all information | H | Add 2–5 year survival; trade secret carve-out only | 5-year survival for all | Reduces indefinite operational burden while protecting truly sensitive info | Legal | Before signature | | Return/destruction | No backup carve-out | M | Add backup/legal hold exception + continued confidentiality | Allow retention in immutable backups only | Required for standard IT operations; avoids impossible compliance | Security + Legal | Before signature | ## 5-step workflow ### Step 1 — Identify stance (Recipient vs Discloser) - [ ] Confirm which side we are on for *this specific NDA* (titles are often misleading). - [ ] Confirm the NDA is **one-way (unilateral)**. If it is mutual, stop (out of scope). **Quick heuristic:** - If we are being asked to keep their info secret → we are **Recipient**. - If we are sharing our sensitive info → we are **Discloser** (if the NDA is mutual, stop: out of scope). ### Step 2 — Triage the NDA (fast risk scan) Flag these immediately: - [ ] **Perpetual** confidentiality for *all* information (no trade secret distinction) - [ ] **Residuals clause** allowing use of “memory” or generalized knowledge - [ ] **Injunctive relief** + **attorneys’ fees** one-way against Recipient - [ ] **Indemnity** for breach or broad third-party claims - [ ] **No carve-outs** for compelled disclosure or prior knowledge - [ ] **Overbroad definition**: “all information, whether marked or not” with no reasonableness - [ ] **Affiliate coverage** missing when we must share internally > If any are present and the NDA matters, proceed with full review and consider escalation. ### Step 3 — Clause-by-clause review (use the reference modules) Use these references while reviewing: - [Key clauses](references/KEY_CLAUSES.md) - [Party obligations](references/PARTY_OBLIGATIONS.md) - [Duration & scope](references/DURATION_SCOPE.md) - [Remedies & liability](references/REMEDIES_LIABILITY.md) - [Standard exceptions](references/STANDARD_EXCEPTIONS.md) ### Step 4 — Draft redlines and negotiation positions For each issue, produce: - **Preferred redline** (best risk outcome) - **Fallback position** (acceptable compromise) - **Rationale** (1–2 sentences: business + operational feasibility) - **Owner** (who needs to approve / negotiate: Legal, Sales, Security, Product) - **Deadline** (by when the counterparty needs the change) **Negotiation discipline:** do not propose 20 changes. Focus on the 5–10 that materially change risk. ### Step 5 — Finalize the package - [ ] Ensure consistency (definitions used the same way everywhere) - [ ] Confirm operational feasibility (can we actually comply?) - [ ] Re-scan the Step 2 triage list and ensure each flagged item is represented in the issue log - [ ] Provide a short “what we changed and why” summary ## Perspective-specific checklists ### A. Recipient checklist (incoming NDA — typical case) | Topic | Red flags | Typical ask | |---|---|---| | Definition of Confidential Information | Overbroad; includes independently developed info; no marking/identification standard | Add reasonableness + identification standard; add exclusions | | Purpose / Permitted Use | Any use restriction beyond evaluation; bans on internal sharing | Tie to stated purpose; allow internal need-to-know | | Representatives | We are liable for any representative breach without control | Limit to those under written confidentiality; commercially reasonable care | | Term & survival | Perpetual for everything; unclear start date | Fixed term; longer only for trade secrets | | Return / destruction | Requires deletion of backups immediately | Add practical backup carve-out | | Remedies | One-way fees + broad
Related in Code Review
gstack
IncludedFast headless browser for QA testing and site dogfooding. Navigate pages, interact with elements, verify state, diff before/after, take annotated screenshots, test responsive layouts, forms, uploads, dialogs, and capture bug evidence. Use when asked to open or test a site, verify a deployment, dogfood a user flow, or file a bug with screenshots. (gstack)
startup-due-diligence
IncludedLegal due diligence review for seed-stage and Series A startups (US, Delaware C-Corp focus). Supports both investor and founder perspectives. Capabilities include: (1) Interactive document review and issue spotting; (2) Document request list generation; (3) Cap table and SAFE/convertible note analysis; (4) Red flag identification with severity ratings; (5) Diligence report generation. TRIGGERS: due diligence, DD, startup investment, cap table review, Series A, seed round, investor diligence, legal review startup, SAFE analysis, convertible note, 409A, founder vesting.
interview-master
IncludedThis skill should be used when the user asks to "generate interview questions", "prepare for interview", "optimize resume", "conduct mock interview", "analyze git commits for resume", "generate resume from code", "review my resume", or mentions interview preparation, career assistance, or extracting project experience from git history. Provides comprehensive interview and career development guidance for both job seekers and interviewers.
fix-issue
IncludedFixes GitHub issues using parallel analysis agents for root cause investigation, code exploration, and regression detection. Reads issue context from gh CLI, searches codebase and memory for related patterns, generates a fix with tests, and links the resolution back to the issue via PR. Includes prevention analysis to avoid recurrence. Use when debugging errors, resolving regressions, fixing bugs, or triaging issues.
sf-apex
IncludedGenerates and reviews Salesforce Apex code with 150-point scoring. TRIGGER when: user writes, reviews, or fixes Apex classes, triggers, test classes, batch/queueable/schedulable jobs, or touches .cls/.trigger files. DO NOT TRIGGER when: LWC JavaScript (use sf-lwc), Flow XML (use sf-flow), SOQL-only queries (use sf-soql), or non-Salesforce code.
swift-development
IncludedComprehensive Swift development for building, testing, and deploying iOS/macOS applications. Use when Claude needs to: (1) Build Swift packages or Xcode projects from command line, (2) Run tests with XCTest or Swift Testing framework, (3) Manage iOS simulators with simctl, (4) Handle code signing, provisioning profiles, and app distribution, (5) Format or lint Swift code with SwiftFormat/SwiftLint, (6) Work with Swift Package Manager (SPM), (7) Implement Swift 6 concurrency patterns (async/await, actors, Sendable), (8) Create SwiftUI views with MVVM architecture, (9) Set up Core Data or SwiftData persistence, or any other Swift/iOS/macOS development tasks.