nda-screening
Rapidly evaluate incoming NDAs, classify them as GREEN (sign-ready), YELLOW (minor issues needing review), or RED (material problems requiring negotiation), and route them appropriately. Use when sales or business development sends a new NDA, when triaging confidentiality agreements, when deciding if an NDA can be approved without counsel, or when assessing non-disclosure agreement risk.
What this skill does
## Evaluation Framework Work through the following ten areas systematically for every NDA that comes in. ### 1. Agreement Format and Direction - **Mutual vs. unilateral**: Determine whether both parties share information (mutual) or only one side discloses (unilateral, and if so, confirm the direction is correct for the relationship) - **Context fit**: Verify the NDA type matches the business scenario -- mutual for exploratory discussions, unilateral when information flows one way - **Standalone check**: Confirm this is a pure confidentiality agreement rather than a confidentiality section buried inside a broader commercial contract ### 2. Scope of Protected Information - **Breadth**: The definition should be appropriately bounded, not an all-encompassing net like "any and all information regardless of form or marking" - **Designation mechanics**: If marking or written identification is required, confirm the process is workable (written confirmation within 30 days of oral disclosure is the market norm) - **Required exceptions**: Standard carve-outs must be present (see Area 4 below) - **Overreach**: The definition must not capture publicly available data or material the receiving party developed on its own ### 3. Recipient Duties - **Care standard**: The agreement should require reasonable care, or at minimum the same level of protection the recipient applies to its own sensitive information - **Purpose limitation**: Usage must be confined to the stated business objective - **Sharing restrictions**: Distribution limited to individuals with a genuine need who are bound by equivalent obligations - **Practicality**: No operationally burdensome mandates such as encrypting every communication or maintaining physical access logs ### 4. Required Carve-Outs Every acceptable NDA must contain all five of these exceptions: - **Publicly available**: Information already in or entering the public domain without fault of the recipient - **Already known**: Information the recipient possessed before it was disclosed - **Self-developed**: Information the recipient created independently without accessing or referencing the disclosed material - **Legitimate third-party source**: Information obtained from another party who was free to share it - **Compelled disclosure**: The right to disclose under legal, regulatory, or judicial compulsion, with notice to the discloser where law permits ### 5. Authorized Sharing - **Internal personnel**: Employees with a need to access the information - **Professional advisors**: Outside counsel, accountants, and consultants operating under matching confidentiality duties - **Corporate affiliates**: Parent, subsidiary, or sister companies when the business purpose requires it - **Regulatory and judicial**: Disclosures mandated by law, regulation, or court order ### 6. Time Boundaries - **Agreement duration**: A reasonable window for the business relationship, typically one to three years - **Post-termination survival**: Confidentiality duties should persist for a defined period after the agreement ends, typically two to five years; trade secrets may justify longer protection - **No perpetual obligations**: Indefinite confidentiality commitments are unacceptable unless narrowly limited to trade secret material ### 7. Information Return and Disposal - **Trigger**: Obligation activates upon termination or upon written request - **Scope**: Covers all copies of protected information in any medium - **Compliance exception**: Must allow retention of copies that law, regulation, or internal compliance and backup policies require - **Verification**: A written confirmation of disposal is standard; a sworn affidavit is excessive ### 8. Enforcement and Remedies - **Equitable relief**: An acknowledgment that breach could cause irreparable harm and that injunctive or equitable remedies may be appropriate -- this is standard language - **No pre-set damages**: Liquidated damages provisions are unusual and unwelcome in NDAs - **Balanced application**: In mutual agreements, remedy provisions should apply equally to both sides ### 9. Hidden Provisions to Flag Watch for terms that do not belong in a standard confidentiality agreement: - **Employee non-solicitation** -- inappropriate in an NDA - **Non-compete restrictions** -- inappropriate in an NDA - **Exclusivity** -- should not prevent either party from pursuing parallel discussions with others - **Standstill** -- only appropriate in a formal M&A context - **Residuals clause** -- if present, must be tightly limited to unaided memory of authorized individuals and must exclude trade secrets and patented material - **IP transfer or license** -- an NDA should grant zero intellectual property rights - **Audit provisions** -- not customary in standard confidentiality agreements ### 10. Jurisdiction and Dispute Mechanics - **Forum selection**: Should be a well-regarded commercial jurisdiction - **Internal consistency**: Governing law and dispute forum should be in the same or closely related jurisdictions - **Dispute pathway**: Litigation is generally preferred over arbitration for NDA disputes; mandatory arbitration is a flag ## Classification Rules ### GREEN -- Approve for Signature **Every one** of these conditions must hold: - Mutual structure (or correctly-directed unilateral) - All five required carve-outs present - Duration within standard bands (one to three year term, two to five year survival) - Free of non-solicitation, non-compete, and exclusivity provisions - No residuals clause, or one that is tightly constrained - Reasonable forum and governing law - Standard remedy provisions without liquidated damages - Authorized sharing extends to employees, advisors, and contractors - Return/disposal provisions include a compliance retention exception - Confidential information definition is reasonably bounded **Next step**: Route for execution under standard delegation authority. No attorney review needed. ### YELLOW -- Targeted Attorney Review **At least one** of these conditions exists, but the agreement is fundamentally sound: - Confidential information definition is broader than ideal but not unreasonable - Duration exceeds the standard band but remains within market norms (five-year term, seven-year survival) - One standard carve-out is absent but could be easily added - Residuals clause exists but is narrowly tailored to unaided memory - Governing law in an acceptable but secondary-choice jurisdiction - Modest asymmetry in a mutual agreement (one party has slightly wider sharing rights) - Marking requirements exist but are manageable in practice - Return/disposal section lacks an explicit compliance retention exception (likely implied, should be added) - Unusual but benign provisions (such as a duty to report suspected breaches) **Next step**: Forward to the assigned reviewer with a specific list of issues. Typically resolvable with a single round of targeted edits. ### RED -- Full Legal Engagement Required **At least one** of these conditions exists: - Wrong structure for the relationship (unilateral when mutual is needed, or facing the wrong direction) - Critical carve-outs missing (particularly independent development or compelled disclosure) - Non-solicitation or non-compete language embedded in the NDA - Exclusivity or standstill terms without proper M&A context - Extreme duration (ten or more years, or perpetual without trade secret justification) - Definition so broad it could encompass public information or independently created work - Expansive residuals clause that functions as a de facto usage license - Intellectual property assignment or license grant concealed in the NDA - Liquidated damages or penalty terms - Audit rights with vague scope or no notice requirements - Hostile jurisdiction combined with mandatory arbitration - The document is not actually a confidentiality agreement (contains substantive commercial obligations, exclusivity, or deal term
Related in Code Review
gstack
IncludedFast headless browser for QA testing and site dogfooding. Navigate pages, interact with elements, verify state, diff before/after, take annotated screenshots, test responsive layouts, forms, uploads, dialogs, and capture bug evidence. Use when asked to open or test a site, verify a deployment, dogfood a user flow, or file a bug with screenshots. (gstack)
startup-due-diligence
IncludedLegal due diligence review for seed-stage and Series A startups (US, Delaware C-Corp focus). Supports both investor and founder perspectives. Capabilities include: (1) Interactive document review and issue spotting; (2) Document request list generation; (3) Cap table and SAFE/convertible note analysis; (4) Red flag identification with severity ratings; (5) Diligence report generation. TRIGGERS: due diligence, DD, startup investment, cap table review, Series A, seed round, investor diligence, legal review startup, SAFE analysis, convertible note, 409A, founder vesting.
interview-master
IncludedThis skill should be used when the user asks to "generate interview questions", "prepare for interview", "optimize resume", "conduct mock interview", "analyze git commits for resume", "generate resume from code", "review my resume", or mentions interview preparation, career assistance, or extracting project experience from git history. Provides comprehensive interview and career development guidance for both job seekers and interviewers.
fix-issue
IncludedFixes GitHub issues using parallel analysis agents for root cause investigation, code exploration, and regression detection. Reads issue context from gh CLI, searches codebase and memory for related patterns, generates a fix with tests, and links the resolution back to the issue via PR. Includes prevention analysis to avoid recurrence. Use when debugging errors, resolving regressions, fixing bugs, or triaging issues.
sf-apex
IncludedGenerates and reviews Salesforce Apex code with 150-point scoring. TRIGGER when: user writes, reviews, or fixes Apex classes, triggers, test classes, batch/queueable/schedulable jobs, or touches .cls/.trigger files. DO NOT TRIGGER when: LWC JavaScript (use sf-lwc), Flow XML (use sf-flow), SOQL-only queries (use sf-soql), or non-Salesforce code.
swift-development
IncludedComprehensive Swift development for building, testing, and deploying iOS/macOS applications. Use when Claude needs to: (1) Build Swift packages or Xcode projects from command line, (2) Run tests with XCTest or Swift Testing framework, (3) Manage iOS simulators with simctl, (4) Handle code signing, provisioning profiles, and app distribution, (5) Format or lint Swift code with SwiftFormat/SwiftLint, (6) Work with Swift Package Manager (SPM), (7) Implement Swift 6 concurrency patterns (async/await, actors, Sendable), (8) Create SwiftUI views with MVVM architecture, (9) Set up Core Data or SwiftData persistence, or any other Swift/iOS/macOS development tasks.