
Contract Review
- 1.8k installs
- 23.3k repo stars
- Updated August 5, 2026
- anthropics/knowledge-work-plugins
contract-review is an agent skill that apply contract-review agent skill workflows from documented skill.md guidance.
About
contract-review is an agent skill from anthropics/knowledge-work-plugins that apply contract-review agent skill workflows from documented skill.md guidance. # Contract Review ## Quick start Attach a contract file, forward the email containing it, or paste the text directly. ``` User: "Review this MSA and flag anything I should push back on." → Skill reads the document, identifies parties and contract type, analyzes 8 risk categories, returns a severity-tiered summary with a negotiation playbook, Developers invoke contract-review during operate/infra work for cloud & infrastructure tasks. The skill documents triggers, prerequisites, and step-by-step workflows grounded in SKILL.md. Compatible with Claude Code, Cursor, and Codex agent runtimes that load marketplace skills. Review the Security Audits panel on this listing before installing in production environments. Category Cloud & Infrastructure with operations vertical focus supports repeatable agent-guided delivery.
- Attach a contract file, forward the email containing it, or paste the text directly.
- User: "Review this MSA and flag anything I should push back on."
- → Skill reads the document, identifies parties and contract type,
- analyzes 8 risk categories, returns a severity-tiered summary
- with a negotiation playbook, and exports a redlined DOCX.
Contract Review by the numbers
- 1,762 all-time installs (skills.sh)
- +108 installs in the week ending Aug 5, 2026 (Skillselion tracking)
- Ranked #217 of 1,039 Cloud & Infrastructure skills by installs in the Skillselion catalog
- Security screen: MEDIUM risk (skills.sh audit)
- Data as of Aug 5, 2026 (Skillselion catalog sync)
contract-review capabilities & compatibility
- Capabilities
- attach a contract file, forward the email contai · user: "review this msa and flag anything i shoul · → skill reads the document, identifies parties a · analyzes 8 risk categories, returns a severity t · with a negotiation playbook, and exports a redli
- Use cases
- orchestration
What contract-review says it does
Attach a contract file, forward the email containing it, or paste the text directly.
User: "Review this MSA and flag anything I should push back on."
→ Skill reads the document, identifies parties and contract type,
npx skills add https://github.com/anthropics/knowledge-work-plugins --skill contract-reviewAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 1.8k |
|---|---|
| repo stars | ★ 23.3k |
| Security audit | 3 / 3 scanners passed |
| Last updated | August 5, 2026 |
| Repository | anthropics/knowledge-work-plugins ↗ |
What it does
Apply contract-review agent skill workflows from documented SKILL.md guidance.
Who is it for?
Developers working on cloud & infrastructure during operate tasks.
Skip if: Tasks outside Cloud & Infrastructure scope described in SKILL.md.
When should I use this skill?
Apply contract-review agent skill workflows from documented SKILL.md guidance.
What you get
Completed cloud & infrastructure workflow aligned with SKILL.md steps.
- Plain-English risk summary
- Marked-up redline DOCX
Files
Contract Review
Quick start
Attach a contract file, forward the email containing it, or paste the text directly.
User: "Review this MSA and flag anything I should push back on."
→ Skill reads the document, identifies parties and contract type,
analyzes 8 risk categories, returns a severity-tiered summary
with a negotiation playbook, and exports a redlined DOCX.Workflow
1. Get the contract — Pull from one of three sources, in order of preference:
- Gmail: Search for recent emails with contract attachments (see
reference/gmail-fetch.md) - DocuSign: Fetch the envelope by ID or search recent drafts awaiting signature (see
reference/docusign-fetch.md) - Local file or paste: Read the PDF (chunked via
pagesparameter for 10+ page files) or DOCX via Read tool. If the user pastes text directly, work with what's provided.
Read the full document before analyzing. Dangerous clauses are frequently in exhibits and schedules at the back.
2. Identify contract type and parties — Determine agreement type (NDA, MSA, SOW, SaaS subscription, consulting, subcontractor, vendor) and which party is the user's company vs. the counterparty. Note if it looks like a counterparty template — these are typically one-sided and the counterparty expects pushback.
3. Analyze across 8 risk categories — Work through the contract from the ops/finance perspective of a small business owner without in-house legal. Categories are ordered by typical risk severity; use judgment for context.
Category 1: Payment terms and cash flow
- Payment timing: Net-30 is standard; Net-60+ is flaggable; Net-90/120 is a hard negotiation point
- Payment triggers: acceptance periods that let the client slow-walk approvals indefinitely
- Late payment penalties: absence is a gap worth noting
- Invoicing requirements: rigid formats or PO numbers that can delay payment on technicalities
- Expense reimbursement: pre-approval requirements and caps
- Rate adjustments: annual increase mechanism for multi-year engagements
Category 2: Liability and indemnification
- Liability caps: uncapped liability is always a red flag
- Mutual vs. one-sided indemnification
- Indemnification scope: "any and all claims arising from the services" is not standard
- Insurance requirements: E&O, cyber, general liability — achievability at the required limits
- Consequential damages waiver: missing = flag prominently
Category 3: Termination and exit
- Termination for convenience: is it mutual? 30-day notice is typical
- Termination for cause: cure period; vague "material breach" without definition
- Wind-down: payment for in-progress work at termination
- Transition assistance: paid vs. unpaid, time-limited vs. open-ended
- Survival clauses: indefinite indemnification survival = flag
Category 4: Intellectual property
- IP assignment vs. license
- Pre-existing IP and background tools carve-out — absence means inadvertent assignment
- Work product definition breadth: drafts, notes, internal tools
Category 5: Scope and change management
- Scope definition clarity
- Change order process: absence = scope creep without compensation
- Acceptance criteria: subjective ("to client's satisfaction") vs. defined
- Timeline asymmetry: user penalized for delays but client is not for slow feedback
Category 6: Non-compete and exclusivity
- Non-compete scope, definition of "competitor," duration
- Exclusivity requirements on the user's company
- Non-solicitation: employee poaching is normal; industry-broad restrictions are not
Category 7: Confidentiality and data
- Confidentiality scope: "all information shared" with no exceptions is overly broad
- Duration: 2–3 years is typical; perpetual is aggressive
- Data handling security requirements vs. company size and data sensitivity
- Return/destruction requirements post-termination
Category 8: Operational concerns
- Governing law and dispute resolution; mandatory arbitration
- Auto-renewal: opt-out window and notice period (missing a 60-day window is a common SMB mistake)
- Assignment rights, especially if the client gets acquired
- Most favored nation: constrains pricing across the entire client book
- Audit rights: scope and frequency
4. Present flagged summary — Organize by severity:
🔴 Red flags (push back before signing) — For each: quote the exact clause, explain the problem in plain language, suggest specific alternative language.
🟡 Yellow flags (negotiate, not deal-breakers) — For each: quote the clause, explain the concern, describe what "better" looks like.
🟢 Key terms to note (awareness only) — Payment schedules, notice periods, renewal dates, insurance requirements, key contacts.
📋 Contract summary — Plain-language summary: who does what, for how much, over what timeframe, under what conditions.
💡 Negotiation playbook — For each red and yellow flag: what to ask for, how to frame the ask, and what a reasonable compromise looks like.
5. Export redline DOCX — After presenting the summary, offer to export a redlined DOCX with the suggested changes marked up. Use the docx skill to generate a Word document that:
- Preserves the original contract structure
- Marks suggested deletions in strikethrough and additions in underline
- Adds a cover page summarizing the changes
Ask: "Want me to export a redlined DOCX you can send back to the counterparty?"
Approval gates
- Never characterize the output as legal advice. Always recommend attorney review for red flags or binding decisions.
- Quote actual clause language, not paraphrases. The user needs the exact text for negotiation calls.
- Flag what's missing, not just what's there. A contract silent on liability caps or change orders is often more dangerous than one with unfavorable terms.
- Do not flag standard boilerplate. If a clause is fair and market-standard, skip it. The user wants signal, not a clause-by-clause restatement.
- Compare to market norms when flagging: "Net-90 is uncommon in professional services — Net-30 is standard."
- Adjust recommendations to the power dynamic. A Fortune 500 procurement MSA is a different negotiation than a small startup agreement.
- Never send the redlined DOCX to the counterparty without explicit user confirmation.
Reference
reference/gotchas.md— edge cases in contract analysisreference/docusign-fetch.md— pulling envelopes from DocuSignreference/gmail-fetch.md— finding contract attachments in Gmailreference/examples/flagged-summary-saas.md— worked example: SaaS agreement review output
DocuSign: fetching contracts for review
Use the DocuSign MCP connector to pull envelopes awaiting signature.
Fetch pending envelopes
Use getEnvelopes to list envelopes in sent or delivered status (awaiting recipient action):
Tool: getEnvelopes
Params: { status: "sent" } // or "delivered"Returns a list of envelopes with: envelopeId, emailSubject, createdDateTime, status, recipients.
Download document from envelope
Use getEnvelope with the envelopeId to get the full envelope details, then download the document for reading.
What NOT to do
- Never call
triggerWorkflowor any action that moves the envelope forward in the signing process. - Never call
updateEnvelopeto modify the document. - Never call
createEnvelope— this skill is review-only.
Fallback
If DocuSign is not connected or the envelope is not found:
"DocuSign isn't connected — paste the contract text or attach the file directly."Example: SaaS vendor agreement flagged summary
A worked example of contract-review output. Contract: a SaaS subscription agreement from a mid-size software vendor.
---
Input
"Review this SaaS agreement before I sign. We're a 12-person consulting firm."
Contract: 18-page SaaS Subscription Agreement, vendor template, governing law: California.
---
Output
📋 Contract summary
12-month SaaS subscription, auto-renewing annually. Vendor provides project management software. You pay $2,400/year billed monthly. Vendor hosts data; you own your data but grant vendor a broad license to use it for "product improvement." You can terminate with 30 days notice but owe fees through end of the contract term.
---
🔴 Red flags (push back before signing)
1. Uncapped liability
"IN NO EVENT SHALL VENDOR'S LIABILITY EXCEED THE AMOUNTS ACTUALLY PAID BY CUSTOMER IN THE THREE (3) MONTHS PRECEDING THE CLAIM."
Problem: Three months of fees = $600. If a vendor data breach exposes your client data, your recovery is capped at $600 — regardless of actual damages. For a consulting firm handling client information, this is inadequate.
Ask for: Cap at 12 months of fees paid ($2,400), or at a fixed floor of $50,000 for data security incidents. Suggested language:
"Vendor's total liability shall not exceed the greater of (a) fees paid in the twelve (12) months preceding the claim or (b) $50,000 for claims arising from data security incidents."
---
2. Auto-renewal with 60-day opt-out window
"This Agreement shall automatically renew for successive one-year terms unless either party provides written notice of non-renewal no less than sixty (60) days prior to the end of the then-current term."
Problem: You have a 60-day window to opt out. Miss it and you're committed to another year. With a $2,400/year contract, that's easy to overlook.
Ask for: Reduce to 30-day opt-out, or add a reminder obligation from vendor. Alternatively, calendar the opt-out deadline now (2027-04-01 if signing May 1, 2026).
---
🟡 Yellow flags (negotiate if possible)
3. Broad data license
"Customer grants Vendor a non-exclusive, worldwide license to use, process, and analyze Customer Data to improve Vendor's products and services."
Concern: Vendor can use your data — including client project data — to train their product. This may conflict with your client confidentiality obligations.
Ask for: Restrict to aggregated, anonymized usage only. Suggested language:
"...limited to aggregated, de-identified data and expressly excluding any Customer Data that identifies Customer's clients or projects."
---
4. No termination for cause cure period
"Vendor may terminate this Agreement immediately upon Customer's material breach."
Concern: Vendor can cut off access immediately for any "material breach" with no chance to fix it. No definition of "material." You could lose access to your data mid-project.
Ask for: 15-day cure period. Suggested: "...upon written notice and Customer's failure to cure such breach within fifteen (15) days."
---
🟢 Key terms to note
- Payment: Monthly, auto-charged. Keep credit card current or service suspends immediately.
- Data portability: You can export your data at any time and for 30 days post-termination. Plan export before cancellation.
- Governing law: California. Any disputes go to Santa Clara County courts.
- Uptime SLA: 99.5% monthly. Credits issued as account credits, not cash.
---
💡 Negotiation playbook
| Flag | Ask | Framing |
|---|---|---|
| Liability cap | Raise to 12 months ($2,400) or $50K for security incidents | "We handle client data — we need the liability cap to reflect actual risk" |
| Auto-renewal window | Reduce to 30 days | "60 days is tight for a small team — 30 is more typical" |
| Data license | Restrict to anonymized/aggregated | "Our client agreements restrict how we share their project data" |
| Termination cure | Add 15-day cure period | "We need a chance to fix issues before access is cut off" |
---
This is not legal advice. For binding decisions, consult an attorney.
---
Redline DOCX
A redlined DOCX with these suggested changes marked in tracked-changes format was exported to: contract-review-redline-2026-05-01.docx
Gmail: finding contract attachments
Use the Gmail MCP connector to find contract attachments in recent email.
Search for contract emails
Use search_threads with a query targeting recent emails with attachments:
Query: "has:attachment (contract OR agreement OR NDA OR MSA OR SOW) newer_than:14d"What to do with results
1. Present a short list (subject, sender, date) if multiple candidates match. 2. Ask the user to confirm which one before downloading. 3. Use get_thread to fetch the full thread, then locate and read the attachment.
Fallback
If Gmail is not connected or no matching attachment is found:
"I didn't find a recent contract attachment in Gmail — can you forward it or attach the file directly?"What NOT to do
- Do not read emails unrelated to the contract (no general inbox trawl).
- Do not send any reply or draft email during the review workflow.
Gotchas
Edge cases in contract analysis. Good / Bad pairs.
---
Gotcha: Flagging standard boilerplate as a red flag
Why it matters: Over-flagging trains the user to ignore the summary. If everything is a red flag, nothing is.
✗ Bad
Contract has a standard mutual NDA confidentiality clause, 2-year duration.
Claude: "🔴 Red flag: Confidentiality clause imposes obligations on both parties."Standard mutual NDA is market-norm. Flagging it as a red flag destroys signal-to-noise ratio.
✓ Good
Contract has a standard mutual NDA confidentiality clause, 2-year duration.
Claude: [skips; does not flag]Reserve red flags for genuinely non-standard terms. If a clause is boilerplate and fair, omit it.
---
Gotcha: Missing clauses aren't missing from the analysis
Why it matters: For SMBs, the absence of standard protections (liability cap, change order process, consequential damages waiver) is often more dangerous than an unfavorable clause — the default legal position fills the gap, usually in the counterparty's favor.
✗ Bad
Contract has no liability cap.
Claude: [no mention; only analyzes clauses that are present]User signs thinking liability is limited. It isn't.
✓ Good
Contract has no liability cap.
Claude: "🔴 Missing: No liability cap. This contract contains no limitation-of-liability
clause. Under default law, your exposure is uncapped. Standard practice is to cap at
fees paid in the prior 12 months. Suggest adding: 'Each party's total liability shall
not exceed the fees paid or payable in the 12 months preceding the claim.'"Treat absent-but-standard clauses as red flags. Explicitly label them "Missing."
---
Gotcha: Large PDFs truncated mid-analysis
Why it matters: Contracts over 20–30 pages often have the most dangerous terms in exhibits, schedules, or "Order Forms" at the back. If the PDF is read only up to page 15, key terms are silently missed.
✗ Bad
Skill reads pages 1–10 of a 40-page MSA. Schedules A–D (starting page 28) contain
the IP assignment and liability cap. Skill produces a "clean" summary.✓ Good
Read the PDF in chunks: pages 1–10, 11–20, 21–40. Analyze all chunks before
producing the summary. If a section heading mentions "Schedule," "Exhibit," or
"Appendix," flag it explicitly and ensure it was read.Always read the full document. Use the pages parameter to chunk large PDFs.
---
Gotcha: Counterparty template vs. negotiated draft
Why it matters: Recommendations should match the negotiating context. Pushing back hard on a startup's first-draft agreement is different from pushing back on a Fortune 500 procurement template — the latter is often non-negotiable on 80% of its terms.
✗ Bad
Fortune 500 vendor agreement with standard procurement terms.
Claude: "🔴 This Net-60 payment term should be renegotiated to Net-30.
Their legal team will likely accept the change."Unrealistic recommendation wastes the user's political capital.
✓ Good
Claude: "🟡 Net-60 payment terms. This is longer than typical (Net-30 is standard),
but common in large enterprise procurement templates. Worth asking for
Net-45 as a compromise — they may accept it, especially for recurring work.
Note: if this is a Fortune 500 template, payment terms are often non-negotiable
in the first engagement."Match the recommendation to the power dynamic. Label it yellow, not red. Acknowledge the reality.
Related skills
How it compares
Pick this over general document skills when the input is a legal agreement requiring clause-level risk flagging and redline output.
FAQ
What does contract-review do?
Apply contract-review agent skill workflows from documented SKILL.md guidance.
When should I use contract-review?
During operate infra work for cloud & infrastructure.
Is contract-review safe to install?
Review the Security Audits panel on this listing before production use.