
Nda Review
- 47 installs
- 451 repo stars
- Updated July 21, 2026
- borghei/claude-skills
nda-review is a Claude Code skill that performs deep clause-by-clause NDA review and produces an issue log with redlines, fallbacks, rationales, owners, and deadlines.
About
nda-review is a skill for deep clause-by-clause review of non-disclosure agreements from either the Recipient or Discloser perspective. It produces a structured issue log with risk ratings, preferred redlines, fallback positions, rationale, owners, and deadlines, backed by a clause reference and review templates. It is flagged experimental and does not constitute legal advice. A user runs it when reviewing an NDA for negotiation or approval.
- Clause-by-clause NDA review from Recipient or Discloser perspective
- Produces an issue log with H/M/L risk ratings, redlines, fallbacks, and owners
- Flags 7 immediate red flags and runs an 8-topic recipient checklist
Nda Review by the numbers
- 47 all-time installs (skills.sh)
- +2 installs in the week ending Jun 23, 2026 (Skillselion tracking)
- Ranked #1,652 of 3,282 Productivity & Planning skills by installs in the Skillselion catalog
- Data as of Aug 5, 2026 (Skillselion catalog sync)
nda-review capabilities & compatibility
- Capabilities
- nda triage · clause review · contract analysis
- Use cases
- research
What nda-review says it does
Deep clause-by-clause NDA review from Recipient or Discloser perspective.
Produces issue log with redlines, fallbacks, rationales, owners, deadlines.
Stop review and escalate if any of these 7 red flags are present.
npx skills add https://github.com/borghei/claude-skills --skill nda-reviewAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 47 |
|---|---|
| repo stars | ★ 451 |
| Last updated | July 21, 2026 |
| Repository | borghei/claude-skills ↗ |
What it does
Review an NDA clause by clause and produce redlines with a risk-rated issue log.
Who is it for?
Reviewing an NDA for negotiation or approval from the Recipient or Discloser side.
Skip if: Binding legal advice; the skill is experimental and informational only.
When should I use this skill?
You are reviewing an NDA for negotiation or approval and need a redlined issue log.
What you get
A clause-by-clause issue log with risk ratings, preferred redlines, fallbacks, owners, and deadlines.
- Clause-by-clause issue log
- Preferred redlines and fallback positions
- Owner and deadline assignments
By the numbers
- 7 immediate red flags
- 8-topic recipient checklist
- 5 standard carveouts checked
Files
⚠️ EXPERIMENTAL — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output.
NDA Review
Deep clause-by-clause NDA review tool that analyzes agreements from Recipient or Discloser perspective. Produces structured issue logs with preferred redlines, fallback positions, rationale, owners, and deadlines.
---
Table of Contents
- Tools
- NDA Clause Reviewer
- Reference Guides
- Workflows
- Full NDA Review
- Perspective-Based Review
- Immediate Red Flags
- Review Checklists
- Variation Callouts
- Risk Rating Guide
- Common Pitfalls
- Troubleshooting
- Success Criteria
- Scope & Limitations
- Anti-Patterns
- Tool Reference
---
Tools
NDA Clause Reviewer
Performs deep analysis of NDA text, extracting and classifying each clause against best practices. Detects overbroad definitions, missing carveouts, problematic residuals, IP grants, indemnification, and audit rights.
# Review from recipient perspective (default)
python scripts/nda_clause_reviewer.py nda_draft.txt
# Review from discloser perspective
python scripts/nda_clause_reviewer.py nda_draft.txt --perspective discloser
# JSON output for integration
python scripts/nda_clause_reviewer.py nda_draft.txt --json
# Save issue log
python scripts/nda_clause_reviewer.py nda_draft.txt --output issues.json --jsonWhat it produces:
- Clause-by-clause issue log with H/M/L risk ratings
- Preferred redline for each issue
- Fallback position if preferred is rejected
- Rationale for each recommendation
- Owner assignment (legal, business, executive)
- Deadline category (pre-signing, 30-day, 90-day)
---
Reference Guides
NDA Clause Reference
references/nda_clause_reference.md
Five deep reference modules:
- Duration & Scope (term, survival, scope limitations)
- Key Clauses (definition, purpose, permitted use, marking)
- Party Obligations (standard of care, use restriction, disclosure limits)
- Remedies & Liability (injunctive relief, damages, indemnification)
- Standard Exceptions (public knowledge, prior possession, independent development, third-party receipt, legal compulsion)
NDA Review Templates
references/nda_review_templates.md
Output templates and worked examples:
- Executive Summary format
- Clause-by-clause Issue Log table format
- Ownership and timing defaults by topic category
- Worked examples for social media endorsement and group licensing scenarios
---
Workflows
Full NDA Review
1. Triage first -- Run nda-triage skill for quick GREEN/YELLOW/RED classification 2. Deep review -- Run nda_clause_reviewer.py with appropriate --perspective 3. Review issue log -- Address HIGH-risk items first, then MEDIUM, then LOW 4. Prepare redlines -- Use preferred positions; prepare fallbacks 5. Assign owners -- Legal owns clause language; business owns commercial terms 6. Set deadlines -- Pre-signing items before next meeting; post-signing items within 30-90 days 7. Negotiate -- Present redlines; use fallbacks as needed 8. Final review -- Verify all issues resolved before execution
Perspective-Based Review
| Perspective | Focus Areas | Key Concerns |
|---|---|---|
| Recipient | Scope of obligations, carveouts, residuals, return/destruction | Protecting freedom to operate; avoiding contamination claims |
| Discloser | Definition breadth, remedies, duration, permitted disclosures | Maximizing protection; ensuring adequate enforcement |
---
Immediate Red Flags
Stop review and escalate if any of these 7 red flags are present.
| # | Red Flag | Why It Matters | Escalation |
|---|---|---|---|
| 1 | Non-compete clause | Restricts business operations; requires separate consideration and analysis | Senior counsel immediately |
| 2 | IP assignment or license grant | Transfers rights beyond confidentiality scope | Senior counsel immediately |
| 3 | Non-solicitation of employees or customers | Employment law implications; may be unenforceable | Senior counsel within 24 hours |
| 4 | Missing 3+ standard carveouts | Fundamentally deficient NDA | Counsel review before any response |
| 5 | Liquidated damages or penalty clause | Transforms NDA into penalty contract | Senior counsel within 24 hours |
| 6 | Perpetual obligations with no termination | Indefinite legal burden with no exit | Counsel review within 48 hours |
| 7 | Exclusivity provision | Limits engagement with other parties | Business leadership + counsel |
---
Review Checklists
Recipient Checklist (8 Topics)
| # | Topic | Key Questions | Risk if Missing |
|---|---|---|---|
| 1 | Definition Scope | Is confidential info bounded? Is there a marking requirement? | Overbroad definition traps all shared information |
| 2 | Standard Carveouts | Are all 5 carveouts present and properly drafted? | Missing carveouts restrict legitimate business activities |
| 3 | Permitted Use | Is use restricted to stated purpose? Can we share with advisors? | Overly restrictive use limits may impede evaluation |
| 4 | Residuals | Is there a residuals clause? Is it narrow or broad? | Broad residuals clause benefits; narrow or absent protects discloser |
| 5 | Return/Destruction | Return or destroy option? Retention exception for backups? | No retention exception is impractical for electronic data |
| 6 | Term & Survival | Reasonable term? Reasonable survival period? Termination right? | Perpetual obligations are burdensome |
| 7 | Remedies | Injunctive relief only? Or liquidated damages/indemnification? | Excessive remedies shift risk disproportionately |
| 8 | Problematic Provisions | Non-compete? Non-solicitation? IP assignment? Audit rights? | These provisions have no place in a standard NDA |
Discloser Checklist (5 Topics)
| # | Topic | Key Questions | Risk if Missing |
|---|---|---|---|
| 1 | Definition Breadth | Does definition cover all information we will share? All forms? | Gaps in definition leave information unprotected |
| 2 | Obligation Strength | Standard of care adequate? Written agreements from recipients? | Weak obligations increase risk of unauthorized disclosure |
| 3 | Remedies | Injunctive relief available? Is it meaningful in this jurisdiction? | Without adequate remedies, NDA is unenforceable in practice |
| 4 | Duration | Is the term long enough? Does survival cover our exposure window? | Short terms may expire before information loses value |
| 5 | Recipient Limits | Who can receive? Is need-to-know enforced? Downstream binding? | Unrestricted sharing exposes information to unauthorized parties |
---
Variation Callouts
Different NDA contexts require different review emphasis.
M&A Context
| Additional Concern | Reason | Recommended Position |
|---|---|---|
| Standstill provision | Prevents hostile acquisition moves during due diligence | Accept if mutual and time-limited (12-18 months) |
| Non-solicitation of employees | Standard in M&A NDAs | Accept if limited to key employees for 12 months |
| Broader definition | M&A requires extensive information sharing | Accept broader definition with strong carveouts |
| Longer survival | Sensitive strategic information shared | 3-5 year survival is appropriate |
| Residuals clause sensitivity | Competitive intelligence at stake | Resist residuals clause or narrow significantly |
Employment Context
| Additional Concern | Reason | Recommended Position |
|---|---|---|
| Invention assignment | Employer IP ownership | Separate from NDA; use invention assignment agreement |
| Post-employment obligations | Obligations after employment ends | Limit survival to 2 years; ensure enforceability |
| Scope of work product | What the employee creates | Define in employment agreement, not NDA |
| Non-compete enforceability | Varies by jurisdiction | Review local law before including; may be void |
VC / Fundraising Context
| Additional Concern | Reason | Recommended Position |
|---|---|---|
| Investor portfolio conflicts | VC may have portfolio companies in same space | Include portfolio company exclusion or conflict provision |
| Residuals clause | VCs see many similar pitches | Resist; protect trade secrets and specific data |
| Term limitations | VCs want short obligations | 2-3 year term acceptable; ensure adequate survival |
| Definition scope | Founders want maximum protection | Balance with investor need for portfolio flexibility |
---
Risk Rating Guide
| Rating | Criteria | Action | Timeline |
|---|---|---|---|
| HIGH (H) | Could result in material legal or financial exposure; deal-breaker potential | Must resolve before signing | Pre-signing |
| MEDIUM (M) | Creates meaningful risk but manageable; strong preference to resolve | Should resolve; accept with documented risk if necessary | Within 30 days |
| LOW (L) | Minor preference; improves agreement but not material | Nice to resolve; concede if needed for higher-priority wins | Within 90 days |
Risk Rating by Issue Type
| Issue Type | Typical Rating | Escalation |
|---|---|---|
| Missing carveout (any) | M-H | Counsel |
| Overbroad definition | M | Counsel |
| Non-compete/non-solicitation | H | Senior counsel |
| IP assignment | H | Senior counsel |
| Residuals clause (broad) | M | Counsel |
| Perpetual obligations | M-H | Counsel |
| No return/destruction | M | Counsel |
| Liquidated damages | H | Senior counsel |
| Missing governing law | L-M | Counsel |
| One-sided obligations | M | Counsel |
---
Common Pitfalls
| Pitfall | Impact | Fix |
|---|---|---|
| Reviewing without knowing your perspective | Recipient and discloser have opposing interests on many clauses | Always set --perspective flag; review with clear role in mind |
| Treating the NDA as "just a formality" | Missing problematic provisions that create real obligations | Run full clause review on every NDA, regardless of perceived importance |
| Negotiating clause-by-clause in document order | Wastes time on early low-priority clauses; may not reach critical issues | Prioritize by risk rating; address H items first |
| Accepting "standard" NDAs without review | Every organization's "standard" is different; one party's standard favors that party | No NDA is truly standard; always review |
| Ignoring context (M&A, employment, VC) | Standard NDA review misses context-specific risks | Use variation callouts for specialized contexts |
| Not preparing fallback positions | Stuck when counterparty rejects preferred redline | Prepare preferred + fallback for every H and M item |
| Signing before resolving H-rated issues | Creates material legal exposure | Require all H items resolved or executive sign-off |
---
Troubleshooting
| Problem | Cause | Solution |
|---|---|---|
| All issues rated LOW | NDA is genuinely well-drafted, or text extraction lost key sections | Manually verify critical sections (definition, carveouts, remedies) are in the input file |
| Perspective flag has no effect | Tool adjusts weighting, not detection; same issues found either way | Perspective changes risk ratings and recommendations, not issue detection |
| Too many issues generated | NDA is non-standard or poorly drafted | Focus on H-rated issues first; use the issue log as a negotiation roadmap |
| Script misses embedded provisions | Non-compete or IP clause hidden in definitions or general provisions | Search full document for "compete", "assign", "license", "solicit" manually |
| Output format does not match template | Tool outputs structured data, not final deliverable | Use references/nda_review_templates.md to format the output for stakeholders |
---
Success Criteria
- Complete clause-by-clause review in under 15 minutes: Automated analysis replaces 1-2 hours of manual review.
- Zero missed HIGH-risk issues: Every non-compete, IP assignment, and missing carveout is identified.
- Actionable redlines for every H and M issue: Each issue has preferred position, fallback, and rationale.
- Clear ownership assignment: Every issue has a designated owner (legal, business, executive).
- Perspective-appropriate recommendations: Recipient and discloser reviews produce different risk weightings.
- Context-aware review: M&A, employment, and VC variations are flagged when relevant.
---
Scope & Limitations
Covers:
- Deep clause-by-clause NDA analysis with pattern matching and risk classification
- Perspective-based review (Recipient vs. Discloser)
- Issue log generation with redlines, fallbacks, rationale, owners, and deadlines
- Detection of 7 immediate red flags for triage
- Context variation awareness (M&A, Employment, VC)
Does NOT cover:
- Legal advice -- this tool supports review, it does not replace qualified legal counsel
- Rapid triage -- use
nda-triagefor quick GREEN/YELLOW/RED screening - Contract types beyond NDAs -- use
contract-reviewfor general commercial agreements - Jurisdiction-specific enforceability analysis -- requires local counsel assessment
- Non-English NDAs -- pattern matching is English-language only
---
Anti-Patterns
| Anti-Pattern | Why It Fails | Better Approach |
|---|---|---|
| Running deep review without triage first | Wastes time on detailed analysis of NDAs that should be rejected outright (RED triage) | Always run nda-triage first; only proceed to deep review for YELLOW or GREEN-with-complexity |
| Using Recipient perspective for both sides | Recipient perspective minimizes obligations and maximizes carveouts, which is wrong if you are the discloser | Always set the correct --perspective flag based on your role |
| Accepting all LOW-rated issues without review | Some LOW issues are low-risk individually but create cumulative exposure when combined | Review the full issue log for interaction effects; multiple LOW issues in the same area may compound to MEDIUM |
| Skipping the variation callouts for specialized contexts | Standard NDA review misses M&A standstill provisions, employment invention assignment, VC portfolio conflicts | Check the variation callouts section for your specific deal context |
---
Tool Reference
nda_clause_reviewer.py
Purpose: Performs deep clause-by-clause NDA analysis. Detects overbroad definitions, missing carveouts, problematic provisions, and generates an issue log with redlines, fallbacks, rationale, owners, and deadlines.
Usage:
python scripts/nda_clause_reviewer.py <nda_file> [--perspective PERSPECTIVE] [--json] [--output FILE]Flags:
| Flag | Short | Default | Description |
|---|---|---|---|
nda_file | (positional) | Path to NDA text file (.txt or .md) | |
--perspective | -p | recipient | Review perspective: recipient or discloser |
--json | off | Output in JSON format | |
--output | -o | (stdout) | Write output to file |
Example Output (JSON):
{
"file": "vendor_nda.txt",
"perspective": "recipient",
"issues": [
{
"id": 1,
"clause": "Definition of Confidential Information",
"issue": "Overbroad definition with no marking requirement",
"risk": "H",
"preferred_redline": "Narrow to information marked Confidential or confirmed in writing within 10 days",
"fallback": "Add marking requirement for written; 10-day confirmation for oral",
"rationale": "Overbroad definition traps all shared information as confidential",
"owner": "legal",
"deadline": "pre-signing"
}
],
"summary": {
"total_issues": 5,
"high": 2,
"medium": 2,
"low": 1
}
}Example Output (Text):
NDA CLAUSE REVIEW — ISSUE LOG
==============================
File: vendor_nda.txt
Perspective: Recipient
Issues Found: 5 (H:2 M:2 L:1)
# Risk Clause Issue
1 H Definition of Confidential Info Overbroad definition; no marking requirement
Preferred: Narrow to marked information with 10-day oral confirmation
Fallback: Add marking requirement for written; 10-day confirmation for oral
Rationale: Overbroad definition traps all shared information
Owner: legal | Deadline: pre-signing
2 H Standard Carveouts Missing independent development carveout
Preferred: Add standard independent development exception
Fallback: Add with documentary evidence requirement
Rationale: Missing carveout blocks internal R&D
Owner: legal | Deadline: pre-signingNDA Clause Reference
Deep reference for clause-by-clause NDA analysis. Organized into five modules covering duration and scope, key clauses, party obligations, remedies and liability, and standard exceptions.
---
Table of Contents
- Module 1: Duration and Scope
- Module 2: Key Clauses
- Module 3: Party Obligations
- Module 4: Remedies and Liability
- Module 5: Standard Exceptions
- Cross-Module Analysis Framework
---
Module 1: Duration and Scope
Term of Agreement
| Element | Description | Analysis Points |
|---|---|---|
| Initial Term | Duration of the NDA from effective date | Standard: 2-5 years; flag if >7 years or perpetual |
| Renewal | Whether and how the NDA renews | Auto-renewal acceptable with opt-out; mutual written renewal preferred |
| Effective Date | When obligations begin | Should be clearly stated; "date of last signature" is common |
| Termination Right | How parties can end the agreement | Convenience termination with 30-60 day notice is standard |
Survival Period
The survival period determines how long confidentiality obligations continue after the NDA terminates or expires.
| Survival Duration | Appropriateness | Context |
|---|---|---|
| 1 year | Minimum acceptable | Low-sensitivity, short-term projects |
| 2-3 years | Market standard | Most commercial relationships |
| 3-5 years | Strong protection | Sensitive technology, strategic plans |
| 5+ years | Unusual | Trade secrets, national security |
| Perpetual | RED flag unless limited to trade secrets | Only acceptable with trade secret carveout |
Scope Limitations
| Scope Element | What to Check | Red Flag |
|---|---|---|
| Subject Matter | Is the NDA limited to a specific purpose or project? | "Any and all business purposes" -- no limitation |
| Geographic | Any geographic limitations on obligations? | Unusual in NDAs; flag if present |
| Information Types | Are specific categories of information identified? | No categories listed -- everything is confidential |
| Temporal | Does the NDA apply to past disclosures? | Retroactive application without clear boundary |
Analysis Framework for Duration
1. Is the term proportionate to the relationship? A 5-year NDA for a 2-week evaluation is excessive. 2. Does the survival period match the sensitivity? Trade secrets may warrant longer survival; general business information does not. 3. Is there a termination right? Either party should be able to terminate with notice. 4. What happens on termination? Return/destruction obligations should trigger on termination.
---
Module 2: Key Clauses
Definition of Confidential Information
This is the most critical clause in any NDA. It determines what is protected and what is not.
| Element | Standard Position | Red Flag |
|---|---|---|
| Scope | Information relating to the stated purpose | "All information of any kind" |
| Form | Written, oral, visual, electronic | Limited to written only (excludes oral discussions) |
| Marking | Must be marked "Confidential" or confirmed in writing | No marking requirement |
| Oral Confirmation | 10-30 day window to confirm oral disclosures | No window or unreasonably short (24 hours) |
| Negative Definition | What is NOT confidential (carveouts) | No exclusions from definition |
Quality Indicators:
| Quality Level | Characteristics |
|---|---|
| Strong | Specific categories listed; marking required; oral confirmation window; tied to purpose |
| Standard | Broad but reasonable scope; some marking requirement; carveouts present |
| Weak | Overly broad; no marking; no oral confirmation; missing carveouts |
| Deficient | "All information" with no limits; no carveouts; no marking |
Purpose Clause
| Element | Standard Position | Red Flag |
|---|---|---|
| Specificity | Named project, evaluation, or business opportunity | "Any purpose" or no purpose stated |
| Limitation | Use restricted to stated purpose | No use restriction |
| Expansion | How purpose can be expanded | Unilateral expansion by one party |
Permitted Use
| Element | Standard Position | Red Flag |
|---|---|---|
| Use Restriction | Solely for the stated purpose | No use restriction |
| Internal Use | Sharing within organization on need-to-know basis | Unrestricted internal use |
| Derivative Works | Cannot create derivative works from confidential info | Right to create derivatives |
| Competitive Use | Cannot use for competitive purposes | Residuals clause allowing competitive use |
Marking Requirements
| Marking Type | Standard Approach | Notes |
|---|---|---|
| Written Documents | Marked "Confidential" or similar designation | Most common requirement |
| Oral Disclosures | Identified as confidential at time of disclosure; confirmed in writing within 10-30 days | Important for meetings and calls |
| Visual/Demonstrations | Identified as confidential prior to disclosure | Often overlooked |
| Electronic Data | Marked in metadata or transmission notice | Increasingly important |
---
Module 3: Party Obligations
Standard of Care
| Standard | Meaning | Recipient Risk | Discloser Preference |
|---|---|---|---|
| Reasonable care | What a reasonable organization would do | Moderate | Minimum acceptable |
| Same degree as own | Same care as for party's own confidential info | Moderate | Preferred |
| Industry standard | Consistent with industry practices | Moderate | Good for regulated industries |
| Best efforts | Highest possible standard | High | Aggressive; may be unenforceable |
| Absolute | Guarantees no unauthorized disclosure | Very High | Unreasonable; resist |
Use Restrictions
| Restriction | Standard Language | Analysis Point |
|---|---|---|
| Purpose limitation | "Use solely for the Purpose" | Must match the defined purpose |
| No reverse engineering | "Shall not reverse engineer, decompile, or disassemble" | Standard for technology disclosures |
| No copying | "Shall not copy except as reasonably necessary" | Allow copies needed for the purpose |
| No modification | "Shall not modify or create derivative works" | Standard restriction |
Disclosure Limits
| Permitted Recipient | Standard Requirement | Red Flag |
|---|---|---|
| Employees | Need-to-know basis; bound by written agreement | No need-to-know requirement |
| Officers/Directors | Need-to-know; inherently bound by fiduciary duty | Excluded from permitted recipients |
| Legal Counsel | Need-to-know; bound by professional obligation | Excluded (creates compliance impossibility) |
| Accountants/Auditors | Need-to-know; bound by professional obligation | Excluded |
| Affiliates | Need-to-know; bound by written agreement | Unrestricted affiliate sharing |
| Consultants | Need-to-know; bound by written agreement at least as protective | No downstream binding requirement |
Notification Obligations
| Event | Standard Obligation | Red Flag |
|---|---|---|
| Unauthorized disclosure | Prompt written notice | No notification requirement |
| Legal compulsion | Notice before disclosure (if permitted) | No notice of compelled disclosure |
| Breach by representative | Prompt notice; receiving party responsible | No responsibility for representative breach |
---
Module 4: Remedies and Liability
Injunctive Relief
| Element | Standard Position | Analysis Point |
|---|---|---|
| Availability | Injunctive relief available for breach | Should be explicit |
| Bond | Without requirement of bond or security | Bond requirement may delay enforcement |
| Irreparable Harm | Acknowledgment that breach causes irreparable harm | Standard; strengthens injunctive relief argument |
| Cumulative Remedies | Injunctive relief in addition to other remedies | Should not be sole remedy |
Damages Framework
| Damages Type | Standard in NDAs? | Notes |
|---|---|---|
| Actual damages | Yes | Standard breach-of-contract remedy |
| Consequential damages | Usually excluded | May be included for willful breach |
| Liquidated damages | No -- RED flag | Transforms NDA into penalty contract |
| Punitive damages | No | Rarely available for contract breach |
| Lost profits | Fact-dependent | Difficult to prove in NDA context |
Indemnification in NDAs
| Aspect | Standard Position | Red Flag |
|---|---|---|
| Presence | Not standard in NDAs | One-way indemnification |
| Scope | If present, limited to third-party claims from breach | Broad indemnification for any damages |
| Mutuality | If present, should be mutual | One-sided obligation |
| Cap | If present, should be capped | Uncapped indemnification |
| Procedure | Notice, control, cooperation | No procedure specified |
Red Flags in Remedies
| Provision | Severity | Impact | Action |
|---|---|---|---|
| Liquidated damages | H | Creates predetermined penalty; may be unenforceable | Delete; use standard remedies |
| Unlimited liability | M | No cap on breach damages | Add reasonable liability cap |
| One-way indemnification | M | Shifts all risk to one party | Make mutual or delete |
| Mandatory arbitration (no injunctive carveout) | M | May delay emergency relief | Add carveout for injunctive relief in courts |
| Prevailing party attorney fees | L | May deter smaller party from enforcing | Acceptable either way |
---
Module 5: Standard Exceptions
Exception 1: Public Knowledge
Standard Language: "Information that is or becomes generally available to the public through no fault of, or breach of this Agreement by, the receiving party."
| Analysis Point | What to Check |
|---|---|
| Causation | "Through no fault of the receiving party" -- receiving party's breach should not activate this carveout |
| Partial Publication | Does public availability of part of the information make the whole non-confidential? Should specify it does not |
| Timing | "At the time of disclosure or thereafter" -- covers both pre-existing and subsequent public availability |
Red Flags:
- Missing "through no fault" qualifier (allows receiving party to leak then claim public knowledge)
- Limited to "at the time of disclosure" only (does not cover subsequent publication)
Exception 2: Prior Possession
Standard Language: "Information that was already in the receiving party's possession prior to disclosure by the disclosing party, as demonstrated by the receiving party's written records."
| Analysis Point | What to Check |
|---|---|
| Documentary Evidence | "As demonstrated by written records" -- protects discloser from unfounded claims |
| Timing | "Prior to disclosure" -- clear temporal boundary |
| Source | Should not have been obtained from the disclosing party or under other confidentiality obligations |
Red Flags:
- No documentary evidence requirement (allows unsubstantiated claims)
- No temporal boundary (ambiguous when possession occurred)
Exception 3: Independent Development
Standard Language: "Information independently developed by the receiving party without use of or reference to the disclosing party's Confidential Information, as demonstrated by the receiving party's written records."
| Analysis Point | What to Check |
|---|---|
| Clean Room | Implies clean-room development process |
| Documentary Evidence | "As demonstrated by written records" -- essential for enforcement |
| Scope | "Without use of or reference to" -- both direct use and reference prohibited |
Red Flags:
- Missing from carveouts entirely (HIGH risk for recipients; blocks R&D)
- No documentary evidence requirement
- Weakened language: "without direct use" (allows indirect reference)
Practical Impact: Missing independent development carveout can contaminate entire engineering teams. If a developer sees confidential information and later works on a similar product, the discloser can claim derivation. This carveout is the most important for technology companies.
Exception 4: Third-Party Receipt
Standard Language: "Information received by the receiving party from a third party who, to the receiving party's knowledge, is not under any obligation of confidentiality to the disclosing party with respect to such information."
| Analysis Point | What to Check |
|---|---|
| Knowledge Qualifier | "To the receiving party's knowledge" -- receiving party not required to investigate |
| Third-Party Obligation | Third party must not be bound by confidentiality to discloser |
| Lawful Receipt | Information must be lawfully obtained |
Red Flags:
- Requires receiving party to investigate third party's obligations (impractical)
- Missing "to the receiving party's knowledge" qualifier (strict liability standard)
Exception 5: Legal Compulsion
Standard Language: "Information required to be disclosed by applicable law, regulation, court order, or governmental authority, provided that the receiving party gives prompt written notice to the disclosing party (to the extent legally permitted) and cooperates with the disclosing party's efforts to obtain a protective order."
| Analysis Point | What to Check |
|---|---|
| Notice Requirement | Prompt notice before disclosure (if not prohibited by law) |
| Cooperation | Cooperation with protective order efforts |
| Minimization | Disclose only the minimum required |
| Waiver for Legal Prohibition | Notice waived if law prohibits it |
Red Flags:
- No notice requirement (discloser cannot seek protective order)
- No minimization requirement (entire file may be disclosed when only a portion is required)
- No waiver for situations where notice is prohibited by law (creates impossible obligation)
---
Cross-Module Analysis Framework
Use this framework to systematically review an NDA across all five modules.
Step 1: Duration and Scope Assessment
| Question | GREEN | YELLOW | RED |
|---|---|---|---|
| Is the term reasonable (2-5 years)? | Yes | 5-7 years | Perpetual or >7 years |
| Is there a termination right? | Yes, either party | Yes, but conditional | No termination right |
| Does survival match sensitivity? | 2-3 years | 5+ years | Perpetual survival |
| Is purpose clearly stated? | Specific project/purpose | General business purpose | No purpose or "any purpose" |
Step 2: Definition Quality Assessment
| Question | GREEN | YELLOW | RED |
|---|---|---|---|
| Is scope bounded? | Tied to purpose with categories | Broad but reasonable | "All information of any kind" |
| Is marking required? | Yes, with oral confirmation window | Partial (written only) | No marking requirement |
| Are carveouts present? | All 5 standard carveouts | 3-4 carveouts | 0-2 carveouts |
Step 3: Obligation Balance Assessment
| Question | GREEN | YELLOW | RED |
|---|---|---|---|
| Are obligations mutual? | Yes (if mutual NDA) | Mostly balanced | One-sided in mutual NDA |
| Is standard of care reasonable? | Reasonable care | Same degree as own | Best efforts or absolute |
| Are permitted disclosures adequate? | Representatives + advisors + affiliates | Representatives only | No permitted disclosures |
Step 4: Remedy Proportionality Assessment
| Question | GREEN | YELLOW | RED |
|---|---|---|---|
| Is injunctive relief available? | Yes, without bond | Yes, with bond | Not mentioned |
| Are damages appropriate? | Actual damages | Includes consequential | Liquidated damages |
| Is indemnification absent or mutual? | Absent | Mutual with cap | One-sided, uncapped |
Step 5: Exception Completeness Assessment
| Question | GREEN | YELLOW | RED |
|---|---|---|---|
| Public knowledge carveout? | Present with "no fault" qualifier | Present without qualifier | Missing |
| Prior possession carveout? | Present with evidence requirement | Present without evidence req. | Missing |
| Independent development carveout? | Present with evidence requirement | Present without evidence req. | Missing |
| Third-party receipt carveout? | Present with knowledge qualifier | Present without qualifier | Missing |
| Legal compulsion carveout? | Present with notice + cooperation | Present with notice only | Missing |
NDA Review Templates
Output templates for NDA review deliverables. Includes Executive Summary format, clause-by-clause Issue Log table, ownership and timing defaults, and worked examples.
---
Table of Contents
- Executive Summary Template
- Clause-by-Clause Issue Log
- Ownership and Timing Defaults
- Worked Example: Social Media Endorsement NDA
- Worked Example: Group Licensing NDA
- Redline Delivery Template
---
Executive Summary Template
Use this format for communicating NDA review findings to business stakeholders.
Template
NDA REVIEW — EXECUTIVE SUMMARY
================================
Agreement: [Counterparty Name] Mutual/Unilateral NDA
Reviewer: [Name]
Date: [Date]
Perspective: Recipient / Discloser
Status: GREEN / YELLOW / RED
OVERVIEW
--------
[1-2 sentence description of the NDA scope and purpose]
RISK ASSESSMENT
---------------
HIGH-risk issues: [count]
MEDIUM-risk issues: [count]
LOW-risk issues: [count]
KEY FINDINGS
------------
1. [Most critical finding with one-line description]
2. [Second most critical finding]
3. [Third most critical finding]
RECOMMENDATION
--------------
[One of the following:]
- SIGN: No material issues. Proceed with execution.
- NEGOTIATE: [X] issues require resolution before signing.
Priority items: [list top 2-3 issues]
- REJECT: Material structural deficiencies. [Brief reason]
- ESCALATE: [Brief reason and escalation target]
NEXT STEPS
----------
1. [Specific action item with owner]
2. [Specific action item with owner]
3. [Specific action item with owner]
TIMELINE
--------
Redlines due to counterparty: [date]
Target execution date: [date]Filled Example
NDA REVIEW — EXECUTIVE SUMMARY
================================
Agreement: Acme Corp Mutual NDA
Reviewer: Legal Team
Date: 2026-04-10
Perspective: Recipient
Status: YELLOW
OVERVIEW
--------
Mutual NDA covering evaluation of potential technology partnership.
Standard bilateral structure with 3-year term.
RISK ASSESSMENT
---------------
HIGH-risk issues: 1
MEDIUM-risk issues: 2
LOW-risk issues: 1
KEY FINDINGS
------------
1. Missing independent development carveout (HIGH) — blocks R&D freedom
2. Overbroad definition without marking requirement (MEDIUM)
3. Residuals clause with no trade secret exclusion (MEDIUM)
RECOMMENDATION
--------------
NEGOTIATE: 3 issues require resolution before signing.
Priority items: independent development carveout, definition narrowing
NEXT STEPS
----------
1. Legal to prepare redline with carveout language (owner: outside counsel)
2. Business to confirm scope of anticipated information sharing (owner: BD lead)
3. Schedule counterparty call to discuss redlines (owner: legal)
TIMELINE
--------
Redlines due to counterparty: 2026-04-14
Target execution date: 2026-04-21---
Clause-by-Clause Issue Log
Table Format
| # | Risk | Clause | Issue | Preferred Redline | Fallback | Rationale | Owner | Deadline |
|---|---|---|---|---|---|---|---|---|
| 1 | H | [Clause name] | [Issue description] | [Proposed language] | [Alternative] | [Why it matters] | [legal/business/exec] | [pre-signing/30d/90d] |
Column Definitions
| Column | Description | Values |
|---|---|---|
| # | Sequential issue number | 1, 2, 3... |
| Risk | Risk rating | H (High), M (Medium), L (Low) |
| Clause | NDA clause or section | Definition, Carveouts, Obligations, Remedies, Term, etc. |
| Issue | Brief description of the problem | Factual, specific |
| Preferred Redline | Recommended contract language change | Specific proposed language |
| Fallback | Alternative if preferred is rejected | Less ideal but acceptable |
| Rationale | Why this change matters | Business or legal justification |
| Owner | Who is responsible for resolution | legal, business, executive |
| Deadline | When this must be resolved | pre-signing, 30-day, 90-day |
Filled Example
| # | Risk | Clause | Issue | Preferred Redline | Fallback | Rationale | Owner | Deadline |
|---|---|---|---|---|---|---|---|---|
| 1 | H | Carveouts | Missing independent development carveout | Add: "Information independently developed without use of or reference to Confidential Information" | Add with documentary evidence requirement | Missing carveout blocks internal R&D; contamination risk | legal | pre-signing |
| 2 | M | Definition | Overbroad; no marking requirement | Narrow to marked information with 10-day oral confirmation | Add "reasonably understood to be confidential" standard | All shared information becomes confidential without marking | legal | pre-signing |
| 3 | M | Residuals | Broad residuals clause; no trade secret exclusion | Delete residuals clause | Narrow to exclude trade secrets and specific data | Residuals clause undermines NDA protection for key information | legal | pre-signing |
| 4 | L | Governing Law | Counterparty's home jurisdiction | Change to neutral jurisdiction (Delaware) | Accept with arbitration under AAA rules | Unfamiliar jurisdiction increases litigation cost | legal | pre-signing |
---
Ownership and Timing Defaults
Owner Assignment by Topic
| Topic Category | Default Owner | Escalation To | Rationale |
|---|---|---|---|
| Definition scope and carveouts | Legal counsel | Senior counsel | Legal interpretation; enforceability |
| Obligations and standard of care | Legal counsel | Senior counsel | Legal risk assessment |
| Remedies and liability | Legal counsel | General counsel | Financial exposure |
| Term and duration | Business lead | Legal counsel | Business relationship decision |
| Purpose and scope | Business lead | Legal counsel | Business context dependent |
| Governing law and jurisdiction | Legal counsel | General counsel | Litigation strategy |
| Non-compete / non-solicitation | Senior counsel | General counsel | Significant business restriction |
| IP assignment | Senior counsel | General counsel | Material IP implications |
| Data protection provisions | Privacy counsel / DPO | Legal counsel | Regulatory compliance |
| Commercial terms | Business lead | Finance | Business decision |
Deadline Categories
| Category | Meaning | Standard Timeline | Applies To |
|---|---|---|---|
| Pre-signing | Must be resolved before execution | Before next counterparty meeting | All H-risk issues; structural M-risk issues |
| 30-day | Should be resolved within 30 days of signing | 30 calendar days | M-risk issues that can be addressed via amendment |
| 90-day | Nice to resolve within 90 days | 90 calendar days | L-risk issues; process improvements |
Escalation Triggers
| Trigger | Escalation Target | Timeline |
|---|---|---|
| Any H-risk issue unresolved after 2 negotiation rounds | General counsel | Immediate |
| Counterparty refuses all fallback positions | Senior counsel + business leadership | Within 48 hours |
| Non-compete or IP clause in NDA | Senior counsel | Immediate upon detection |
| Deal timeline pressure vs. unresolved issues | General counsel + business sponsor | Before signing deadline |
---
Worked Example: Social Media Endorsement NDA
Context
A consumer brand asks an influencer to sign an NDA before discussing a paid endorsement partnership. The influencer is the recipient of confidential brand strategy information.
Issue Log
| # | Risk | Clause | Issue | Preferred Redline | Fallback | Owner | Deadline |
|---|---|---|---|---|---|---|---|
| 1 | H | Definition | "All information shared during any meeting or call" — no marking, no boundaries | Narrow to information relating to the endorsement campaign, marked Confidential | Add: "reasonably understood to be confidential given the context" | legal | pre-signing |
| 2 | H | Carveouts | Missing independent development carveout | Add all 5 standard carveouts | At minimum add public knowledge and independent development | legal | pre-signing |
| 3 | H | Problematic | Non-compete: "shall not endorse competing brands for 24 months" | Delete entirely; address exclusivity in endorsement agreement, not NDA | Reduce to 6 months, limited to directly competing products | legal | pre-signing |
| 4 | M | Term | 5-year term with 3-year survival for endorsement evaluation | Reduce to 1-year term with 1-year survival | 2-year term with 2-year survival | business | pre-signing |
| 5 | M | Remedies | Liquidated damages of $50,000 per breach | Delete; use standard breach remedies | Cap at $10,000 with materiality threshold | legal | pre-signing |
| 6 | L | Governing Law | New York law; exclusive jurisdiction | Accept (standard for media/entertainment) | N/A | legal | pre-signing |
Key Observations
- Non-compete clause in an NDA is a RED flag; should be in the endorsement agreement with proper consideration
- Liquidated damages are excessive for an NDA; more appropriate for the endorsement agreement itself
- 5-year term is disproportionate to the likely engagement duration
---
Worked Example: Group Licensing NDA
Context
A sports league shares player performance data with a data analytics company for a licensing evaluation. The analytics company is the recipient of proprietary player data, statistics, and business terms.
Issue Log
| # | Risk | Clause | Issue | Preferred Redline | Fallback | Owner | Deadline |
|---|---|---|---|---|---|---|---|
| 1 | H | Definition | Includes "any derivative analysis or insights generated from the data" | Limit to raw data provided; exclude independently generated analysis | Add: "derivatives are confidential only if they would reveal the underlying Confidential Information" | legal | pre-signing |
| 2 | H | Residuals | No residuals clause; analytics team will inherently retain knowledge | Add standard residuals clause for general knowledge and techniques | Add residuals limited to general analytical methodology, excluding specific data points | business | pre-signing |
| 3 | M | IP | "All analysis, models, and outputs shall be the property of the League" | NDA should not address IP; reserve for licensing agreement | Add: "Pre-existing analytical tools and methodologies remain property of the recipient" | legal | pre-signing |
| 4 | M | Term | 3-year term covering evaluation period | Reduce to 12 months (evaluation should not take 3 years) | Accept 18 months with convenience termination after 6 months | business | pre-signing |
| 5 | M | Return | "Return or destroy all data, analyses, derivatives, and models" | Limit to raw data; retain independently created analysis | Add retention exception for de-identified aggregate statistics | legal | pre-signing |
| 6 | L | Permitted | No disclosure to sub-contractors or cloud service providers | Add: permitted disclosure to sub-contractors bound by equivalent obligations | Add: permitted storage on secure cloud infrastructure | legal | pre-signing |
Key Observations
- Derivative works clause is critical -- analytics company must protect its ability to use general skills and knowledge
- Residuals clause is important FROM the recipient perspective (unusual) because analysts will inherently retain general knowledge
- IP ownership clause has no place in an NDA; defer to the licensing agreement
- Return/destruction of independently created analysis is unreasonable
---
Redline Delivery Template
Use this format when sending redline markup to the counterparty.
Email Template
Subject: [Company Name] — NDA Redline Comments
Dear [Counterparty Contact],
Thank you for sharing the proposed NDA. We have completed our review and
have the following comments, organized by priority:
MUST-RESOLVE (before execution):
1. [Section X.X] — [Brief description and proposed language]
2. [Section X.X] — [Brief description and proposed language]
STRONG PREFERENCES (recommend resolving):
3. [Section X.X] — [Brief description and proposed language]
4. [Section X.X] — [Brief description and proposed language]
MINOR COMMENTS (flexible):
5. [Section X.X] — [Brief description and proposed language]
We are happy to discuss these comments at your convenience. Our goal is
to finalize the NDA by [target date] so we can proceed with [purpose].
Best regards,
[Name]Redline Markup Format
For each redline in the marked-up document:
[SECTION X.X — CLAUSE NAME]
CURRENT TEXT:
"[Exact current language from the NDA]"
PROPOSED TEXT:
"[Your proposed replacement language, with changes highlighted]"
RATIONALE:
[One sentence explaining why the change is needed]
PRIORITY: Must-Resolve / Strong Preference / Minor Comment#!/usr/bin/env python3
"""
NDA Clause Reviewer
Performs deep clause-by-clause NDA analysis from Recipient or Discloser
perspective. Generates structured issue log with redlines, fallbacks,
rationale, owners, and deadlines.
Usage:
python nda_clause_reviewer.py nda_draft.txt
python nda_clause_reviewer.py nda_draft.txt --perspective discloser
python nda_clause_reviewer.py nda_draft.txt --json --output issues.json
"""
import argparse
import json
import os
import re
import sys
from typing import Dict, List, Optional, Tuple
# Issue templates organized by clause area
# Each issue has: detection patterns, risk ratings per perspective, redlines
ISSUE_DEFINITIONS = [
{
"id": "overbroad_definition",
"clause": "Definition of Confidential Information",
"patterns": [
r"all\s+information\s+(?:of\s+any\s+(?:kind|nature|type)|whatsoever)",
r"any\s+(?:and\s+all\s+)?information.*(?:relating|concerning|regarding)",
r"without\s+limitation.*(?:oral|written|visual|electronic|any\s+(?:form|medium))",
],
"issue": "Overbroad definition with no clear boundaries",
"risk": {"recipient": "H", "discloser": "L"},
"preferred": "Narrow definition to information specifically marked or designated as Confidential, with 10-day written confirmation for oral disclosures",
"fallback": "Add marking requirement for written information; 10-day confirmation window for oral disclosures",
"rationale": {
"recipient": "Overbroad definition traps all shared information as confidential, restricting normal business operations",
"discloser": "Broad definition maximizes protection scope; minor concern",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "no_marking_requirement",
"clause": "Definition of Confidential Information",
"patterns": [
# Negative: detect ABSENCE of marking requirement
# We check for presence of marking; if not found, this fires
],
"positive_patterns": [
r"mark(?:ed|ing)\s+(?:as\s+)?(?:\"|')?\s*confidential",
r"(?:labeled|designated|stamped)\s+(?:as\s+)?confidential",
r"(?:written|oral).*(?:confirm|identif|summariz).*(?:in\s+writing|\d+\s+(?:day|business))",
],
"negative_check": True,
"issue": "No marking or identification requirement for confidential information",
"risk": {"recipient": "M", "discloser": "L"},
"preferred": "Add: Information must be marked 'Confidential' when written; oral disclosures confirmed in writing within 10 business days",
"fallback": "Add: Information reasonably understood to be confidential given the nature and circumstances of disclosure",
"rationale": {
"recipient": "Without marking, all information exchanged could be treated as confidential, creating uncertainty",
"discloser": "No marking requirement means all information is protected without effort; generally favorable",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "missing_public_knowledge",
"clause": "Standard Carveouts",
"patterns": [],
"positive_patterns": [
r"public(?:ly)?\s+(?:known|available|domain)",
r"generally\s+(?:known|available)\s+to\s+the\s+public",
],
"negative_check": True,
"issue": "Missing public knowledge carveout",
"risk": {"recipient": "H", "discloser": "M"},
"preferred": "Add: Information that is or becomes publicly available through no fault of the receiving party",
"fallback": "Add: Information that is part of the public domain at the time of disclosure or thereafter",
"rationale": {
"recipient": "Without this carveout, information that becomes public may still be treated as confidential",
"discloser": "Standard carveout; absence may raise concerns about enforceability",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "missing_prior_possession",
"clause": "Standard Carveouts",
"patterns": [],
"positive_patterns": [
r"prior\s+(?:possession|knowledge|receipt)",
r"already\s+(?:known|possessed|in\s+possession)",
],
"negative_check": True,
"issue": "Missing prior possession carveout",
"risk": {"recipient": "H", "discloser": "M"},
"preferred": "Add: Information already in the receiving party's possession prior to disclosure, as documented by written records",
"fallback": "Add: Information known to the receiving party prior to disclosure",
"rationale": {
"recipient": "Without this, pre-existing knowledge becomes subject to NDA restrictions",
"discloser": "Standard carveout; documentary evidence requirement protects discloser interests",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "missing_independent_development",
"clause": "Standard Carveouts",
"patterns": [],
"positive_patterns": [
r"independent(?:ly)?\s+develop",
r"without\s+(?:use\s+of|reference\s+to)\s+(?:the\s+)?confidential",
],
"negative_check": True,
"issue": "Missing independent development carveout",
"risk": {"recipient": "H", "discloser": "M"},
"preferred": "Add: Information independently developed by the receiving party without use of or reference to Confidential Information",
"fallback": "Add: Information independently developed as demonstrated by documentary evidence created prior to or independent of any disclosure",
"rationale": {
"recipient": "Missing carveout blocks internal R&D; can create contamination claims against entire engineering teams",
"discloser": "Standard carveout; documentary evidence requirement is acceptable protection",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "missing_third_party_receipt",
"clause": "Standard Carveouts",
"patterns": [],
"positive_patterns": [
r"(?:received|obtained)\s+from\s+a\s+third\s+party",
r"third[- ]party\s+(?:source|disclosure|receipt)",
],
"negative_check": True,
"issue": "Missing third-party receipt carveout",
"risk": {"recipient": "M", "discloser": "L"},
"preferred": "Add: Information received from a third party not under a confidentiality obligation to the disclosing party",
"fallback": "Add: Information lawfully obtained from a third party who had the right to disclose it",
"rationale": {
"recipient": "Without this, information legitimately received from other sources becomes restricted",
"discloser": "Standard carveout; low risk to discloser",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "missing_legal_compulsion",
"clause": "Standard Carveouts",
"patterns": [],
"positive_patterns": [
r"(?:required|compelled|ordered)\s+(?:by|under)\s+law",
r"court\s+order",
r"subpoena",
r"legal(?:ly)?\s+(?:required|compelled)",
],
"negative_check": True,
"issue": "Missing legal compulsion carveout",
"risk": {"recipient": "M", "discloser": "L"},
"preferred": "Add: Disclosure required by law, court order, or governmental authority, with prompt notice to disclosing party prior to disclosure",
"fallback": "Add: Disclosure compelled by legal process, with notice to the extent permitted by law",
"rationale": {
"recipient": "Without this, compliance with legal obligations could technically breach the NDA",
"discloser": "Standard carveout; notice requirement protects discloser's ability to seek protective order",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "non_compete",
"clause": "Problematic Provisions",
"patterns": [
r"non[- ]?compete",
r"shall\s+not\s+compete",
r"competitive\s+activit",
r"refrain\s+from\s+compet",
],
"issue": "Non-compete clause restricting business activities",
"risk": {"recipient": "H", "discloser": "H"},
"preferred": "Delete entire non-compete provision; inappropriate for an NDA",
"fallback": "If counterparty insists, require separate non-compete agreement with independent consideration and limited scope/duration",
"rationale": {
"recipient": "Non-compete in NDA restricts business operations without appropriate consideration",
"discloser": "Non-compete enforceability varies by jurisdiction; separate agreement is more defensible",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "non_solicitation",
"clause": "Problematic Provisions",
"patterns": [
r"non[- ]?solicitation",
r"shall\s+not\s+solicit",
r"refrain\s+from\s+soliciting",
],
"issue": "Non-solicitation clause restricting hiring or business solicitation",
"risk": {"recipient": "H", "discloser": "M"},
"preferred": "Delete non-solicitation provision entirely",
"fallback": "Limit to direct solicitation of specific named individuals for 12 months; exclude general advertising and unsolicited inquiries",
"rationale": {
"recipient": "Non-solicitation in NDA limits talent acquisition and business development without appropriate context",
"discloser": "May be appropriate in M&A context; otherwise excessive for standard NDA",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "ip_assignment",
"clause": "Problematic Provisions",
"patterns": [
r"assign(?:s|ment)?\s+(?:all\s+)?(?:right|title|interest)",
r"work[- ]?(?:for[- ]?hire|made\s+for\s+hire)",
r"hereby\s+assign",
],
"issue": "IP assignment or work-for-hire clause in NDA",
"risk": {"recipient": "H", "discloser": "H"},
"preferred": "Delete IP assignment provision; NDA should protect information, not transfer IP rights",
"fallback": "If IP transfer needed, negotiate in a separate services or development agreement with appropriate scope and consideration",
"rationale": {
"recipient": "IP assignment in NDA transfers rights without appropriate scope or consideration",
"discloser": "IP assignment in NDA is overbroad and may be unenforceable; use separate IP agreement",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "broad_residuals",
"clause": "Residuals",
"patterns": [
r"residual(?:s)?\s+(?:clause|knowledge|information|rights)",
r"unaided\s+(?:memory|recall|recollection)",
r"retained\s+in\s+(?:the\s+)?(?:unaided\s+)?memor",
r"general\s+(?:knowledge|skills|experience)\s+retained",
],
"issue": "Broad residuals clause allowing use of ideas retained in memory",
"risk": {"recipient": "L", "discloser": "H"},
"preferred": {
"recipient": "Accept if narrowly scoped to exclude trade secrets and specific data",
"discloser": "Delete residuals clause entirely; it undermines NDA protection",
},
"fallback": {
"recipient": "Accept with requirement that retention was not intentional",
"discloser": "Narrow to general concepts only, excluding trade secrets, algorithms, and specific data points",
},
"rationale": {
"recipient": "Residuals clause protects freedom to operate after NDA engagement",
"discloser": "Broad residuals clause effectively creates a carveout that swallows the NDA",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "ip_license_grant",
"clause": "Problematic Provisions",
"patterns": [
r"grant(?:s)?\s+(?:a\s+)?(?:non-exclusive|exclusive|perpetual|irrevocable)\s+license",
r"license\s+to\s+use.*confidential",
r"right\s+to\s+(?:use|exploit|commercialize)",
],
"issue": "License grant over confidential information",
"risk": {"recipient": "H", "discloser": "H"},
"preferred": "Delete license grant; NDA protects information, it does not license it",
"fallback": "If license needed, negotiate in separate agreement with appropriate scope and terms",
"rationale": {
"recipient": "License grant in NDA creates confusion about permitted use vs. confidentiality obligations",
"discloser": "License grant undermines the protective purpose of the NDA",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "liquidated_damages",
"clause": "Remedies",
"patterns": [
r"liquidated\s+damages",
r"stipulated\s+damages",
r"penalty\s+(?:of|in\s+the\s+amount)",
r"\$[\d,]+\s+(?:per|for\s+each)\s+(?:breach|violation)",
],
"issue": "Liquidated damages or penalty clause for breach",
"risk": {"recipient": "H", "discloser": "M"},
"preferred": "Delete liquidated damages; standard NDA remedies (injunctive relief + actual damages) are sufficient",
"fallback": "If counterparty insists, require that amount is a reasonable pre-estimate of loss and cap at a defined amount",
"rationale": {
"recipient": "Liquidated damages transform NDA from protective agreement into penalty contract",
"discloser": "Liquidated damages may be unenforceable if deemed a penalty; actual damages are more reliable",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "perpetual_obligations",
"clause": "Term & Duration",
"patterns": [
r"perpetual(?:ly)?\s+(?:confidential|obligat)",
r"obligations?\s+(?:shall\s+)?(?:survive|continue)\s+(?:in\s+)?perpetuit",
r"indefinite(?:ly)?\s+(?:period|term|duration|obligat)",
r"forever\s+(?:remain|be\s+kept|maintain)",
],
"issue": "Perpetual or indefinite confidentiality obligations",
"risk": {"recipient": "M", "discloser": "L"},
"preferred": "Limit obligations to 3 years from date of disclosure or termination of agreement",
"fallback": "Accept 5-year survival period; perpetual only for information meeting the legal definition of trade secret",
"rationale": {
"recipient": "Perpetual obligations create indefinite legal burden with no exit and unclear long-term compliance",
"discloser": "Longer obligations provide more protection; perpetual may be appropriate for trade secrets",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "indemnification",
"clause": "Remedies",
"patterns": [
r"indemnif(?:y|ication)",
r"hold\s+harmless",
r"defend\s+and\s+indemnif",
],
"issue": "Indemnification clause in NDA",
"risk": {"recipient": "M", "discloser": "L"},
"preferred": "Remove indemnification; standard NDA remedies are sufficient",
"fallback": "If retained, make mutual and subject to a reasonable cap",
"rationale": {
"recipient": "Indemnification in NDA creates additional financial exposure beyond standard breach remedies",
"discloser": "Indemnification adds protection but may complicate negotiation unnecessarily",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "audit_rights",
"clause": "Problematic Provisions",
"patterns": [
r"(?:unlimited|unrestricted)\s+(?:audit|inspection|access)",
r"audit\s+(?:at\s+any\s+time|without\s+(?:notice|limitation))",
r"right\s+to\s+inspect.*(?:premises|records|systems)",
r"audit\s+(?:right|provision|clause)",
],
"issue": "Audit rights allowing inspection of premises, records, or systems",
"risk": {"recipient": "M", "discloser": "L"},
"preferred": "Remove audit rights; excessive for standard NDA",
"fallback": "Limit to annual audit with 30 days notice, during business hours, at auditing party's expense",
"rationale": {
"recipient": "Audit rights create operational burden and security concerns for receiving party",
"discloser": "Audit rights provide verification but may be impractical and damage relationship",
},
"owner": "legal",
"deadline": "pre-signing",
},
{
"id": "one_sided_obligations",
"clause": "Party Obligations",
"patterns": [
r"(?:only|solely)\s+(?:the\s+)?(?:receiving|recipient)\s+(?:party\s+)?(?:shall|agrees?)",
r"(?:disclos(?:ing|er)|provider)\s+(?:party\s+)?(?:shall\s+have\s+no|is\s+not\s+(?:subject|bound))",
],
"issue": "One-sided obligations in purportedly mutual NDA",
"risk": {"recipient": "M", "discloser": "L"},
"preferred": "Make obligations mutual if agreement is structured as mutual NDA",
"fallback": "Accept one-way obligations if agreement is accurately labeled as unilateral; ensure structure matches title",
"rationale": {
"recipient": "One-sided obligations in a 'mutual' NDA create imbalanced risk allocation",
"discloser": "One-sided obligations are appropriate for unilateral NDAs; ensure labeling matches structure",
},
"owner": "legal",
"deadline": "pre-signing",
},
]
def read_nda(file_path: str) -> str:
"""Read NDA text from file."""
if not os.path.isfile(file_path):
print(f"Error: File not found: {file_path}", file=sys.stderr)
sys.exit(1)
try:
with open(file_path, "r", encoding="utf-8") as f:
return f.read()
except UnicodeDecodeError:
with open(file_path, "r", encoding="latin-1") as f:
return f.read()
def get_value(field, perspective: str) -> str:
"""Get perspective-specific value from a field that may be a string or dict."""
if isinstance(field, dict):
return field.get(perspective, field.get("recipient", str(field)))
return str(field)
def detect_issues(text: str, perspective: str) -> List[Dict]:
"""Detect all issues in NDA text from the given perspective."""
text_lower = text.lower()
issues: List[Dict] = []
issue_counter = 0
for issue_def in ISSUE_DEFINITIONS:
triggered = False
if issue_def.get("negative_check"):
# Negative check: issue triggers when positive_patterns are NOT found
found = False
for pattern in issue_def.get("positive_patterns", []):
if re.search(pattern, text_lower):
found = True
break
triggered = not found
else:
# Positive check: issue triggers when patterns ARE found
for pattern in issue_def.get("patterns", []):
if re.search(pattern, text_lower):
triggered = True
break
if triggered:
issue_counter += 1
risk = issue_def["risk"]
risk_rating = risk.get(perspective, risk.get("recipient", "M"))
issues.append({
"id": issue_counter,
"issue_key": issue_def["id"],
"clause": issue_def["clause"],
"issue": issue_def["issue"],
"risk": risk_rating,
"preferred_redline": get_value(issue_def["preferred"], perspective),
"fallback": get_value(issue_def["fallback"], perspective),
"rationale": get_value(issue_def["rationale"], perspective),
"owner": issue_def["owner"],
"deadline": issue_def["deadline"],
})
# Sort by risk: H first, then M, then L
risk_order = {"H": 0, "M": 1, "L": 2}
issues.sort(key=lambda i: (risk_order.get(i["risk"], 1), i["id"]))
# Re-number after sort
for idx, issue in enumerate(issues, 1):
issue["id"] = idx
return issues
def compute_summary(issues: List[Dict]) -> Dict:
"""Compute issue summary counts."""
counts = {"H": 0, "M": 0, "L": 0}
for issue in issues:
counts[issue["risk"]] = counts.get(issue["risk"], 0) + 1
return {
"total_issues": len(issues),
"high": counts["H"],
"medium": counts["M"],
"low": counts["L"],
}
def format_text_output(result: Dict) -> str:
"""Format issue log as human-readable text."""
lines = []
lines.append("NDA CLAUSE REVIEW -- ISSUE LOG")
lines.append("=" * 55)
lines.append(f"File: {result['file']}")
lines.append(f"Perspective: {result['perspective'].title()}")
s = result["summary"]
lines.append(f"Issues Found: {s['total_issues']} (H:{s['high']} M:{s['medium']} L:{s['low']})")
lines.append("")
if not result["issues"]:
lines.append("No issues detected. NDA appears well-drafted from this perspective.")
return "\n".join(lines)
for issue in result["issues"]:
lines.append(
f" {issue['id']:>2} [{issue['risk']}] {issue['clause']}"
)
lines.append(f" Issue: {issue['issue']}")
lines.append(f" Preferred: {issue['preferred_redline']}")
lines.append(f" Fallback: {issue['fallback']}")
lines.append(f" Rationale: {issue['rationale']}")
lines.append(f" Owner: {issue['owner']} | Deadline: {issue['deadline']}")
lines.append("")
# Executive summary
lines.append("-" * 55)
lines.append("EXECUTIVE SUMMARY")
lines.append("")
if s["high"] > 0:
lines.append(f" {s['high']} HIGH-risk issue(s) must be resolved before signing.")
if s["medium"] > 0:
lines.append(f" {s['medium']} MEDIUM-risk issue(s) should be addressed in negotiation.")
if s["low"] > 0:
lines.append(f" {s['low']} LOW-risk issue(s) are nice-to-have improvements.")
lines.append("")
if s["high"] > 0:
lines.append(" RECOMMENDATION: Do not sign until all HIGH-risk issues are resolved.")
elif s["medium"] > 0:
lines.append(" RECOMMENDATION: Negotiate MEDIUM-risk items; sign with documented risk acceptance if needed.")
else:
lines.append(" RECOMMENDATION: LOW-risk issues only. Acceptable to sign with minor improvements.")
return "\n".join(lines)
def review_nda(file_path: str, perspective: str) -> Dict:
"""Main review pipeline."""
text = read_nda(file_path)
issues = detect_issues(text, perspective)
summary = compute_summary(issues)
return {
"file": os.path.basename(file_path),
"perspective": perspective,
"issues": issues,
"summary": summary,
}
def main():
parser = argparse.ArgumentParser(
description="Deep clause-by-clause NDA review with issue log, redlines, and fallbacks."
)
parser.add_argument("nda_file", help="Path to NDA text file (.txt or .md)")
parser.add_argument("-p", "--perspective", choices=["recipient", "discloser"],
default="recipient",
help="Review perspective: recipient (default) or discloser")
parser.add_argument("--json", action="store_true", dest="json_output",
help="Output in JSON format")
parser.add_argument("-o", "--output", help="Write output to file")
args = parser.parse_args()
result = review_nda(args.nda_file, args.perspective)
if args.json_output:
output = json.dumps(result, indent=2)
else:
output = format_text_output(result)
if args.output:
try:
with open(args.output, "w", encoding="utf-8") as f:
f.write(output)
print(f"Output written to {args.output}")
except IOError as e:
print(f"Error writing to {args.output}: {e}", file=sys.stderr)
sys.exit(1)
else:
print(output)
if __name__ == "__main__":
main()
Related skills
FAQ
Can it review from both sides?
Yes. It supports Recipient (default) and Discloser perspectives via a --perspective flag.
Is this legal advice?
No. It is experimental and for educational and informational purposes only.