vendor-ai-review

Review vendor AI agreement terms against internal governance positions.

Updated May 19, 2026
One-click install
npx skills add https://github.com/jrhueiueng/codex-for-legal --skill vendor-ai-review-jrhueiueng
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-ai-review
Source: https://github.com/jrhueiueng/codex-for-legal/tree/main/plugins/jrhueiueng/codex-for-legal/skills/ai-governance-legal__vendor-ai-review
Command: npx skills add https://github.com/jrhueiueng/codex-for-legal --skill vendor-ai-review-jrhueiueng

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Vendor AI agreements often hide high-risk terms—like training on your data, model-change notices, liability for AI outputs, and human review rights—making it hard to tell whether the contract matches your governance positions.

Core Features & Use Cases

  • Governance-position comparison: Compares vendor AI terms term-by-term against your playbook positions in ai-governance-legal/CLAUDE.md.
  • AI-specific risk coverage: Reviews training-on-data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review rights, use restrictions, auditability, subprocessors/model providers, data residency, and termination impacts.
  • Stacked-vendor flow-down checks: Identifies when there are multiple layers (app, gateway, model provider, RAG/data sources, subprocessors) and checks whether commitments flow down or leave gaps.
  • Output-ready negotiation guidance: Produces a bottom line, severity-tagged term gaps, and recommended surgical redlines, plus escalation routing when outside fallback.
  • DPA gap awareness + policy consistency: Detects missing AI addenda when a DPA exists and flags inconsistencies with your stated AI policy commitments.

Quick Start

Use vendor-ai-review to review the AI addendum in openai-enterprise-agreement.pdf.

Frequently Asked Questions about vendor-ai-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review vendor AI contract terms against my data governance positions?

To review vendor AI contract terms against your data governance positions, compare agreement clauses term-by-term against your internal AI playbook to identify gaps in training-on-data rights, confidentiality, and liability.

What is a stacked-vendor flow-down check for AI agreements?

A stacked-vendor flow-down check identifies multi-layer AI scenarios—like app, gateway, model provider, and subprocessors—to verify whether contractual commitments flow down properly or leave governance gaps in the agreement.

How do I generate redlines for an AI addendum based on severity?

You can generate surgical redlines for an AI addendum by mapping vendor terms against your governance playbook, which produces severity-tagged gap analyses and recommended contract revisions for each identified risk.

Does contract review cover AI model change notice and human review rights?

Yes, contract review covers AI-specific risks including model-change notice requirements, human review rights, output IP ownership, incident notification obligations, and limitations on use restrictions embedded in the terms.

Can I detect missing AI addenda when a data processing agreement already exists?

Yes, the review process detects missing AI addenda when a DPA exists and flags inconsistencies between the vendor terms and your stated AI policy commitments to ensure full governance coverage.

When should I escalate vendor AI liability risks outside my fallback positions?

You should escalate vendor AI liability risks when the agreement terms fall outside your established playbook fallbacks, using the severity-tagged gap analysis to route high-risk contractual deviations to the appropriate stakeholders.