vendor-ai-review

Compare vendor AI agreement terms against internal governance positions to identify gaps.

Updated Dec 4, 2025
One-click install
npx skills add https://github.com/PolliticalSolutions/political-portal --skill vendor-ai-review-polliticalsolutions
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-ai-review
Source: https://github.com/PolliticalSolutions/political-portal/tree/main/.claude/skills/ai-governance-legal/vendor-ai-review
Command: npx skills add https://github.com/PolliticalSolutions/political-portal --skill vendor-ai-review-polliticalsolutions

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Vendor AI agreements often contain hidden terms about training on your data, liability for AI output errors, model change notices, and auditability that can conflict with your governance positions.

Core Features & Use Cases

  • Term-by-term AI governance review: evaluates training on data, confidentiality, model changes, output/IP ownership, liability, incident notification, human review rights, use restrictions, audit rights, subprocessors, data residency, and termination/deletion.
  • Playbook consistency check: compares findings against governance positions in the configured CLAUDE.md playbook and assigns severity (aligned to critical) per term.
  • Stacked-vendor gap detection: identifies upstream model/provider layers (SaaS wrapper, gateway, foundation model provider, RAG/index/data services) and checks flow-down risk where upstream commitments may not be enforceable.

Quick Start

Use the vendor AI review skill to review the attached AI addendum or agreement text for training-on-data, liability, model changes, and policy consistency.

Frequently Asked Questions about vendor-ai-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a vendor AI agreement for training on data and liability risks?

To review a vendor AI agreement for risks, perform a term-by-term extraction comparing training on data, liability, model change notice, and output ownership clauses against your internal governance positions to identify contractual gaps.

What terms should I check in an AI addendum during SaaS procurement?

When checking an AI addendum during SaaS procurement, review confidentiality, incident notification, human review rights, use restrictions, audit rights, subprocessors, data residency, and termination clauses to ensure alignment with your governance playbook.

How does stacked-vendor gap detection work for upstream model providers?

Stacked-vendor gap detection works by identifying upstream layers like SaaS wrappers, gateways, and foundation model providers, then checking flow-down enforceability to ensure upstream commitments hold across the vendor stack.

Can I compare vendor AI terms against my existing CLAUDE.md playbook?

Yes, you can compare vendor AI terms against your CLAUDE.md playbook by running a consistency check that evaluates extracted provisions and assigns severity levels from aligned to critical per term based on your governance positions.

What is flow-down enforceability risk in vendor AI agreements?

Flow-down enforceability risk in vendor AI agreements is the danger that upstream model provider or gateway commitments—such as data residency or incident notification—may not be contractually enforceable against the end customer.

When do I need a term-by-term AI governance review?

You need a term-by-term AI governance review when deploying vendor AI or SaaS solutions during procurement and legal workflows, especially when agreements contain embedded terms of service or AI addenda with training-on-data and model change provisions.