vendor-ai-review

Review vendor AI agreements against governance positions and generate redlines.

Updated Jun 17, 2026
One-click install
npx skills add https://github.com/tk1cntt/PhapChe --skill vendor-ai-review-tk1cntt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-ai-review
Source: https://github.com/tk1cntt/PhapChe/tree/main/docs/claude-for-legal-main/ai-governance-legal/skills/vendor-ai-review
Command: npx skills add https://github.com/tk1cntt/PhapChe --skill vendor-ai-review-tk1cntt

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Vendor AI contracts hide critical risks — training on your data, liability gaps, silent model changes — and reviewing them term-by-term against your organization's governance positions is slow and inconsistent. This Skill automates that comparison and produces actionable redlines. ## Core Features & Use Cases - Term-by-term contract review: Extracts and evaluates training-on-data, confidentiality, output IP, liability, incident notification, audit rights, and stacked-vendor flow-down clauses against your configured playbook. - Severity-rated gap analysis: Flags each term as aligned, note, significant, or critical, with proposed surgical redline language or escalation routing. - AI policy consistency check: Cross-checks vendor terms against your internal AI policy commitments and detects DPA-without-AI-addendum gaps. - Use Case: A vendor sends an AI addendum for a SaaS tool built on a cloud-hosted foundation model. The Skill maps the vendor stack, tests flow-down of data commitments across layers, and outputs a bottom-line recommendation with redlines. ## Quick Start Attach the vendor's AI agreement or addendum and ask to review these vendor AI terms against our governance positions.

Frequently Asked Questions about vendor-ai-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a vendor AI agreement for legal risks?

Share the vendor's AI addendum, main agreement AI provisions, or terms of service. The review extracts each key term — training on data, liability, model changes, output IP — and compares it against your governance playbook with severity ratings and proposed redlines.

What contract terms matter most in AI vendor agreements?

The training-on-data clause is typically most critical, followed by confidentiality of inputs, liability for outputs, model change notification, and incident notification. For stacked vendors, flow-down of commitments from upstream model providers must also be verified.

Can I review an AI contract without a configured playbook?

Yes. A provisional mode runs the review against generic defaults — US jurisdiction, middle risk appetite, lawyer role — and tags every output as provisional. Configuring the practice profile via the cold-start interview produces tailored results.

Does this review cover DPA and data protection terms?

No. The review covers AI-specific terms only and explicitly excludes DPA provisions, which require a separate DPA review. It does flag when a DPA exists without an AI addendum, since that leaves training, liability, and model-change risks unaddressed.

What happens if the vendor terms fall outside acceptable positions?

Terms outside the playbook's fallback positions are rated critical and routed per the escalation table rather than redlined. The review also documents gaps for renewal leverage and suggests fallback positions for each significant or critical finding.