skill
Contract Review
Lightweight NDA, MSA, and vendor contract review for SMBs without legal on staff. Reads contracts from local files, mail attachments (Gmail or M365), a connected file store (Google Drive or M365), or DocuSign envelopes; flags non-standard terms; explains risks in plain English; and outputs a marked-up redline as a separate DOCX. Use when the user says "review this contract," "what am I signing," "red flags," "flag any concerns," "check the payment terms," or uploads/forwards a contract or leg...
About
# Contract Review
## Where this skill sits
Two standing jobs, neither dependent on any chain:
1. **Standalone review** — the owner forwards or uploads any NDA, MSA, lease, or vendor agreement and gets the plain-English risk read and the redline. This is the everyday case for a business with no legal on staff. 2. **The counterparty's paper in a deal** — when `proposal-builder` sends a proposal out and the customer's own contract comes back, this skill is the risk read on that paper before the owner signs. That pairing is the quote-to-cash story's closing beat.
## Quick start
Attach a contract file, forward the email containing it, or paste the text directly.
``` User: "Review this MSA and flag anything I should push back on." → Skill reads the document, identifies parties and contract type, analyzes 8 risk categories, returns a severity-tiered summary with a negotiation playbook, and exports a redlined DOCX. ```
## Workflow
1. **Get the contract** — **Use what the user already gave you first.** If they attached a file or pasted the text, that is the document; go straight to step 2 and do not touch a connector. - **Local file or paste**: Read the PDF (chunked via `pages` parameter for 10+ page files) or DOCX via Read tool. If the user pastes text directly, work with what's provided. - **Gmail or Microsoft 365** (only when nothing was handed over): Search the connected mailbox for recent emails with contract attachments (see `reference/gmail-fetch.md`, or `reference/m365-fetch.md` for Microsoft 365) - **Google Drive or Microsoft 365** (only when nothing was handed over, and only in a folder the owner names): search the connected file store for the document by counterparty name or agreement title — never browse recent files (see `reference/m365-fetch.md`) - **DocuSign** (only when nothing was handed over): Fetch the envelope by ID or search recent drafts awaiting signature (see `reference/docusign-fetch.md`)
If no connector is available and nothing was handed over, ask the user to paste the text or attach the file. That is a normal path, not a failure.
A connected mailbox, file store, or DocuSign account is the owner's only once its address or tenant matches the `## Business context` block or the owner names it; on a mismatch, stop and ask, and use nothing read from it (`../../shared/tenant-scope.md`).
Read the full document before analyzing. Dangerous clauses are frequently in exhibits and schedules at the back.
2. **Identify contract type and parties** — Determine agreement type (NDA, MSA, SOW, SaaS subscription, consulting, subcontractor, vendor) and which party is the user's company vs. the counterparty. **If the document does not make it obvious which side the owner is on, ask** — one line, naming both parties. Reviewing from the wrong side inverts every red flag in the summary. Note if it looks like a counterparty template — these are typically one-sided and the counterparty expects pushback.
3. **Analyze across 8 risk categories** — Work through the contract from the ops/finance perspective of a small business owner without in-house legal. Categories are ordered by typical risk severity; use judgment for context.
**Category 1: Payment terms and cash flow** - Payment timing: Net-30 is standard; Net-60+ is flaggable; Net-90/120 is a hard negotiation point - Payment triggers: acceptance periods that let the client slow-walk approvals indefinitely - Late payment penalties: absence is a gap worth noting - Invoicing requirements: rigid formats or PO numbers that can delay payment on technicalities - Expense reimbursement: pre-approval requirements and caps - Rate adjustments: annual increase mechanism for multi-year engagements
**Category 2: Liability and indemnification** - Liability caps: uncapped liability is always a red flag - Mutual vs. one-sided indemnification - Indemnification scope: "any and all claims arising from the services" is not standard - Insurance requirements: E&O, cyber, general liability — achievability at the required limits - Consequential damages waiver: missing = flag prominently
**Category 3: Termination and exit** - Termination for convenience: is it mutual? 30-day notice is typical - Termination for cause: cure period; vague "material breach" without definition - Wind-down: payment for in-progress work at termination - Transition assistance: paid vs. unpaid, time-limited vs. open-ended - Survival clauses: indefinite indemnification survival = flag
**Category 4: Intellectual property** - IP assignment vs. license - Pre-existing IP and background tools carve-out — absence means inadvertent assignment - Work product definition breadth: drafts, notes, internal tools
**Category 5: Scope and change management** - Scope definition clarity - Change order process: absence = scope creep without compensation - Acceptance criteria: subjective ("to client's
Install
Run this command
git clone https://github.com/anthropics/knowledge-work-plugins && cp -r knowledge-work-plugins/small-business/skills/contract-review ~/.claude/skills/Works with
Manual steps
Clone the repository and copy the `small-business/skills/contract-review` folder into your Claude skills directory. Compatible with Claude Code, Cursor, Codex, and any Agent Skills-compatible agent.
Related assets
More curated picks in Productivity & Office.
npm install @modelcontextprotocol/server-time
git clone https://github.com/anthropics/knowledge-work-plugins && cp -r knowledge-work-plugins/operations/skills/change-request ~/.claude/skills/
git clone https://github.com/anthropics/knowledge-work-plugins && cp -r knowledge-work-plugins/product-management/skills/product-brainstorming ~/.claude/skills/
git clone https://github.com/anthropics/knowledge-work-plugins && cp -r knowledge-work-plugins/operations/skills/compliance-tracking ~/.claude/skills/
git clone https://github.com/anthropics/knowledge-work-plugins && cp -r knowledge-work-plugins/operations/skills/process-optimization ~/.claude/skills/
git clone https://github.com/anthropics/knowledge-work-plugins && cp -r knowledge-work-plugins/enterprise-search/skills/search-strategy ~/.claude/skills/
Audit before you install
Run any source through our checks - AI visibility, security, performance, and stack detection.
Automated Web Security Scan
security
PageSpeed Analyzer
performance
AI Content Quality Test
arabic content
AI Agent / MCP Server Tester
ai testing
Site Stack Detector
migration
AI SEO / AEO / GEO Audit
ai visibility
llms.txt Generator
ai visibility
Readability Score
arabic content
Schema / JSON-LD Builder
ai visibility
AI Cost Calculator
ai testing
Headline Analyzer
arabic content