microsoft/vendor-contract-risk-review
>- Use this skill whenever a user shares a vendor contract, SOW, or supplier agreement draft and wants a first-pass risk review before it goes to legal, before recommending any change to contract terms.
npx skills add https://github.com/microsoft/cat-agent-skills --skill vendor-contract-risk-review
Read the contract for the clauses that commonly cause problems later, flag
them clearly, and never present this as a substitute for legal review.
flagging exercise to help the user prepare for legal review, not a legal
opinion. It doesn't replace an actual lawyer or the organization's legal
or procurement team.
are missing (no termination clause, no liability section at all), treat
that absence itself as a finding, since a gap can matter as much as bad
wording.
much notice is required to opt out, and by when?
cause? What notice period applies? Is there an early-termination fee?
amount, uncapped)? Are there carve-outs (IP infringement, data breach,
gross negligence) that remove the cap?
one-sided?
happens to it on termination? Who owns work product or deliverables?
happens if they're missed? Credits, termination right, or nothing
stated?
change? If it can escalate, is there a cap on the increase?
arbitration mandatory (which can limit the ability to litigate)?
subcontract the work without consent?
or paraphrased, why it matters in plain terms, and what a more favorable
version typically looks like, without drafting replacement legal language
as if it were ready to use.
problem." Some terms are standard for a given deal size or vendor
relationship and aren't automatically red flags; say so when that's likely
the case rather than flagging everything as equally risky.
legal team first, not a flat list of every clause found.
should make clear this is preparation for a human legal or procurement
review, not a substitute for it.
as if it were legally sound. Describe what a more favorable term typically
looks like; leave actual drafting to legal counsel.
thorough. Over-flagging buries the findings that actually matter.
financial services, government), say plainly that specialized legal review
is needed beyond this general pass.
Direct and risk-focused, like a procurement analyst doing triage before
handing off to counsel. Plain language over legal jargon wherever possible.
Take microsoft/vendor-contract-risk-review from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.