skills/legal/confidentiality-security-agreement/SKILL.md
Drafts enforceable U.S. Employee Confidentiality and Security Agreements protecting proprietary information, trade secrets, and digital assets, with layered confidential-information definitions, security and acceptable-use obligations, incident reporting protocols, termination property-return procedures, and post-employment restrictive covenants. Incorporates state-specific enforceability standards, DTSA whistleblower immunity notice, and NLRA Section 7 savings clauses. Use when onboarding employees, updating confidentiality policies, or drafting NDA-style employment agreements (trigger keywords: confidentiality agreement, employee NDA, security agreement, trade secret, acceptable use, incident reporting, post-employment restrictions).
npx skillsauth add casemark/skills confidentiality-security-agreementInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Drafts an execution-ready agreement protecting company proprietary information, trade secrets, and digital assets while establishing employee security obligations and post-employment restrictions.
Ask every time unless user says "use defaults." Gather:
If user doesn't respond, apply and label defaults: at-will employment state; general staff access level; 3-year non-trade-secret duration; 1-year non-solicitation; governing law per company's home state.
| Item | Details | |---|---| | Company (legal name/entity/state) | | | Employee (name/title/department) | | | Governing jurisdiction | | | Access level (general / elevated / executive) | | | Regulated industry? (specify) | | | Existing agreements to harmonize | | | Post-hire execution? (additional consideration needed) | |
| Area | Key Items | |---|---| | State enforceability | Restrictive covenant standards, blue-pencil vs. reformation, consideration requirements | | Trade secret law | UTSA adoption, state statutes, DTSA federal protections | | Employee mobility | Non-compete bans/restrictions, NLRA § 7 protections, whistleblower statutes | | Data protection | State privacy acts, HIPAA, GLBA, CMMC (if defense) | | Recent case law | Reasonableness standards for scope/duration in governing jurisdiction |
| Category | Examples | |---|---| | Technical/Proprietary | Trade secrets, source code, algorithms, R&D, manufacturing processes | | Business Strategy | Business plans, pricing, margins, financial projections, M&A targets | | Customer/Relationship | Customer lists, supplier networks, contract terms, referral sources | | Financial/Operational | Financial statements, budgets, compensation structures, performance metrics | | Intellectual Property | Inventions, patents, copyrights, trademarks, proprietary methodologies |
Employee bears burden of proof (clear and convincing evidence):
Immediate notice to legal on receipt of subpoena/court order → cooperate with protective order efforts → disclose only what is legally required.
| Permitted | Prohibited | |---|---| | Primary business use of company systems | Unauthorized software/extension installation | | Limited personal use (non-interfering) | Circumventing security controls or monitoring | | Professional communications via company tools | Unauthorized devices on company networks | | | Illegal, explicit, or infringing content | | | Competitive activities on company systems | | | Company data on unapproved personal cloud |
Reportable: data breaches, unauthorized access, malware, phishing, lost/stolen devices, inadvertent disclosure, suspicious behavior, physical security breaches.
Non-retaliation: Good faith reporting carries no negative consequences, even if incident resulted from employee's error.
Company rights: inspect workspace/devices, remotely wipe MDM-enrolled devices, pursue legal remedies.
| Obligation | Duration | |---|---| | Trade secret confidentiality | Indefinite (while information qualifies) | | Other Confidential Information | [3–5] years post-termination | | Employee non-solicitation | [1–2] years (jurisdiction-dependent) | | Customer non-solicitation | [1–2] years, material-contact customers only |
[VERIFY][VERIFY]Employee signature, printed name, date; authorized company representative signature, title, date. Separate acknowledgment page optional.
After delivering the initial draft, ask:
If user doesn't answer, recommend confirming non-solicitation scope and post-hire consideration (highest-risk decisions) and proceed if authorized.
Before finalizing, verify:
[VERIFY][VERIFY][VERIFY][VERIFY][VERIFY current status][VERIFY][VERIFY]tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.