/SKILL.md
Reviews incoming one-way (unilateral) commercial NDAs in a jurisdiction-agnostic way, from either a Recipient or Discloser perspective (user-selected), producing a clause-by-clause issue log with preferred redlines, fallbacks, rationales, owners, and deadlines.
npx skillsauth add jamietso/nda-review-skill nda-reviewInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Version 1.0 — December 2025
This skill is a structured review playbook. It is not legal advice. When the NDA is high-risk, high-value, cross-border, or otherwise sensitive, escalate to qualified counsel.
| What this skill does | What it does not do | |---|---| | Reviews an NDA and outputs issues, risks, and suggested redlines | Provide jurisdiction-specific legal conclusions | | Supports Recipient or Discloser perspectives (user-chosen) | Guarantee enforceability | | Produces an executive summary + clause-by-clause markup guidance | Replace counsel for complex deals |
Scope limitation (important): this playbook supports one-way (unilateral) commercial NDAs only.
If the NDA is mutual, stop: this playbook is out of scope and you should escalate to counsel or use a separate mutual-NDA review approach.
Variation callouts appear throughout:
- M&A / Due diligence
- Employment / contractor
- Investor / VC
Jurisdiction-agnostic note: avoid asserting “this clause is invalid” without the governing law details; focus on commercial risk, operational feasibility, and market norms.
ALWAYS output:
Use a single table so counsel and business owners can track issues, owners, and deadlines.
| Clause | Issue (1 line) | Risk (H/M/L) | Preferred redline | Fallback | Rationale (1–2 sentences) | Owner | Deadline | |---|---|---:|---|---|---|---|---| | Definition | Overbroad; includes unmarked info with no reasonableness | | | | | | | | Term & survival | Perpetual confidentiality for all information | | | | | | | | Use restriction | Purpose too broad; blocks internal evaluation | | | | | | | | Disclosures | Representatives undefined; strict liability | | | | | | | | Return/destruction | No backup carve-out | | | | | | | | Remedies | One-way fees + automatic injunction | | | | | | | | Liability | Indemnity + unlimited consequential damages | | | | | | | | Boilerplate | Assignment prohibits change of control | | | | | | |
Executive summary (example skeleton):
Issue log (example rows):
| Clause | Issue (1 line) | Risk (H/M/L) | Preferred redline | Fallback | Rationale (1–2 sentences) | Owner | Deadline | |---|---|---:|---|---|---|---|---| | Term & survival | Perpetual confidentiality for all information | H | Add 2–5 year survival; trade secret carve-out only | 5-year survival for all | Reduces indefinite operational burden while protecting truly sensitive info | Legal | Before signature | | Return/destruction | No backup carve-out | M | Add backup/legal hold exception + continued confidentiality | Allow retention in immutable backups only | Required for standard IT operations; avoids impossible compliance | Security + Legal | Before signature |
Quick heuristic:
Flag these immediately:
If any are present and the NDA matters, proceed with full review and consider escalation.
Use these references while reviewing:
For each issue, produce:
Negotiation discipline: do not propose 20 changes. Focus on the 5–10 that materially change risk.
| Topic | Red flags | Typical ask | |---|---|---| | Definition of Confidential Information | Overbroad; includes independently developed info; no marking/identification standard | Add reasonableness + identification standard; add exclusions | | Purpose / Permitted Use | Any use restriction beyond evaluation; bans on internal sharing | Tie to stated purpose; allow internal need-to-know | | Representatives | We are liable for any representative breach without control | Limit to those under written confidentiality; commercially reasonable care | | Term & survival | Perpetual for everything; unclear start date | Fixed term; longer only for trade secrets | | Return / destruction | Requires deletion of backups immediately | Add practical backup carve-out | | Remedies | One-way fees + broad injunction language | Mutuality or reasonableness; clarify equitable relief scope | | Liability / indemnity | Indemnity; unlimited damages; consequential damages | Cap or exclude categories; remove indemnity | | Residuals | Allows use of “retained in memory” | Delete or narrow heavily |
M&A / Due diligence: ensure diligence sharing (advisors, financing, affiliates) is permitted and that data room exports/notes are covered.
| Topic | Red flags | Typical ask | |---|---|---| | Definition | Too narrow; requires marking only; excludes oral disclosures | Add oral confirmation mechanism; broaden categories reasonably | | Security standard | Only “reasonable” with no baseline | Add minimum safeguards, or align with internal policy | | Exclusions | Too broad (e.g., “independently developed” with no proof) | Require written evidence of prior knowledge/independent development | | Term & survival | Too short | Extend for sensitive categories; trade secret survival | | Remedies | No equitable relief, no fees | Add equitable relief and/or fees (carefully) |
Investor / VC: watch for standstill, solicitation, and “no contact” provisions—these are not standard in plain NDAs and may need separate agreement.
| Rating | Meaning | Example | |---:|---|---| | High | Creates material, uncapped, or operationally impossible risk | Broad indemnity + unlimited damages for any breach | | Medium | Risk is real but manageable with process controls | Strict notice deadlines for compelled disclosure | | Low | Mostly cosmetic or market-standard | Minor notice method issues |
| Issue | Risk | Suggested fix | |---|---|---| | “All information is confidential forever” | Operational burden; unfair risk allocation | Add fixed term + trade secret carve-out | | No compelled disclosure carve-out | Breach if subpoenaed | Add “required by law” disclosure path | | Return/destruction requires purge of backups | Impossible to comply | Add backup and system integrity exception | | Recipient indemnifies discloser | Open-ended exposure | Remove indemnity; use direct damages only | | Residuals clause | Allows de facto use of confidential info | Delete or restrict to non-trade-secret, non-source-code |
Use these defaults to populate Owner and Deadline in the issue log:
| Topic | Default owner | Default deadline | |---|---|---| | Confidentiality scope/definition, exceptions, term/survival | Legal | Before signature | | Security standards / audit rights | Security + Legal | Before signature | | Return/destruction and backups | Security + IT + Legal | Before signature | | Liability cap / damages / indemnity / fees | Legal + Finance | Before signature | | Operational constraints (representatives, affiliates, tooling) | Legal + Business owner | Before signature |
If you want, I can add a short “model answer” example output format inside this file, but I kept v1 focused on the playbook structure (no extra templates/assets as requested).
testing
Create, edit, improve, or audit AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit, tidy up, or clean up an existing skill or SKILL.md file. Also use when editing or restructuring a skill directory (moving files to references/ or scripts/, removing stale content, validating against the AgentSkills spec). Triggers on phrases like "create a skill", "author a skill", "tidy up a skill", "improve this skill", "review the skill", "clean up the skill", "audit the skill".
testing
Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
testing
Create, edit, improve, or audit AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit, tidy up, or clean up an existing skill or SKILL.md file. Also use when editing or restructuring a skill directory (moving files to references/ or scripts/, removing stale content, validating against the AgentSkills spec). Triggers on phrases like "create a skill", "author a skill", "tidy up a skill", "improve this skill", "review the skill", "clean up the skill", "audit the skill".
testing
Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).