- Home
- Skills
- Legal & Compliance
- ContractGuard — AI Contract Risk Review & Redline Generator
Works with the AI tools you already use
ContractGuard — AI Contract Risk Review & Redline Generator
The problem it solves Business teams sign contracts they have not read.
$39
ContractGuard — AI Contract Risk Review & Redline Generator
Example session with this skill installed
We're a US healthcare technology company. We're buying an AI medical scribe
product from a vendor called Lumen Health AI. 2-year deal, $95,000/year. The
product will process protected health information (PHI) from our patients, so
this is regulated data. Our legal team is stretched thin and we're under time
pressure — our existing vendor is sunsetting in 6 weeks, so we need to decide
fast. We're the customer. Balanced posture, leaning conservative because of
the PHI.
Here's what Lumen sent. They said the DPA is "available on request" and we
should just sign the MSA first.
--- EXCERPT: LUMEN HEALTH AI — MASTER SUBSCRIPTION AGREEMENT ---
1.3 "Protected Health Information" or "PHI" has the meaning given in
45 C.F.R. § 160.103. Lumen will process PHI solely on Customer's documented
instructions and solely to provide the Services.
2.4 Order of Precedence. In the event of a conflict between this Agreement
and any Business Associate Agreement executed between the parties, this
Agreement shall control.
4.1 Fees. Customer shall pay the annual subscription fee set forth in the
Order Form. Lumen may increase the subscription fee by up to seven percent
(7%) per year upon sixty (60) days' prior written notice.
5.2 Term. The Initial Term is twenty-four (24) months and shall
automatically renew for successive twelve (12) month periods unless either
party provides written notice of non-renewal at least sixty (60) days prior
to the end of the then-current term.
6.1 Machine Learning. Lumen may use de-identified data derived from
Customer's use of the Services, including clinical encounter data, to train,
fine-tune, and improve Lumen's machine learning models. Customer may opt out
of such use by providing written notice to Lumen, in which case Lumen will
cease such use within ninety (90) days.
7.2 Data Security. Lumen shall implement commercially reasonable
administrative, technical, and physical safeguards designed to protect PHI.
Lumen will notify Customer of any confirmed Breach of unsecured PHI without
unreasonable delay and in no event later than thirty (30) days after
discovery.
9.1 Limitation of Liability. Each party's total aggregate liability arising
out of or relating to this Agreement, whether in contract, tort, or
otherwise, shall not exceed the fees paid by Customer in the six (6) months
preceding the claim. Neither party shall be liable for indirect, incidental,
special, or consequential damages. The foregoing limitations shall not apply
to a party's gross negligence or willful misconduct, or to Customer's
indemnification obligations under Section 10.
10.2 Indemnification. Customer shall indemnify, defend, and hold harmless
Lumen from claims arising out of (a) Customer's use of the Services in
violation of applicable law, or (b) Customer's breach of Section 1.3. Lumen
shall indemnify Customer from third-party claims alleging that the Services
infringe any U.S. patent or copyright.
12.3 Service Levels. Lumen shall make the Services available 99.5% of the
time, measured monthly. Customer's sole and exclusive remedy for any failure
to meet the service level shall be service credits as set forth in the
Service Level Schedule.
14.2 Termination. Lumen may terminate this Agreement for convenience upon
sixty (60) days' notice. Either party may terminate for material breach not
cured within thirty (30) days after written notice.
15.1 Confidentiality. Each party shall protect the other's Confidential
Information using at least the same degree of care it uses to protect its own
confidential information, and in no event less than reasonable care, for a
period of five (5) years following disclosure, except that trade secrets
shall be protected for so long as they remain trade secrets.
17.4 Amendments. Lumen may update these Terms by posting a revised version
at lumenhealth.ai/terms. Continued use of the Services thirty (30) days after
posting constitutes acceptance.
--- END EXCERPT ---
- Read your context and instructions
- Compiled the contractguard
- Generated the document
Contract Risk Brief — Lumen Health AI Master Subscription Agreement
Prepared for: Buyer (Customer) ·
Posture: Balanced, conservative-leaning given PHI exposure ·
Playbook: Default (no contractguard-playbook.md found)
Overall deal risk: CRITICAL
Recommendation: NEGOTIATE THEN SIGN
Not legal advice. Route all Critical and High findings to qualified counsel before signature. Protected Health Information (PHI, patient health data protected under federal law) is in scope; healthcare-specialized counsel review is mandatory before signature regardless of the scores below.
1. Deal snapshot
| Field | Value |
|---|---|
| Parties | Customer (unnamed US healthcare technology company, buyer) and Lumen Health AI ("Lumen," vendor) |
| User's side | Buyer/Customer — stated by user |
| Effective date / term | Effective date not stated. Initial Term: 24 months (§5.2) |
| Renewal | Automatic 12-month renewals unless either party gives 60 days' non-renewal notice (§5.2) |
| Contract value | $95,000/year (user-stated) — approx. $190,000 over the 24-month Initial Term |
| Governing law / venue | Not stated in provided excerpt |
| Order of precedence | MSA controls over the Business Associate Agreement (BAA) in a conflict (§2.4) — see Critical finding F1 |
| Source completeness | BAA not provided, referenced at §2.4 [INCOMPLETE SOURCE]; Order Form not provided, referenced at §4.1 [INCOMPLETE SOURCE]; Service Level Schedule not provided, referenced at §12.3 [INCOMPLETE SOURCE] |
2. Top five issues
- No Business Associate Agreement (BAA) has been executed or provided, and Lumen has told you to sign the MSA first — this is not sequencing, it's a legal prerequisite gap (F2, Critical).
The MSA overrides the BAA on any conflict (§2.4), meaning HIPAA-driven privacy and security terms in the BAA could be legally subordinated to this contract (F1, Critical).
3.
Lumen can train its models on your clinical data by default, with opt-out (not opt-in) and a 90-day tail after you object (§6.1) (F3, Critical).
4. Lumen can change the contract terms unilaterally just by posting new terms online (§17.4) (F4, Critical).
5.
Liability is capped at 6 months' fees (~$47,500) with no carve-out for a PHI data breach — far below realistic breach costs (F5, High).
3. Risk register
| # | Clause | § | Severity | Issue in one sentence | Business impact |
|---|---|---|---|---|---|
| F1 | Order of precedence | 2.4 | Critical | MSA controls over the BAA in any conflict | Could nullify HIPAA-required BAA protections exactly when they matter most |
| F2 | Missing BAA | 2.4 (ref.) | Critical | No BAA executed or supplied before PHI processing begins | Processing PHI without an executed BAA is a foundational HIPAA compliance gap |
| F3 | Model training on PHI-derived data | 6.1 | Critical | Opt-out (not opt-in) use of clinical data to train Lumen's models, 90-day tail | Loss of control over derivative use of patient data; de-identification standard unconfirmed |
| F4 | Unilateral amendment | 17.4 | Critical | Lumen can change terms by posting online; continued use = acceptance | Terms you negotiate today can be silently overridden later |
| F5 | Liability cap | 9.1 | High | Cap is 6 months' fees with no PHI breach carve-out | Exposure from a real breach could vastly exceed the ~$47,500 cap |
| F6 | Breach notification window | 7.2 | High | 30-day notice window to Customer, vague security standard | Compresses your own HIPAA notification timeline to HHS/patients |
| F7 | Indemnification scope | 10.2 | High | Lumen only indemnifies for patent/copyright infringement, not data breach | You bear the cost of a Lumen-caused PHI breach with no vendor backstop |
| F9 | Termination asymmetry | 14.2 | High | Only Lumen has a termination-for-convenience right; no transition assistance | Vendor can exit with 60 days' notice while you're locked in for cause-only termination |
| F8 | SLA sole remedy | 12.3 | Medium | Service credits are the sole remedy for downtime | No off-ramp for chronic or material outages of clinical documentation tooling |
| F10 | Fee increase cap | 4.1 | Medium | 7% annual increase allowed, no termination right on increase | Exceeds default 5%/CPI benchmark; no exit valve if pricing outpaces budget |
4. Findings and fallback ladder
F1 — Order of precedence · Critical
Location: §2.4
Current language: "In the event of a conflict between this Agreement and any Business Associate Agreement executed between the parties, this Agreement shall control."
Why it matters: A BAA (Business Associate Agreement, the HIPAA-required contract governing how a vendor may use and protect PHI) is supposed to set the floor for how PHI is handled. Subordinating it to the MSA means any privacy or security commitment in the BAA can be overridden by this document — including one Lumen can unilaterally amend under §17.4.
Ideal position: BAA controls on all PHI-related terms; MSA controls on everything else.
Target position: BAA controls on privacy, security, and breach-notification terms specifically; MSA controls only on commercial terms.
Acceptable minimum: An express carve-out stating the BAA controls on any term required by 45 C.F.R. Part 164.
Walk-away trigger: Lumen refuses any carve-out preserving BAA primacy on PHI terms.
Replacement language:
"In the event of any conflict between this Agreement and the Business Associate Agreement executed between the parties with respect to the use, disclosure, or protection of Protected Health Information, the Business Associate Agreement shall control. In all other respects, this Agreement shall control."
F2 — Missing Business Associate Agreement · Critical [INCOMPLETE SOURCE]
Location: §2.4 (reference only — no BAA text supplied)
Current language: No BAA text was available. §2.4 references "any Business Associate Agreement executed between the parties." Per the user, Lumen stated the DPA/BAA is "available on request" and recommended executing the MSA first.
Why it matters: HIPAA requires a compliant BAA to be in place before a business associate processes PHI. Signing the MSA — especially one that subordinates the BAA (F1) — before the BAA exists or is even reviewed reverses the correct sequence and leaves you processing PHI without the legally required safeguards documented.
Ideal position: Full BAA reviewed and executed concurrently with, or before, the MSA.
Target position: BAA execution as a condition precedent written into the MSA itself.
Acceptable minimum: Written commitment with a firm delivery date for BAA review, with no PHI flowing until execution.
Walk-away trigger: Lumen cannot produce a BAA, or asks you to begin processing PHI before one is signed.
Replacement language:
"Lumen shall execute the Business Associate Agreement (attached as Exhibit A) concurrently with this Agreement. No Services involving Protected Health Information shall commence, and no PHI shall be transmitted to Lumen, until both documents are fully executed by both parties."
F3 — Model training on clinical data · Critical
Location: §6.1
Current language: "Lumen may use de-identified data derived from Customer's use of the Services, including clinical encounter data, to train, fine-tune, and improve Lumen's machine learning models."
Why it matters: This is opt-out, not opt-in — the default playbook's permanent walk-away trigger for AI training terms. "De-identified" is doing a lot of work here: the clause doesn't specify whether de-identification meets HIPAA's Safe Harbor or Expert Determination standard, and even after you opt out, Lumen keeps using your data for another 90 days.
Ideal position: No training on Customer-derived data without explicit prior written opt-in.
Target position: Opt-in required, with the de-identification method specified and immediate (not 90-day) cessation upon revocation.
Acceptable minimum: Opt-in required at minimum for anything derived from clinical encounter data (as opposed to fully de-identified aggregate usage metrics).
Walk-away trigger: Lumen insists on retaining an opt-out default for clinical encounter data.
Replacement language:
"Lumen may not use Customer Data, including de-identified or aggregated data derived from Customer Data, to train, fine-tune, or improve Lumen's machine learning models unless Customer has provided prior written opt-in consent, which Customer may revoke at any time effective immediately upon notice."
F4 — Unilateral amendment · Critical
Location: §17.4
Current language: "Lumen may update these Terms by posting a revised version at lumenhealth.ai/terms. Continued use of the Services thirty (30) days after posting constitutes acceptance."
Why it matters: This lets Lumen rewrite the deal you negotiated — including the BAA-subordination clause in F1 — just by posting a webpage. For a regulated-data contract, this is a permanent walk-away trigger regardless of how the other terms land.
Ideal position: No amendments without a signed writing from both parties.
Target position: Same, with an exception for non-material administrative updates (e.g., contact addresses).
Acceptable minimum: Material terms (fees, liability, data use, security, termination) require signed written amendment; only truly administrative terms may be updated by notice.
Walk-away trigger: Lumen refuses to remove unilateral amendment rights over any material term.
Replacement language:
"Lumen may amend this Agreement only by written agreement signed by both parties. No amendment shall be effective solely by posting revised terms online or by Customer's continued use of the Services."
F5 — Limitation of liability · High
Location: §9.1
Current language: "shall not exceed the fees paid by Customer in the six (6) months preceding the claim."
Why it matters: Six months' fees is roughly $47,500 — a fraction of what a PHI breach typically costs once you add breach notification, credit monitoring, regulatory fines, and reputational harm. The carve-outs cover gross negligence and your own indemnification obligations, but not a data breach caused by Lumen.
Suggested ask: Raise the cap to 12 months' fees or a fixed floor (e.g., $500,000), and add an uncapped or separately-capped carve-out for PHI breaches and confidentiality violations.
Replacement language:
"Each party's total aggregate liability arising out of or relating to this Agreement shall not exceed the greater of (a) the fees paid or payable by Customer under this Agreement in the twelve (12) months preceding the claim, or (b) $500,000. The foregoing cap shall not apply to (i) either party's indemnification obligations, (ii) breach of confidentiality obligations, (iii) a Security Incident or Breach of unsecured PHI, or (iv) gross negligence or willful misconduct."
F6 — Breach notification window · High
Location: §7.2
Current language: "Lumen will notify Customer of any confirmed Breach of unsecured PHI without unreasonable delay and in no event later than thirty (30) days after discovery."
Why it matters: As the covered entity, you have your own HIPAA clock — generally 60 days from discovery to notify HHS and affected patients. If Lumen waits the full 30 days to tell you, you're left with roughly half your own compliance window to investigate, draft notices, and mail them.
Suggested ask: Shorten to 72 hours and require Lumen to supply the information you need to meet your own downstream notification duties.
Replacement language:
"Lumen will notify Customer of any Security Incident or confirmed Breach of unsecured PHI without unreasonable delay and in no event later than seventy-two (72) hours after discovery, and will provide all information reasonably necessary for Customer to meet its own notification obligations under 45 C.F.R. Part 164, Subpart D."
F7 — Indemnification scope · High
Location: §10.2
Current language: "Lumen shall indemnify Customer from third-party claims alleging that the Services infringe any U.S. patent or copyright."
Why it matters: Lumen's indemnification duty runs only to IP infringement claims. If Lumen causes a PHI breach through its own negligence, you have no indemnification backstop — only the thin liability cap in F5.
Suggested ask: Add vendor indemnification for data breach and unauthorized PHI disclosure.
Replacement language:
"Lumen shall indemnify, defend, and hold harmless Customer from and against any third-party claims, damages, fines, and costs (including breach notification and credit monitoring costs) arising out of (a) Lumen's breach of its data security or confidentiality obligations, (b) any Security Incident or Breach of PHI caused by Lumen or its subcontractors, or (c) allegations that the Services infringe any U.S. patent or copyright."
F9 — Termination asymmetry · High
Location: §14.2
Current language: "Lumen may terminate this Agreement for convenience upon sixty (60) days' notice."
Why it matters: Only Lumen gets a no-fault exit; you're locked in for the 24-month term absent a material breach. Combined with no transition-assistance obligation, a Lumen-initiated exit could leave your clinical documentation workflow stranded with 60 days to migrate — the same bind you're in with your current vendor.
Suggested ask: Add a reciprocal termination-for-convenience right and a transition assistance obligation.
Replacement language:
"Either party may terminate this Agreement for convenience upon sixty (60) days' written notice. Upon any termination or expiration, Lumen shall provide up to ninety (90) days of transition assistance, including data export in a usable format, at no additional charge."
F8 — Service levels · Medium
Location: §12.3 ·
Issue: Service credits are the sole and exclusive remedy for downtime, even if outages are chronic or material. ·
Suggested ask: Add a termination-for-cause right after two consecutive months (or three in twelve) below the 99.5% commitment.
F10 — Fees & payment · Medium
Location: §4.1 ·
Issue: 7% annual increase cap exceeds the 5%/CPI market benchmark, with no termination right if invoked. ·
Suggested ask: Cap increases at CPI or 5%, whichever is greater, with a termination right if Lumen invokes the maximum.
5. Missing clauses
Security certification obligations — no SOC 2 Type II, ISO 27001, or penetration-testing commitment anywhere in the excerpt. For a vendor processing PHI, this is a foundational gap. Insert a requirement for current SOC 2 Type II or ISO 27001 certification, annual third-party penetration testing, and a defined remediation SLA for critical vulnerabilities.
2.
Insurance requirements — no cyber liability or errors & omissions insurance requirement. Insert a minimum coverage requirement (e.g., $2M cyber liability, $1M E&O) with Customer named as additional insured or certificate holder.
3.
Governing law / dispute resolution — not addressed in the provided excerpt. Insert a governing-law and venue clause reflecting Customer's home jurisdiction, with an injunctive-relief carve-out if arbitration is used.
4.
Direct audit rights — no customer right to audit Lumen's security controls independent of the (unsupplied) BAA. Insert an annual audit right with 30 days' notice, using Lumen's existing SOC 2 report as the first line of documentation.
5.
Assignment / change of control — not addressed. Insert a consent requirement for assignment outside an affiliate or merger context, particularly given the sensitivity of a PHI-handling vendor changing ownership.
6. Trade matrix
| Concede (low value to us) | Extract (high value to us) |
|---|---|
| Accept service credits as the primary remedy for downtime | In exchange, get a termination-for-cause right after chronic/material SLA failures (F8) |
| Accept a 5–7% annual fee increase | In exchange, get a termination right if the increase exceeds 5% (F10) |
| Keep the 24-month initial term | In exchange, get a reciprocal termination-for-convenience right and 90-day transition assistance (F9) |
| Accept "commercially reasonable" as the general security baseline | In exchange, require named certifications (SOC 2 Type II / ISO 27001) and a defined pen-test cadence |
| Accept Lumen's standard IP indemnification language as-is | In exchange, add vendor indemnification for data breach and unauthorized PHI disclosure (F7) |
Sequencing given the 6-week timeline: treat F1 (BAA precedence), F2 (missing BAA), F3 (training opt-in), and F4 (unilateral amendment) as non-negotiable first-pass asks — these are structural and cheap for Lumen to fix. Push those to closure first; the fee cap (F10) and SLA remedy (F8) trade items can be finalized in parallel or slightly after, since they don't block signature on compliance grounds.
7. Open questions for counsel
- Does subordinating the BAA to the MSA (§2.4) comply with the Business Associate provisions of 45 C.F.R. § 164.504(e), given that the BAA is meant to control PHI use and disclosure terms?
- Does the "de-identified data" used for model training under §6.1 meet HIPAA's Safe Harbor or Expert Determination de-identification standard, or does the clinical-encounter linkage keep it identifiable?
- Does the 30-day breach notification window in §7.2 leave Customer enough time to meet its own HIPAA Breach Notification Rule obligations to HHS and patients?
- Is Lumen's unilateral amendment clause (§17.4) enforceable against a customer with independent HIPAA compliance obligations, given that continued use constitutes acceptance?
- Does the liability cap and indemnification allocation in §9.1/§10.2 hold up under the healthcare-data-breach liability standards of Customer's home state?
8. Assumptions and limitations
- Only the excerpted sections were provided. The full MSA, the BAA (referenced §2.4), the Order Form (referenced §4.1), and the Service Level Schedule (referenced §12.3) were not supplied and are tagged
[INCOMPLETE SOURCE]above. - User's side (buyer/customer) was stated explicitly, not inferred.
- Posture applied: balanced with a conservative lean, per the user's stated PHI sensitivity — this tightened the liability-cap and data-use recommendations above default.
- Deal value used ($95,000/year, ~$190,000 over the 24-month Initial Term) is as stated by the user; not independently confirmed against a supplied Order Form.
- Governing law, venue, insurance, security certifications, and audit rights are absent from the provided text — this brief cannot confirm whether they exist elsewhere in the full agreement.
- This brief does not cover enforceability opinions, state-specific healthcare data breach liability standards, or any provision outside the sections quoted above.
Since no saved playbook was found, I can save these positions (liability floor, opt-in training, BAA precedence, etc.) to contractguard-playbook.md so future vendor reviews start from this baseline — just say the word if you'd like that.
contractguard-ai-contract-risk-review-re.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
ContractGuard is a production-grade Claude Code skill that reviews MSAs, SaaS terms, NDAs, DPAs, SOWs, order forms, and vendor agreements against a configurable risk playbook — then produces a structured, severity-ranked negotiation brief with redline-ready replacement language for every finding.
The problem it solves Business teams sign contracts they have not read. Legal teams are a bottleneck. Reviewing a vendor agreement properly takes hours a generalist does not have and a lawyer may not be available to spend. The result: teams accept uncapped liability, perpetual data licenses, unilateral amendment rights, and AI training clauses they never would have agreed to if someone had pointed them out.
What ContractGuard produces Every run generates an eight-section Contract Risk Brief:
Section What it contains Deal snapshot Parties, term, value, governing law, source completeness Top five issues The five findings that most affect the decision Risk register Every finding with clause, section reference, severity, and business impact Findings and fallback ladder Full eight-field blocks for Critical findings, compressed blocks with replacement language for High findings, one-line entries for Medium Missing clauses Provisions your side would normally require, with suggested insert language Trade matrix Concede/extract pairs that turn the analysis into negotiating ammunition Open questions for counsel Five or fewer questions that genuinely require a licensed opinion Assumptions and limitations Source completeness, inferences made, scope limits Core capabilities Verbatim clause citations. Every finding is tied to a section reference and a word-for-word quote. The skill never paraphrases or invents contract text.
Drop-in replacement language. Every Critical and High finding includes a pasteable redline. Not an instruction to draft — the actual clause text.
Deterministic recommendation. SIGN AS-IS, SIGN WITH AMENDMENTS, NEGOTIATE THEN SIGN, or DO NOT SIGN — derived mechanically from severity scores and walk-away status, not from vibes.
Regulated-data escalation. PHI, financial records, children's data, and government data trigger a mandatory counsel-review flag regardless of other scores.
Configurable playbook. On first run, the skill offers to save your standing positions to contractguard-playbook.md. Every subsequent review inherits your liability caps, required carve-outs, banned clauses, and preferred governing law.
Side-aware. Works for buyers reviewing vendor paper and sellers reviewing customer paper. Infers side if unstated and discloses the inference.
Severity-tiered output. Not every finding deserves the same depth. Criticals get the full eight-field ladder. Highs get a compressed format that still preserves the redline. Mediums get one line. Acceptable clauses are suppressed entirely.
What it is not ContractGuard is not a lawyer and does not give legal advice. It is a triage and negotiation-preparation instrument. It says so in every output, and it routes genuinely legal questions to qualified counsel in a dedicated section. Critical findings carry an explicit escalation flag.
Who this is for Procurement and vendor management teams who need a first-pass risk read before legal gets involved
In-house counsel at lean legal departments who need to triage inbound paper faster
Founders and operators at companies without dedicated legal who are about to sign a material vendor agreement
Agencies and consultancies reviewing customer paper before accepting a deal
Legal ops professionals who want a consistent, documented review standard across the organisation
Technical details Format: SKILL.md following the Agent Skills open standard
Compatible with: Claude Code, and any agent that supports the SKILL.md standard
Dependencies: None. No external APIs, no MCP servers, no network calls required.
Tools used: Read, Write, Glob, Grep (for the optional playbook feature)
Language: English (non-English contracts require translation before review)
Output: Markdown brief, ready to paste into a document, email, or redline tool
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 5 days ago
- Passed all security checks, Safe to install