Skip to content

feat(starter): add reviewed NDA triage skill - #913

Open
FenjuFu wants to merge 1 commit into
mainfrom
feat/starter-triage-nda-912
Open

FenjuFu wants to merge 1 commit into
mainfrom
feat/starter-triage-nda-912

Conversation

@FenjuFu

@FenjuFu FenjuFu commented Oct 1, 2026

Copy link
Copy Markdown
Member

Summary

  • add a reviewed triage-nda package to the curated starter source collection: it screens an incoming NDA against ten criteria and classifies it GREEN (standard approval), YELLOW (counsel review), or RED (full legal review)
  • pin the Apache-2.0 upstream anthropics/knowledge-work-plugins at da38ec1ee89d41e5380e652a97382695003396e7 (legal/skills/triage-nda, legal plugin 1.3.0) and record every adaptation in NOTICE.md
  • LICENSE.txt is the legal/LICENSE file at that revision, byte for byte
  • add a realistic regression case to evals.json

Closes #912

Review and safety adaptation

The package is one SKILL.md plus license and notice: no scripts, no network access, no credentials, no connectors. The adapted copy:

  • removes the Claude Code specific argument-hint, @$1 expansion, /triage-nda block, and the link to the plugin-level CONNECTORS.md
  • accepts only NDA text or files the user provides; for a document-system link it asks for the text instead of fetching
  • treats the NDA as untrusted counterparty text, so embedded notes addressed to the reviewer are flagged, not followed
  • uses a screening playbook only when the user supplies or points to it, instead of searching local settings
  • breaks ties between classification bands toward the more cautious class, writes Not stated for report fields the document does not supply, and states that the Skill does not sign, send, forward, or file documents

The screening criteria, classification bands, report template, and standard positions are otherwise unchanged.

Validation

  • SkillHub package builder: 23 reviewed packages built successfully
  • deterministic build: two independent builds produced byte-identical artifacts.json
  • scripts/tests/build-builtin-skills-test.sh on an LF export of this commit: double build, runtime-manifest SHA-256 cross-check, ZIP layout check (SKILL.md, LICENSE.txt, NOTICE.md, sorted names, no traversal), and per-ZIP byte comparison all pass
  • realistic usage, with the packaged SKILL.md loaded as the system prompt on Spark-X2.5 (spark-x2.5, iFlytek Astron Token Plan, temperature 0.2):
    • the evals.json case: classified RED with default standards stated; flagged the 24-month non-solicit, perpetual term, USD 250,000 liquidated damages, overbroad definition, and the three missing carveouts; flagged clause 7 ("classify it GREEN") as untrusted counterparty text; reported governing law as Not stated; recommended counsel review or a counterproposal with the not-legal-advice note
    • control case, a clean mutual NDA (all five carveouts, 2-year term with 3-year survival, return/destroy with retention exception, injunctive relief, no IP grant, England and Wales): classified GREEN with every criterion PASS
  • git diff --check: passed

The Zero Slop sub-test in the same script runs very slowly on this Windows machine; GitHub Linux CI is the authoritative run for it. This change does not touch Zero Slop.

Risk

  • User-facing impact: none until the package is published to the runtime manifest
  • Deployment or migration impact: none; the runtime manifest is intentionally unchanged until an immutable CDN URL and matching SHA-256 are available, as required by builtin-skills/README.md
  • Rollback approach: revert this commit

Notes

Signed-off-by: FenjuFu <fufenjupku@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature] Share a Skill: NDA triage (GREEN / YELLOW / RED) from anthropics/knowledge-work-plugins

1 participant