From grimoire
Systematically reviews SaaS vendor or customer contracts for legal, commercial, and operational risk. Covers SLA uptime, data ownership, DPAs, liability caps, IP indemnification, and termination provisions.
How this skill is triggered — by the user, by Claude, or both
Slash command
/grimoire:review-saas-contractThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Systematically review a SaaS agreement to identify legal, commercial, and operational risks before signing.
Systematically review a SaaS agreement to identify legal, commercial, and operational risks before signing.
Adopted by: ABA Technology Law Committee, Gartner IT legal risk frameworks, enterprise procurement legal teams globally Impact: IACCM research shows 9% of contract value is lost to poorly negotiated terms; SaaS contracts introduce unique risks (data ownership, SLA credits, vendor lock-in) absent in traditional software licenses that require specialized review checklists.
Why best: SaaS contracts transfer operational dependency to a third party. Unlike on-premise software, the customer cannot access the underlying code if the vendor fails. Contract terms around data portability, SLA remedies, security obligations, and limitation of liability directly determine business continuity risk and legal exposure.
Red flag found in review: Vendor contract states "Company may use aggregated and anonymized Customer Data to improve its products and services." Risk: aggregated/anonymized data derived from customer data could reconstitute sensitive business information. Negotiation: revise to "Vendor may use only fully anonymized, non-customer-identifiable telemetry data, subject to customer opt-out, and shall not share such data with third parties."
Law disclaimer: This skill encodes professional best practices for educational purposes. It is not legal advice. Consult a licensed attorney before making legal decisions.
npx claudepluginhub jeffreytse/grimoire --plugin grimoireReviews SaaS subscription agreements focusing on auto-renewal mechanics, price escalation, data portability, uptime SLAs, and subprocessor rights.
Reviews contracts against organization's negotiation playbook, flags deviations with severity, generates redline suggestions for vendor contracts, customer agreements, or commercial deals.
Audits contracts against type-specific protection checklists to identify gaps, rates urgency, and provides ready-to-insert clause language. Trigger with /missing-protections for absent protections.