ai-legal-claude: fourteen legal document skills wired into Claude Code
AI Legal Assistant skill for Claude Code. Contract review, risk analysis, NDA generation, compliance auditing, negotiation strategy, and PDF reports — 14 skills, 5 parallel agents. If you want to learn how to sell this to real businesses, check out the Skool community
At a glance
- What is it?
- A prompt-only toolkit that turns contract review, document generation and compliance checking into slash commands, with five subagents fanning out per review.
- Who is it for?
- What makes this repository interesting is that it contains almost no software. It is a directory of skill definitions and agent prompts, which means the whole tool is inspectable text you can read before installing and edit afterwards if the review misses something you care about.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Activity is slowing. The repository last received commits 6 months ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 9, 2026, and from our analysis. They are not legal advice.
Editorial analysis
A prompt library dressed as a tool
The repository is named ai-legal-claude and it is not an application. There is no server, no API and no model of its own. What ships is a set of skill definitions, five agent prompts and one Python script, and the entire mechanism is that Claude Code discovers them and exposes them as slash commands.
That makes the security question unusually tractable. There is no binary to trust and no service to call, only text files. Reading them before you install costs you a few minutes and tells you exactly what gets written into your Claude Code configuration and how the analysis is structured.
The GitHub language field reports Python, which is technically right and practically misleading. The only Python in the tree is `generate_sample_contract.py` at the root, which generates the `sample-contract.pdf` sitting next to it, plus `scripts/generate_legal_pdf.py` for reports. Everything that does the actual work is markdown. Judge the project on the prompts, not on the language badge.
One command installs everything
The quick start is a single line, and the README is upfront that it is a pipe to bash:
curl -fsSL https://raw.githubusercontent.com/zubair-trabzada/ai-legal-claude/main/install.sh | bashThat installs all fourteen skills, the five agents and the PDF generation scripts at once. The removal path is symmetrical, with a matching uninstall script:
curl -fsSL https://raw.githubusercontent.com/zubair-trabzada/ai-legal-claude/main/uninstall.sh | bashRunning either script from a local checkout is also supported, so if you prefer to read the shell before executing it, cloning first and running `./uninstall.sh` afterwards is the shape the README documents.
Requirements are modest because there is not much to require. Claude Code with an active Anthropic API key is the real dependency. Python 3.8 or newer is needed only for PDF generation, and even then the only third-party package is reportlab, installed separately with pip.
Fourteen commands split across three jobs
The command surface divides into three families, and the division is sensible rather than arbitrary.
Analysis commands take a document and read it: review is the flagship, risks does clause-level scoring with estimated financial exposure, compare diffs two versions and flags additions and removals, plain translates the legalese, negotiate produces replacement language for unfavorable clauses, and missing hunts for protections that should be present and are not.
Generation commands produce documents: nda writes a mutual, one-way, employee or vendor NDA, terms generates terms of service from a URL, privacy generates a privacy policy by scanning what a site actually collects, agreement covers freelancer contracts, partnerships, statements of work and master agreements, and freelancer reviews from the contractor's side with an eye for common traps.
Compliance and reporting close the set: compliance takes a URL and reports gaps against GDPR, CCPA, ADA, PCI-DSS, CAN-SPAM and SOC 2, and report-pdf renders the findings as a PDF with score gauges and risk charts.
The commands that take a URL rather than a file are the unusual ones. `terms` and `privacy` are described as generating documents based on what the website actually does, which implies the skill fetches and reads the site first rather than prompting you to describe it. That is a genuinely useful shortcut and also the one to think about carefully, since it means the tool is making requests to sites you name.
Five parallel agents and a weighted score
The flagship review is the part with an actual design. Running it launches five agents in parallel, each with a stated role and a weight:
| Agent | Role | Weight | |-------|------|--------| | Clause Analyst | Identifies and categorizes every clause | 20% | | Risk Assessor | Scores each clause for risk | 25% | | Compliance Checker | Flags regulatory issues | 20% | | Terms Mapper | Maps obligations, deadlines, and triggers | 15% | | Recommendations Engine | Generates specific fixes | 20% |
The weights are published, which is more than most projects of this kind do. It tells you that the risk assessor has the largest single say and the terms mapper the smallest, so if the output seems to overweight risk scoring rather than obligations tracking, that is the design talking rather than a bug.
The aggregated result has eight parts: a Contract Safety Score from 0 to 100 with a letter grade, a risk dashboard counting high, medium and low clauses, clause-by-clause analysis in plain English with specific fixes, missing protections, an obligations timeline, compliance flags, ranked negotiation priorities, and a next steps checklist. The usage is just the slash command with a file path:
/legal review my-contract.pdfThe parallel fan-out is worth understanding as a latency and coverage trade. Five agents reading the same document can catch things a single pass misses, at the cost of five times the tokens and the usual risk of agents disagreeing. The weighted aggregation is the mechanism that reconciles them.
Two directory names for what looks like one thing
The README documents a project structure with a `legal/` directory containing one subdirectory per skill, each holding a SKILL.md file. Alongside it sit `agents/` with the five agent prompt files, `scripts/` with the PDF generator, `templates/` with a contract review report template, and the two shell scripts.
The repository tree shows those names and adds one the README's listing does not mention: there is a `skills/` directory at the top level alongside `legal/`. Two directories that appear to hold skill definitions is either a migration in progress, a build artifact that got committed, or a staging area the installer copies from.
There is no way to settle that from the listing alone, and the honest guidance is the same either way: read both before installing. If your Claude Code configuration ends up with duplicate skill definitions after running the installer, that duplication is the likely reason.
The assets directory holds the banner image the README renders at the top. The sample contract and its generator script are a genuinely good idea in a project like this, because they let you try a full review without handing a real document to anything.
No license, a stale push, and a community homepage
Three signals deserve flagging before anyone builds on this.
First, licensing. GitHub reports no license for the repository, and there is no LICENSE file in the tree. The README's footer links to a license file in another repository instead. Without an explicit grant, the default copyright position applies, which means you can read the prompts but have no stated permission to copy, modify or redistribute them. That is a real limitation for a project whose entire value is in its text, and it is easy to overlook.
Second, activity. The last push was 2026-03-27, a little over six months before this article was written, and the repository is not archived with six open issues. A project installed by piping a script into your shell is one you would rather see receive updates, since the installer is what changes when the Claude Code plugin format moves.
Third, the homepage. The repository's homepage field points at a paid community site rather than documentation. Combined with the README's framing around selling the capability as a service, that tells you where the author's interest is. It does not tell you anything about the quality of the fourteen SKILL.md files, which are the part you can judge directly.
The disclaimer at the bottom is the right frame for all of it. The tool is for educational and informational purposes, does not provide legal advice, and is not a substitute for a licensed attorney.
Editorial conclusion
What makes this repository interesting is that it contains almost no software. It is a directory of skill definitions and agent prompts, which means the whole tool is inspectable text you can read before installing and edit afterwards if the review misses something you care about. The five-agent split for the flagship review command is a sensible way to make a single pass feel thorough, and the weighted aggregation is explicit about which opinions dominate the score. What it cannot be is a replacement for a lawyer, which the README states in a disclaimer more clearly than the marketing above it suggests. Read the SKILL.md files before you pipe a real contract through it, check what the installer writes into your Claude configuration, and treat the contract safety score as a triage aid rather than an opinion you can act on.
Frequently asked questions
What does installing ai-legal-claude actually do to my machine?
It copies skill definitions, five agent prompt files, a report template and one Python script into your Claude Code setup, and prints a single command from install.sh. There is no daemon and no service; the work happens through your existing Claude Code session and Anthropic API key.
How many agents run during a contract review and how is the score decided?
Five agents run in parallel: a clause analyst, a risk assessor, a compliance checker, a terms mapper and a recommendations engine. Each carries a published weight, 25 percent for the risk assessor down to 15 percent for the terms mapper, and their results are aggregated into a single Contract Safety Score out of 100.
Can this generate a privacy policy or terms of service for my site?
Yes, both take a URL rather than a document. The README describes them as generating terms of service based on what the website actually does, and a privacy policy by scanning what data the site collects, which means the skill fetches and reads the site you name before drafting.
Is it safe to pipe the installer command straight into bash?
The install and uninstall commands are shell scripts fetched over the network and executed immediately. Because the repository ships only text definitions and one Python script rather than a binary, you can clone it and read install.sh before running anything, and the README documents running ./uninstall.sh locally.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/zubair-trabzada-ai-legal-claude)