Loading...
Loading...
Fast "is this a problem?" answer for the quick Slack question — pattern-matches against your calibration. Use when the user says "is this a problem", "quick question", "can we do X", "do I need legal review for", "sanity check", or pastes a PM's question that needs a same-minute fine / needs a look / hold call.
npx skill4agent add anthropics/claude-for-legal is-this-a-problem~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md/product-legal:is-this-a-problem "Can we use customer logos on the pricing page?"## Matter workspacesEnabled✗/product-legal:matter-workspace switch <slug>practice-levelmatter.md~/.claude/plugins/config/claude-for-legal/product-legal/matters/<matter-slug>/Cross-matter contexton## Shared guardrails → Destination check~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md## Risk calibration| Question sounds like | Why it might not be simple | Catch it by asking |
|---|---|---|
| "Can we add [vendor] to the integration?" | Vendor touches a new data category — flag as potentially implicating privacy and vendor-risk regimes and route for research | "What data flows to them?" |
| "Can we A/B test the pricing page?" | Differential pricing by segment can implicate consumer-protection and anti-discrimination regimes — flag and route for research | "Are both arms seeing the same price for the same thing? How are users assigned to arms?" |
| "Can we auto-enroll users in the new feature?" | Default-on behavior for users who previously opted out can implicate consent and consumer-protection rules — flag and route for research | "Does this respect existing preferences?" |
| "Can we use customer logos on the site?" | Logo use is a separate permission from the contract relationship — flag as potentially implicating publicity / endorsement rules and the customer's own contract terms | "What does the contract say about publicity? Do we have written permission?" |
| "Can we train on this data?" | Usage rights for the original collection purpose may not extend to training — flag and research the notice/consent the users were given at collection | "What did we tell users when we collected it? What jurisdictions are the users in?" |
| "It's just an internal tool" | Internal tools still process personal data — flag as potentially implicating privacy regimes and route for research | "Whose data does it touch? Employees, customers, third parties?" |
| "We already do something similar" | "Similar" is doing a lot of work — the delta is where the issue usually is | "Similar how? What's actually different?" |
| "Can we use [AI vendor / LLM] for this?" | Vendor AI terms may permit training on inputs; use case may need an AIA — flag and route to | "Is there an AI addendum? What data goes into the model?" |
| "Can we add AI to this feature?" | May be a new use case not in the registry; may trigger AIA requirement — flag and route to | "What does the AI do — assistive or automated? Who does it act on?" |
| "The model just decides automatically" | Automated decision-making without human review is regulated in some jurisdictions — flag and research the applicable rules for the affected users' jurisdictions | "Who's affected? Is there a human in the loop? Where are the affected users?" |
| "It's AI-generated content" | Output IP and disclosure duties vary by jurisdiction and vendor terms — flag and route for research | "What's the content type? Does the vendor's ToS address output ownership? Who is the audience?" |
| "We're just fine-tuning on our data" | Training data rights, output IP, and vendor obligations all change — flag and route to | "What's in the training data? Is any of it customer or employee data?" |
~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md## Outputs## Who's using this[WORK-PRODUCT HEADER — per plugin config ## Outputs][✅ Fine | ⚠️ Needs a look | 🛑 Hold]
[One sentence: the call and why.]
[If ⚠️: what the look involves, how long]
[If 🛑: who to talk to, when]✅ Fine — adding an analytics event is an FYI here as long as it's covered by
the existing privacy policy categories. This one is.⚠️ Needs a PIA — new data collection for [category]. Usually takes a day.
Want me to kick it off?🛑 Hold — "train on customer data" triggers a bunch of things. What did the
customer agreement say about data use? Let's pull it before anyone promises
this to the customer.⚠️ Needs an AI governance triage — adding an LLM to this workflow means we need
to check the use case against the registry and confirm an AIA is done before it
ships. Takes a day. Want me to run `/ai-governance-legal:use-case-triage` now?## Outputs