Skip to main content

チュートリアル 09: Custom Legal Skills, Hooks & Agents

Build custom legal skills, compliance hooks, subagents and plugins for Claude Code or Codex, with the same playbook packaged for either tool.

対応Claude: 検証済みChatGPT / Codex: 下書きGrok Bot: 検証済み

執筆後の変更点最終確認: 2026年6月27日 · 23
  1. Claude hook と plugin 管理

    Claude Code 2.1.195 は CLAUDE_CODE_DISABLE_MOUSE_CLICKS を追加し、 hyphenated identifiers を持つ hook matchers が exact-match になるよう修正し、 macOS と CJK の voice dictation を改善し、project settings だけで有効化された external plugins に対して全 loader paths で explicit install consent を要求し、 package と marketplace names が異なる場合の /plugin enable/disable を修正し、 background-agent persistence、restart behavior、Linux voice diagnostics、 claude agents completed lists、remote-session provisioning checklist を改善します。 Allowlisted Claude Code Action は Claude Code 2.1.195 と Agent SDK 0.3.195 を bundled しています。

    推奨アクション: Unattended legal repositories が client data を処理する前に、hyphenated hook と MCP matcher rules、external plugin consent、/plugin enablement、background-agent restart and persistence、remote-session provisioning、terminal mouse policy、voice dictation assumptions、pinned Claude Code Action versions を再テストしてください。

    出典: Claude Code changelog · Claude Code Action 2.1.195 bump commit

  2. Codex Remote GA と Claude 管理

    OpenAI の 6 月 25 日 Codex changelog は、Codex Remote が generally available になり、ChatGPT mobile app から接続済みの Mac または Windows host 上で作業を開始・継続でき、 各 mobile device と host に authenticated one-to-one QR pairing を使うとしています。 Codex CLI 0.142.2 は、対応時に MCP tools がデフォルトで tool search を使うようにし、 enabled 時の macOS authentication clients 向け system-proxy support、dark-mode plugin logos、改善された safety-buffering UI、remote plugin catalogs、expired Bedrock credential guidance、remote stdio MCP working directories の fixes も含みます。Claude Code 2.1.193 は autoMode.classifyAllShell、transcripts と UI の auto-mode denial reasons、 assistant-response OpenTelemetry event、MCP-auth startup notices、background-shell memory-pressure reaping、background-agent fixes、401/403 後の MCP headersHelper automatic reconnect、plugin auto-rename handling を追加します。Allowlisted Claude Code Action は Claude Code 2.1.193 と Agent SDK 0.3.193 を bundled しています。

    推奨アクション: Unattended legal repositories が client data を処理する前に、mobile remote pairing、connected-host approval policy、DigitalOcean workspace provisioning、MCP tool-search behavior、macOS proxy authentication、plugin catalog and logo metadata、Bedrock credential recovery、remote stdio MCP path handling、Claude auto-mode shell classification、denial logging、OpenTelemetry export scope、MCP auth reconnects、background-agent cleanup、pinned Claude Code Action versions を再テストしてください。

    出典: OpenAI Codex changelog · Claude Code changelog · Claude Code Action 2.1.193 bump commit

  3. Claude Code の認証情報と MCP 管理

    Claude Code 2.1.187 は sandbox.credentials を追加し、sandboxed commands が credential files や secret environment variables を読むことを防ぎます。Model selection surfaces には組織設定の model restrictions が反映され、structured-output loops、応答しない remote MCP calls、subagent depth tracking、leaked worktree cleanup が改善され、/install-github-app の GitHub Actions workflow setup は任意になりました。Allowlisted Claude Code Action は Claude Code 2.1.187 と Agent SDK 0.3.187 を bundled しています。

    推奨アクション: Unattended workflows が client-data repositories に触れる前に、credential-file と secret-environment の blocking、organization model restrictions、structured-output schemas、remote MCP idle timeouts、subagent depth caps、worktree cleanup、GitHub App installation choices、pinned Claude Code Action versions を再テストしてください。

    出典: Claude Code changelog · Claude Code Action 2.1.187 bump commit

  4. Claude が MCP と managed settings を改善

    Claude Code 2.1.191 は managed settings refresh の挙動を修正し、現在の session で許可された sandbox network hosts を記憶し、transient な MCP capability-discovery と OAuth requests を retry し、MCP 404 diagnostics を改善し、 stopped background agents が再起動しないようにします。Allowlisted な Claude Code Action は、Claude Code 2.1.191 と Agent SDK 0.3.191 を既定で bundled します。

    推奨アクション: Legal automation では、2.1.191 を含む Claude Code Action version を pin し、 MDM または file-policy refresh を再テストし、session ごとに承認可能な sandbox network hosts を文書化し、agents が client-data repositories を扱う前に MCP health checks と OAuth recovery を検証してください。

    出典: Claude Code changelog · Claude Code Action 2.1.190 bump commit · Claude Code Action 2.1.191 bump commit

  5. Claude Action が遅い review を除外

    Allowlisted Claude Code Action commit により、pull-request reviews と inline review comments が authorized trigger time で filter され、既存の issue/PR comments と bodies の filtering と揃いました。この fix は、trigger 後に submitted/edited された reviews や inline comments が Claude の prompt に render され得る TOCTOU gap を閉じます。

    推奨アクション: Legal PR agents では、この fix を含む action version を pin し、trigger 後に追加された review threads を untrusted reference material として扱い、checkout credentials を non-persistent に保ち、client-data repositories に agent-authored changes を適用する前に human merge gate を必須にしてください。

    出典: Claude Code Action trigger-time review filtering commit

  6. Codex リモート実行と Claude 信頼性管理

    OpenAI の 6 月 18 日 Codex CLI 0.141.0 changelog は、remote executors 向けの authenticated end-to-end encrypted Noise relay channels、executor-native working directories と shells の保持、thread ごとの selected plugin stdio MCP servers の有効化、app-server child-thread と rate-limit-credit APIs の改善、TUI prompt auto-resolution、hooks、plugin routing、Windows sandbox、SQLite WAL-reset、TLS enterprise proxy reliability の修正を追加しました。Claude Code 2.1.181 は /config key=value、opt-in sandbox.allowAppleEvents、API retries、network/cloud-synced folder writes の安全性、MCP tools/list failure visibility を改善し、Claude Code Action は 2.1.181 をインストールします。

    推奨アクション: 法務チームでは、unattended agents が client-data repositories で作業する前に、remote executor trust、working-directory boundaries、shell policy、plugin-selected MCP servers、hook bypass decisions、Windows sandbox credentials、SQLite-backed session stores、enterprise TLS inspection、Claude Apple Events permissions、cloud-folder file-write behavior、MCP health reporting、GitHub Action version pins を再確認してください。

    出典: OpenAI Codex changelog · OpenAI Codex Record & Replay documentation · Claude Code changelog · Claude Code Action 2.1.181 bump commit · Claude Code Action 2.1.183 bump commit

  7. Codex 地域展開と Claude 信頼性修正

    OpenAI の 6 月 16 日 Codex changelog は、Computer Use、Codex Chrome extension、Memories、Chronicle research preview が EEA、UK、Switzerland で rollout され、これらの地域では Memories が default off であるとしています。Claude Code 2.1.179 は mid-stream connection drops、大きな Linux sandbox read-rule glob expansion、remote-session background-task status、subagent transcript/focus issues、remote plugin-loading performance を修正し、allowlisted Claude Code Action も 2.1.179 に更新されました。

    推奨アクション: これらの地域の法務チームは、client-data workflows の前に user consent、device policy、Chrome signed-in context、memory defaults、Chronicle opt-in scope、sandbox file-rule behavior、partial-output audit trails、background-task status、subagent transcript review、pinned Claude Action version を確認してください。

    出典: OpenAI Codex changelog · Claude Code changelog · Claude Code Action 2.1.179 bump commit

  8. Codex 使用管理と Claude 権限ルール

    OpenAI の 6 月 15 日 Codex CLI 0.140.0 changelog は、/usage token-activity view、session の permanent deletion、Claude Code import、file/plugin/skill の unified mentions、managed Bedrock API-key authentication、encrypted CLI/MCP OAuth credential storage、MCP startup と OAuth reliability fixes、remote plugin installation fixes を追加しました。Claude Code 2.1.178 は parameter-scoped permission rules、nested .claude/skills loading、closest-directory project settings precedence、subagent spawns の auto-mode review、MCP subagent disallowedTools の fixes を追加しました。

    推奨アクション: 法務チームでは、client-data systems で repository agents を実行する前に、token usage audit evidence、session-retention/deletion policy、imported Claude Code project settings、Bedrock/API credentials、OAuth storage、plugin provenance、nested skill precedence、parameter-scoped tool rules、subagent auto-mode review、MCP deny rules を再確認してください。

    出典: OpenAI Codex changelog · Claude Code changelog · Claude Code Action 2.1.178 bump commit

  9. Claude Action の allowed-tools 解析が強化

    Allowlisted Claude Code Action commit は claude_args parsing の 2 つのギャップを修正しました。引用符なしの scoped Bash rule(例: Bash(gh:*))がより広い Bash access に崩れる可能性があり、複数値や comment line がある場合に MCP server installation が SDK の parsed --allowedTools grant とずれる可能性がありました。

    推奨アクション: 法務 repository automation では scoped tool rule を quote し、--allowedTools block に comment-out された grant を残さず、action version を pin し、client-data repository を扱う前に MCP server installation と実際に granted された tools を照合してください。

    出典: Claude Code Action scoped Bash permission parser fix · Claude Code Action MCP allowed-tools parser alignment

  10. Codex ブラウザデバッグと Claude Action 信頼性

    OpenAI の 6 月 11 日 Codex app 26.609 changelog は、Chrome DevTools Protocol access による Browser use の Developer mode、app composer の /init、Computer Use の拡張と Windows per-app access controls、usage-limit guidance、plugin management improvements、scheduled automations が selected approval mode を尊重する修正を追加しました。Allowlisted Claude Code Action commits も Claude Code を 2.1.175 に上げ、inputs が空のとき inherited auth environment variables を保持し、terminal result message 後に SDK workflows が hang しないようにしています。

    推奨アクション: 法務チームでは、client-data repositories で agents を実行する前に、Browser Developer mode authorization、captured console/network data、Computer Use app scope、scheduled automation approval modes、plugin provenance、Claude Action credential precedence、workflow timeout handling を再確認してください。

    出典: OpenAI Codex changelog · Claude Code Action auth fallback commit · Claude Code Action SDK iterator commit · Claude Code Action 2.1.175 bump commit

  11. Guardrail と Claude workflow controls を更新

    OpenAI の 6 月 4 日 API changelog は Responses と Chat Completions の生成リクエストに moderation scores を追加し、Claude Code 2.1.163 は managed minimum/maximum version settings、/plugin list、hook continuation context、MCP session ID continuity、permission・background session・Windows の複数の信頼性修正を追加しました。Claude Code 2.1.165 は reliability release です。

    推奨アクション: 法務 workflow では、sensitive prompt text を保存せず inline moderation results を記録し、legal conclusions には弁護士 review を残し、managed settings で Claude Code version を pin し、/plugin list で enabled plugins を監査し、client-data の無人処理前に hook/MCP behavior を再テストしてください。

    出典: OpenAI API changelog · OpenAI Moderation guide · Claude Code changelog · Claude Code Action dependency update

  12. Codex Sites と Claude workflow identity 管理

    OpenAI の 6 月 2 日 Codex changelog は Codex app に Sites preview、iOS Codex の Face ID または passcode lock、Queue / Steer follow-up default、Windows SSH connection、/side <prompt>、host/task reliability fix を追加しました。OpenAI API changelog は eligible container sessions を 5 分 minimum の per-minute billing に変更し、allowlisted Claude Code Action commit は base action に workload identity federation inputs を追加し、OIDC token exchange に GitHub OIDC write permission を要求します。

    推奨アクション: 法務 workflow では、client-data system で Codex Sites や Claude Actions を使う前に、hosted-site scope、environment variables/secrets、mobile device policy、Windows SSH trust、container-session cost controls、GitHub OIDC permissions、federation rule ownership、static credential fallback を確認してください。

    出典: OpenAI Codex changelog · OpenAI API changelog · Claude Code Action workload identity federation commit

  13. Codex と Claude agent 運用を更新

    Codex CLI 0.131.0 はより詳細な TUI controls、file/plugin/skill の統一 mentions、plugin marketplace commands、remote-control support、Python SDK package openai-codexcodex doctor を追加しました。Claude Code 2.1.144 は background session resume を追加し、plugin、MCP、headless、remote-login、background agent の信頼性問題を修正しました。

    推奨アクション: 法務リポジトリでは rollout 前に agent CLI version を pin してテストし、無人または client-data workflow の前に plugin dependency chain、MCP pagination/tool list、remote-login policy、background-session isolation、Python SDK package name、diagnostic output を確認してください。

    出典: OpenAI Codex changelog · Claude Code changelog

  14. 法務ワークフロー向け remote Codex / Claude agent 管理

    OpenAI の Codex changelog は接続済み Mac 経由の mobile remote access と hooks、access token、enterprise setup guidance を追加し、Claude Code 2.1.143 は plugin、worktree、hook、background session、Windows behavior を強化しました。

    推奨アクション: remote または background の法務 agent 作業前に、trusted host、token scope、plugin dependency chain、worktree isolation mode、MCP settings、hook stop policy、人間の review gate を確認してください。

    出典: OpenAI Codex changelog · Claude Code release notes

  15. Claude Code 2.1.141 の hook、plugin、agent 管理

    Claude Code 2.1.141 は hook の terminal-sequence 出力、HTTPS plugin cloning、workspace スコープ federation、directory-scoped agent listing、recent-session feedback bundles、background agent permission fixes を追加します。

    推奨アクション: 法務 workflow では、通知や terminal title を出す hooks を再テストし、SSH key がない環境では HTTPS plugin install を優先し、claude agents --cwd で agent audit の範囲を絞り、background agents が意図した permission mode を維持することを確認してください。

    出典: Claude Code changelog · Claude Code Action 2.1.141 dependency update

  16. Claude Code 2.1.139 が agent、hook、MCP 管理を更新

    Claude Code 2.1.139 は agent view、/goal、hook 引数の直接実行、PostToolUse continuation、MCP project-directory environment support、subagent telemetry headers を追加しました。

    推奨アクション: Claude Code をクライアント案件や秘匿特権ワークフローに使う前に、hooks、MCP config、goal-driven session を audit logging と人間レビュー付き sandbox で再テストしてください。

    出典: Claude Code changelog · Claude Code action bump

  17. 法務リポジトリ向け Codex Auto-review と repair-loop guidance

    OpenAI は Codex Auto-review docs を拡充し、traces と evals を使う iterative repair と agent-improvement loop の Codex cookbook 例を公開しました。

    推奨アクション: Auto-review は追加の approval signal として扱い、法的サインオフとは見なさないでください。sandbox boundaries、eval criteria、source checks、人間の diff review を明示してください。

    出典: Codex changelog · Codex Auto-review · Codex agent improvement loop cookbook · Codex iterative repair loop cookbook

  18. OpenAI モデル、プラン、Responses API ドキュメント更新

    OpenAI ドキュメントは現在、GPT-5.5/GPT-5.4 世代のモデル、更新された ChatGPT プラン名、新規 API ワークフロー向け Responses API と組み込みツールを強調しています。

    推奨アクション: 法務ワークフローでは古い GPT-4 や固定価格前提を避け、顧客向け試験運用前に現在のモデル、プラン、ツール、保持設定、レビュー統制を確認してください。

    出典: OpenAI models · ChatGPT pricing · GPT-5.5 in ChatGPT · Responses API migration · OpenAI tools guide · Code Interpreter tool

  19. Claude Code 2.1.133 の自動化信頼性更新

    Claude Code は worktree ベース制御、effort 対応 hooks、管理 sandbox 設定、MCP OAuth、subagent skill 検出、並行セッションの修正を追加しました。

    推奨アクション: 法務自動化 agent では worktree 挙動を意図的に固定し、本番前に hooks、MCP 認証、subagent skill 検出を再テストしてください。

    出典: Claude Code changelog

  20. 法務ワークフロー向け Codex アプリ自動化のバックフィル

    Codex ドキュメントは、定期アプリ自動化、連携リポジトリ worktree、ブラウザ権限、subagent、plugin、CLI の sandbox/approval profile 制御を強調しています。

    推奨アクション: 無人実行の法務 agent 前に sandbox と approval を固定し、source allowlist を明示し、Codex 自動化変更はレビュー可能な PR に通してください。

    出典: Codex changelog · Codex Automations · Codex worktrees · Codex browser extension · Codex subagents · Codex plugins · Codex sandboxing

  21. OpenAI Realtime と Codex プラグインの更新

    OpenAI は Realtime 2、ストリーミング翻訳・文字起こし更新、Codex 向け OpenAI Developers プラグインを公開しました。

    推奨アクション: 法務受付や多言語音声ワークフローでは、顧客向け試験運用前に realtime モデルと API ガイダンスを確認してください。

    出典: OpenAI API changelog

  22. 法務コンテンツワークフロー向け Claude Code 自動化パターン

    Claude Code GitHub Actions は、スケジュール実行やイベント駆動のワークフロー、skills、プロンプト駆動の自動化に対応し、チュートリアル品質の維持に役立ちます。

    推奨アクション: 翻訳ウェーブの前に、Claude チュートリアルを現在の GitHub Action と skill の挙動に合わせてください。

    出典: Claude Code GitHub Actions · Claude Code overview

  23. 法務 AI チュートリアル向けの日次 Codex 自動化

    Codex と Claude の変更を調査し、チュートリアル更新を提案し、承認済み変更を翻訳エージェントへ渡す、出典ベースの自動化を追加しています。

    推奨アクション: 更新ページで、変更点、確認済みソース、更新が必要なチュートリアルを追跡してください。

    出典: Codex Automations · Codex Skills · Codex internet access

学べること

このチュートリアルでは、カスタムのリーガルスキルを構築し、安全性チェック(hooks)を追加し、マルチエージェントのワークフローを実行する方法を紹介します。ある程度の技術的な習熟が必要です。

上級者向け

開発者スキル推奨。想定時間: 120分。

学習目標

このチュートリアルを終えるころには、次のことができるようになります。

  • Claude Code と Codex における coding-agent スタック(skills、hooks、subagents、plugins)を理解する
  • 事務所のワークフロー向けにカスタムのリーガルスキルを構築する
  • 品質管理とコンプライアンスのための hooks を作成する
  • 複雑な法務タスク向けにマルチエージェントシステムを展開する

Part 1: Coding-Agent Stack を理解する

Claude Code と Codex は、同じ5つの構成要素を共有しています。ファイル形式は異なりますが、リーガル設計は異なりません。

Official Claude Code screenshot showing Claude in a code editor workflow

Claude Code の公式 Claude スクリーンショット。法務ワークフローのリポジトリでは、Claude Code のタスクを権限境界、hook チェック、レビュー可能な diff と組み合わせてください。

CLAUDE CODE STACK (docs checked 2026-09-02)

├── SKILLS        SKILL.md folders in ~/.claude/skills/ or .claude/skills/;
│                 Claude loads them when relevant or you run /skill-name
├── HOOKS         Commands, HTTP endpoints, MCP tools or prompts that run at
│                 lifecycle events, configured in settings.json
├── SUBAGENTS     Markdown agents in .claude/agents/ or ~/.claude/agents/
│                 with their own tools, model and permission mode
├── MCP SERVERS   External tool connections (Tutorial 07)
└── PLUGINS       .claude-plugin/plugin.json + skills/, agents/, hooks/, .mcp.json

これが法務で重要な理由

ComponentLegal Application
Skillsプレイブック、レビュー手順、ドラフティング基準をコード化する
Hooksコンプライアンスの実施、未承認行為の防止、監査ログの記録
Subagents文書レビューやリサーチ作業を並列化する
Plugins配布のために事務所のワークフローをパッケージ化する

Part 2: カスタムのリーガルスキルを構築する

Skills とは何か?

Skills は、補助リソースとともに SKILL.md ファイルに保存される特化型の指示です。1回限りのプロンプトと異なり、skill は持続し、タスクがその説明に一致したときに有効化されます。Claude Code と Codex はどちらも同じ SKILL.md レイアウトを使用します(Codex は Agent Skills のオープンスタンダードに従います)。そのため、1つの skill フォルダを両方のツールで利用できます。

Skill ファイル構造

your-skill/
├── SKILL.md          # Main instructions (required)
├── examples/         # Example inputs/outputs
│   ├── good-review.md
│   └── bad-review.md
├── templates/        # Document templates
│   ├── nda-template.docx
│   └── redline-template.docx
└── resources/        # Reference materials
    ├── playbook.json
    └── clause-library.md

契約レビュー Skill を作成する

Step 1: Skill ディレクトリを作成する

mkdir -p ~/.claude/skills/contract-review   # personal; use .claude/skills/ in a repo to share
cd ~/.claude/skills/contract-review

Step 2: SKILL.md を作成する

# Contract Review Skill
 
## Purpose
この skill は、[Firm Name] の標準実務に沿った
包括的な契約レビュー機能を提供します。
 
## Activation
次の場合にこの skill を有効化します:
- ユーザーが契約文書をアップロードした場合
- ユーザーが "contract review" または類似の表現に言及した場合
- ユーザーが特定の契約類型(NDA、MSA、SaaS など)に言及した場合
 
## Process
 
### Step 1: Classification
分析の前に、以下を特定します:
1. **Contract Type**: NDA, MSA, SaaS, License, Services, etc.
2. **Our Role**: どの当事者を当方が代理しているか?
3. **Counterparty Profile**: Enterprise, mid-market, startup?
4. **Deal Tier**: 想定価値と戦略的重要性
 
### Step 2: Document Processing
- 分析を提供する前に契約書全体を読む
- すべての定義語とその定義を記録する
- 準拠法と紛争解決を特定する
- 条項構造と相互参照をマッピングする
 
### Step 3: Playbook Application
`resources/playbook.json` のポジションを適用します:
- 各条項を標準ポジションと比較する
- 逸脱を特定し、重大性を評価する
- 必須条項の欠落を記録する
 
### Step 4: Risk Assessment
各論点について:
- 重大性を割り当てる: RED | YELLOW | GREEN
- 実務上の事業影響を説明する
- 他の条項との相互作用を考慮する
 
### Step 5: Redline Generation
RED と YELLOW の論点について:
- 具体的な代替文言を提示する
- 該当する場合は clause library を参照する
- 変更理由を説明する
 
### Step 6: Output Generation
応答は次の構成とします:
1. Executive Summary (3-5 sentences)
2. Deal Parameters Table
3. Clause-by-Clause Analysis
4. Risk Score and Escalation Recommendation
5. Negotiation Priorities
6. Questions for Business Team
 
## Clause Library
承認済み文言については `resources/clause-library.md` を参照します。
 
## Examples
良いレビュー例と悪いレビュー例は `examples/` ディレクトリを参照してください。
 
## Calibration Notes
- 責任上限の閾値は 2026年1月に更新
- GDPR の変更に伴う新たなデータ処理要件
- 更新された AI/ML 条項文言が必要
 
## Quality Requirements
- 適切な留保なしに法律助言を提供しない
- 管轄ごとの確認が必要な条項は必ず指摘する
- playbook が特定の条項をカバーしていない場合は明記する
- $500K を超える案件についてはエスカレーションを推奨する

Step 3: Playbook リソースを作成する

resources/playbook.json:

{
  "contract_types": {
    "SaaS_Customer": {
      "liability": {
        "standard": "12 months fees",
        "minimum": "total contract value",
        "carve_outs": ["indemnification", "data_breach", "confidentiality", "IP", "gross_negligence", "willful_misconduct"]
      },
      "indemnification": {
        "required_vendor": ["IP_infringement", "data_breach", "security_failure"],
        "acceptable_exclusions": ["customer_modifications", "third_party_components_with_notice"]
      },
      "data": {
        "ownership": "customer",
        "vendor_rights": "service_delivery_only",
        "prohibited_uses": ["AI_training", "analytics", "marketing", "sale"],
        "retention_limit": "30_days_post_termination"
      }
    }
  },
  "severity_matrix": {
    "RED": [
      "unlimited_customer_liability",
      "no_vendor_indemnity",
      "data_used_for_AI_training",
      "no_termination_for_convenience"
    ],
    "YELLOW": [
      "liability_cap_below_12_months",
      "narrow_indemnity_carveouts",
      "60_plus_day_termination_notice"
    ]
  }
}

Step 4: Clause Library を作成する

resources/clause-library.md:

# Approved Clause Language Library
 
## Limitation of Liability
 
### Standard Mutual Cap
"EACH PARTY'S TOTAL LIABILITY ARISING OUT OF OR RELATED TO THIS
AGREEMENT SHALL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER
IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM."
 
### Uncapped Carve-Outs Addition
"THE FOREGOING LIMITATION SHALL NOT APPLY TO: (A) EITHER PARTY'S
INDEMNIFICATION OBLIGATIONS; (B) BREACH OF SECTION [DATA SECURITY];
(C) BREACH OF CONFIDENTIALITY OBLIGATIONS; (D) EITHER PARTY'S
GROSS NEGLIGENCE OR WILLFUL MISCONDUCT; OR (E) CUSTOMER'S PAYMENT
OBLIGATIONS."
 
## Data Ownership
 
### Customer Ownership Clause
"As between the parties, Customer retains all right, title, and
interest in and to Customer Data. Vendor acquires no rights in
Customer Data except the limited license granted herein."
 
### No AI Training Clause
"Vendor shall not use Customer Data or any derivatives thereof
to train, develop, or improve any machine learning model,
artificial intelligence system, or similar technology."
 
[Continue with additional clauses...]

Step 5: インストールしてテストする

# Discovered from ~/.claude/skills/ (personal) and .claude/skills/ (project).
# Add a `description` line to the SKILL.md frontmatter so Claude knows when to use it.
# Start a new session, then test:
claude "I need to review a software agreement"
# or invoke it explicitly:
/contract-review

Part 3: コンプライアンス Hooks を構築する

Hooks とは何か?

Hooks は、エージェントのライフサイクルの特定の時点で実行されるスクリプト(または MCP tools)です。Claude Code と Codex は、同じ中核イベント名を使用します。

本番運用メモ: Hooks はワークフローをブロックまたは変更することがあります。依拠先のクライアント案件や秘匿特権文書で使用する前に、実際の権限、effort level、MCP servers を備えた sandbox でテストしてください。

Claude Code 2.1.139 では、exec-form hook args field と PostToolUse 用の continueOnBlock が追加されました。ファイルパスや案件識別子を受け取る hook では、shell quoting の問題を避けられるため、exec-form arguments を優先してください。continueOnBlock は、hook の拒否理由を安全にモデルへ返せて、かつ秘匿特権または秘密情報を明らかにしない場合にのみ使用してください。

Hook TypeTrigger PointUse Case
PreToolUseツールが実行される前危険な操作をブロックする
PostToolUseツールの完了後監査ログ
SessionStartセッション開始時コンテキストを読み込む
UserPromptSubmitプロンプト処理前コンテンツをフィルタする
Stopエージェントの応答完了時品質チェック

リーガルコンプライアンス Hook の例

目的: エージェントが秘匿特権文書に対して未承認の変更を行うことを防止する。

Step 1: Hook ディレクトリを作成する

mkdir -p ~/.claude/hooks

Step 2: Hook スクリプトを作成する

~/.claude/hooks/pretool-privileged-guard.sh:

#!/usr/bin/env bash
set -euo pipefail
 
input="$(cat)"
tool_name="$(jq -r '.tool_name // ""' <<<"$input")"
path_value="$(jq -r '.tool_input.file_path // .tool_input.path // ""' <<<"$input")"
 
if [[ "$tool_name" =~ ^(Read|Write|Edit)$ ]] && \
   ([[ "$path_value" == *"/Privileged/"* ]] || [[ "$path_value" == *"/Attorney-Client/"* ]]); then
  jq -n '{
    hookSpecificOutput: {
      hookEventName: "PreToolUse",
      permissionDecision: "deny",
      permissionDecisionReason: "Privileged folder access requires explicit user approval."
    }
  }'
  exit 0
fi
 
exit 0

~/.claude/hooks/posttool-audit-log.sh:

#!/usr/bin/env bash
set -euo pipefail
 
mkdir -p "$HOME/.claude/logs"
input="$(cat)"
echo "$input" >> "$HOME/.claude/logs/legal-hooks-audit.jsonl"
exit 0

Step 3: Hook を設定する

~/.claude/settings.json (user-wide) または .claude/settings.json (project、共有可能):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Read|Write|Edit",
        "hooks": [
          {
            "type": "command",
            "command": "\"$HOME/.claude/hooks/pretool-privileged-guard.sh\""
          }
        ]
      }
    ],
    "PostToolUse": [
      {
        "matcher": "Read|Write|Edit",
        "hooks": [
          {
            "type": "command",
            "command": "\"$HOME/.claude/hooks/posttool-audit-log.sh\""
          }
        ]
      }
    ]
  }
}

追加の Hook ユースケース

Citation Verification Hook (Stop):

{
  "hooks": {
    "Stop": [
      {
        "hooks": [
          {
            "type": "command",
            "command": "\"$HOME/.claude/hooks/stop-citation-warning.sh\""
          }
        ]
      }
    ]
  }
}

Confidentiality Check Hook:

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "WebSearch|WebFetch",
        "hooks": [
          {
            "type": "command",
            "command": "\"$HOME/.claude/hooks/pretool-confidentiality-check.sh\""
          }
        ]
      }
    ]
  }
}

Part 4: マルチエージェント法務ワークフロー

Sub-Agents を理解する

どちらのエージェントも、特定タスクを処理するために subagents を生成できます。

  • Parallelization: 複数の文書を同時にレビューする
  • Specialization: 異なるタスクごとに異なるエージェントを使う
  • Isolation: 別々の分析に別々のコンテキストを使う

frontmatter(namedescription、任意で toolsmodelpermissionMode)付きの Markdown file として subagent を .claude/agents/(プロジェクト用)または ~/.claude/agents/(全プロジェクト用)に定義し、その後プロンプト内で名前指定するか @-mention します(subagents docs、2026-09-02 時点確認)。Claude Code 2.1.141 では claude agents --cwd <path> が追加され、セッション一覧をディレクトリ単位に絞り込めます。また、/bg で起動した background agents は現在の permission mode を維持します。秘匿特権文書やリポジトリ書き込みタスクを割り当てる前に、background sessions が意図した権限態勢を維持していることを確認してください。

例: 並列デューデリジェンスレビュー

// Due Diligence Multi-Agent Workflow
 
const agents = [
  {
    name: 'contract-reviewer',
    task: 'Review all customer agreements',
    folder: '/DD/Contracts/Customers',
    instructions: 'Apply customer agreement playbook'
  },
  {
    name: 'ip-reviewer',
    task: 'Review all IP agreements',
    folder: '/DD/Contracts/IP',
    instructions: 'Apply IP agreement playbook'
  },
  {
    name: 'employment-reviewer',
    task: 'Review all employment agreements',
    folder: '/DD/Contracts/Employment',
    instructions: 'Apply employment agreement playbook'
  },
  {
    name: 'litigation-reviewer',
    task: 'Analyze all pending litigation',
    folder: '/DD/Litigation',
    instructions: 'Assess litigation exposure and reserves'
  }
];
 
// Spawn all agents in parallel
const results = await Promise.all(
  agents.map(agent =>
    claude.spawnAgent({
      name: agent.name,
      prompt: `${agent.task} in ${agent.folder}. ${agent.instructions}.
               Output findings in structured JSON format.`,
      timeout: 30 * 60 * 1000 // 30 minute timeout
    })
  )
);
 
// Synthesize results
const synthesis = await claude.prompt(`
  I've received due diligence findings from ${agents.length} specialized reviewers.
 
  ${results.map((r, i) => `
  ## ${agents[i].name} Findings:
  ${r.output}
  `).join('\n')}
 
  Please synthesize into:
  1. Executive Summary of DD findings
  2. Critical issues requiring immediate attention
  3. Risk matrix by category
  4. Recommended deal adjustments
  5. Items requiring seller disclosure
`);

例: リサーチ + ドラフト ワークフロー

// Legal Research + Drafting Multi-Agent Workflow
 
async function researchAndDraft(topic, jurisdiction, outputType) {
  // Stage 1: Research Agent
  const research = await claude.spawnAgent({
    name: 'legal-researcher',
    prompt: `Research ${topic} under ${jurisdiction} law.
             Use available legal research tools (Midpage, CourtListener).
             Provide comprehensive analysis with citations.
             Format as structured legal memorandum outline.`,
    tools: ['midpage', 'courtlistener', 'webSearch']
  });
 
  // Stage 2: Draft Agent (uses research output)
  const draft = await claude.spawnAgent({
    name: 'legal-drafter',
    prompt: `Based on this research:
             ${research.output}
 
             Draft a ${outputType} addressing ${topic}.
             Include all relevant citations.
             Follow firm style guide.`,
    context: research.output
  });
 
  // Stage 3: Review Agent
  const review = await claude.spawnAgent({
    name: 'quality-reviewer',
    prompt: `Review this draft for:
             1. Legal accuracy
             2. Citation completeness
             3. Style compliance
             4. Missing analysis
 
             Draft:
             ${draft.output}`,
    context: draft.output
  });
 
  return {
    research: research.output,
    draft: draft.output,
    review: review.output
  };
}

Part 5: Skills を Plugins にパッケージ化する

Plugin 構造

legal-contract-plugin/
├── .claude-plugin/
│   └── plugin.json       # Manifest: name, description, version
├── skills/
│   └── contract-review/
│       └── SKILL.md      # Skills become /legal-contract-plugin:contract-review
├── agents/               # Subagent definitions
├── hooks/
│   └── hooks.json        # Event handlers
├── .mcp.json             # MCP server config
└── README.md

.claude-plugin/ の中に入るのは plugin.json のみで、それ以外はすべて plugin root に置きます(plugins docs、2026-09-02 時点確認)。

Plugin Manifest と Hooks

Manifest schema は変化しうるため、現在の fields は公式リファレンスを使用してください。最小限の hooks/hooks.json は両方のツールで機能します。

{
  "description": "Legal compliance checks",
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Read|Write|Edit",
        "hooks": [
          {
            "type": "command",
            "command": "${CLAUDE_PLUGIN_ROOT}/hooks/pretool-privileged-guard.sh"
          }
        ]
      }
    ]
  }
}

インストールと配布

# Local development (session-scoped); /reload-plugins picks up edits
claude --plugin-dir /absolute/path/to/legal-contract-plugin
claude plugin validate ./legal-contract-plugin
 
# Marketplace install (recommended for team rollout)
/plugin marketplace add your-org/your-marketplace
claude plugin install legal-contract-review@your-marketplace --scope project
 
# Lifecycle operations
claude plugin enable legal-contract-review@your-marketplace --scope project
claude plugin update legal-contract-review@your-marketplace --scope project

GitHub SSH key がない環境向けに、Claude Code 2.1.141 では CLAUDE_CODE_PLUGIN_PREFER_HTTPS が追加され、GitHub plugin sources を HTTPS 経由で clone できます。workload identity federation を使用するエンタープライズチームは、federation rule が複数の workspace を対象にしている場合、発行トークンを特定の workspace に限定するため ANTHROPIC_WORKSPACE_ID を設定することもできます。


Part 6: セキュリティ上の考慮事項

Skill のセキュリティ

  • Source verification: 信頼できるソースからの skills のみをインストールする
  • Code review: 展開前にすべての hook code をレビューする
  • No client data: skill files にクライアントデータを含めない
  • Version control: skills への変更を追跡する
  • Access control: 事務所の skills を変更できる人を制限する

データ保護

// Example: UserPromptSubmit sanitization hook (conceptual)
{
  "hooks": {
    "UserPromptSubmit": [
      {
        "hooks": [
          {
            "type": "command",
            "command": "\"$HOME/.claude/hooks/userprompt-sanitize.sh\""
          }
        ]
      }
    ]
  }
}

コンプライアンス要件

  • IT セキュリティによる skills のレビュー完了
  • sandbox environment での hooks のテスト完了
  • audit logging の有効化
  • クライアントデータ分離の確認
  • access controls の設定
  • backup procedures の文書化

今すぐやること

  • 事務所のレビュー工程の1つについてカスタム skill を作成する
  • compliance または audit logging のために、少なくとも1つの safety check(hook)を追加する
  • 並列文書処理のためのマルチエージェントワークフローをテストする
  • チームが使えるように skill を文書化する
  • 配布用に plugin としてのパッケージ化を検討する

関連


ナビゲーション

Quick Reference: Claude Code Commands

Official Claude Code terminal screenshot showing Claude running in a command-line workflow

Official Claude screenshot from Claude Code. Terminal workflows should be paired with scoped folders, explicit permission modes, and a reviewable diff before legal workflow changes are accepted.

# Skills (filesystem locations)
~/.claude/skills/           # Personal custom skills
.claude/skills/             # Project custom skills
 
# Hooks
/hooks                      # Open hooks manager in Claude Code
 
# Plugin hooks
${CLAUDE_PLUGIN_ROOT}/hooks/hooks.json
 
# Debugging
claude --help

出典

参考資料