Skip to main content

教程 06: Legal Plugin Workflows

Run contract review, NDA triage, vendor checks, briefings and templated responses as repeatable workflows with the Claude Legal plugin or with Codex skills and custom GPTs.

覆盖Claude: 已验证ChatGPT / Codex: 草稿Grok Bot: 已验证

你将学到什么

本教程将五项反复出现的法律任务转化为可重复的工作流:合同审查、NDA 分流、供应商检查、简报和模板化回复。在 Claude 中,它们作为 Legal plugin 命令运行;在 OpenAI 中,它们作为 Codex skills 或基于同一套 playbook 构建的 custom GPT 运行。请在标签页中选择你的工具;playbook、风险评级和审查清单是共享的。

学习目标

完成本教程后,你将能够:

  • 在你的工具中运行这五个工作流,并解读其带有风险评级的输出
  • 配置你所在组织的 playbook,使工作流能够应用你的立场
  • 连接研究工具,以便引用得到验证而不是猜测
  • 将插件式工作流与 Harvey 和 Legora 的对应方案进行比较

第 1 部分:概览

Claude Legal plugin

Legal plugin 页面(检查日期:2026-09-02)介绍了面向企业法务团队的法律工作流,可安装在 Claude Code 和 Claude Cowork 中:

  • 预构建命令/review-contract/triage-nda/vendor-check/brief/respond
  • 可配置 playbook:在本地 settings file 中设置标准立场、可接受范围和升级触发条件
  • 风险标记:GREEN/YELLOW/RED,并附带具体 redline 建议
  • MCP connectors:文档管理、聊天和项目跟踪工具,用于提供更丰富的上下文

官方优先的安装路径

Anthropic 在开源仓库 Claude for Legal 中发布按业务领域划分的插件(commercial、privacy、corporate、product、IP、litigation、employment、AI governance、clinic 和 law-student plugins),每个插件都包含具名 agents,如 /commercial-legal:review。可在 Legal AI Skills hub 浏览安装命令,尤其是 Claude for Legal suite entry。旧版 knowledge-work-plugins/legal 已弃用。

与竞品相比如何

FeatureClaude Legal pluginCodex skills / custom GPTHarveyLegora
Contract Review/review-contractSkill or GPT + promptWorkflowTabular Review
NDA Triage/triage-ndaSkill or GPT + promptYesYes
Custom PlaybookFull controlFull controlLimitedModerate
Risk RatingsRED/YELLOW/GREENRED/YELLOW/GREENYesYes
Redline SuggestionsYesYesYesYes
Bulk ProcessingScheduled agents in Claude for LegalManual or scriptedEnterprise workflowsEnterprise workflows
Pricing ModelPublic plansPublic plans (verify)Enterprise contractsEnterprise contracts

Harvey 和 Legora 的功能来自供应商资料;请向各供应商核实具体能力。

要求

  • Claude Pro、Max、Team 或 Enterprise;pricing page 列出了 Pro 及以上计划包含 Cowork 和 Claude Code(检查日期:2026-09-02)
  • Claude Code 或 Cowork desktop app,用于安装 plugins
  • 可选:已配置的 practice profile(第 3 部分)和 research connector(第 4 部分)

第 2 部分:工作流参考

下面的五个工作流共享一种输出结构。Claude 标签展示 plugin 命令和示例输出;OpenAI 标签提供可从 skill 或 custom GPT 生成同样结构的 prompt。

/review-contract - 逐条款合同审查

Purpose:根据你的 playbook 进行全面合同分析

Syntax

/review-contract

What It Does

  1. 识别合同类型和当事方
  2. 分析每一项重要条款
  3. 与你配置的 playbook 立场进行比较
  4. 分配风险评级(GREEN/YELLOW/RED)
  5. 提供具体的 redline 建议
  6. 生成谈判优先级列表

Official Claude legal-task screenshot showing contract redlining and negotiation output

来自 Contract redlining and negotiation 的官方 Claude 截图。请将生成的 redlines 视为拟议的谈判措辞,而非法律批准;持证律师应根据源合同、playbook 和交易背景核查每一处编辑。

Example Output

## CONTRACT ANALYSIS: Software License Agreement
**Contract Type**: SaaS Subscription Agreement
**Our Role**: Customer/Licensee
**Counterparty**: Acme Software Inc.

### CLAUSE ANALYSIS

#### 1. LICENSE GRANT (Section 2.1)
GREEN - Acceptable
- Grants non-exclusive, worldwide license
- Includes affiliate usage rights
- Standard use restrictions

#### 2. LIMITATION OF LIABILITY (Section 8)
RED - Must Negotiate
Current: "Vendor's liability shall not exceed $10,000"
Issue: Cap is far below contract value ($150,000 ACV)
Playbook Position: Minimum 12 months fees ($150,000)

**Suggested Redline**:
"Vendor's liability shall not exceed ~~$10,000~~ the greater
of (a) fees paid in the twelve (12) months preceding the
claim or (b) $150,000."

#### 3. INDEMNIFICATION (Section 7)
YELLOW - Should Negotiate
Current: IP indemnity excludes "modifications by Customer"
Issue: Overly broad exclusion could limit protection
Playbook Position: Narrow exclusions to material modifications

**Suggested Redline**:
Add: "provided such modification materially alters the
functionality of the Service in a manner not contemplated
by the Documentation"

### NEGOTIATION PRIORITIES
1. RED Liability Cap (critical gap)
2. RED Data Breach Indemnity (missing entirely)
3. YELLOW Indemnity Exclusions (overbroad)
4. YELLOW Termination Notice (60 vs 30 days)
5. GREEN Auto-renewal period (acceptable at 30 days)

### CUMULATIVE RISK SCORE: 7 (HIGH)
Recommend: Partner review before signing

/triage-nda - 快速 NDA 预筛查

Purpose:快速对收到的 NDA 进行分类,以便采取适当处理方式

Syntax

/triage-nda

What It Does

  1. 识别 NDA 类型(双向/单向及信息流向)
  2. 扫描非标准或有问题的条款
  3. 分类到相应处理路径
  4. 如不属于标准路径,则提供具体关注点

Triage Categories

CategoryDescriptionAction
GREEN - STANDARD APPROVALMatches our standard or betterParalegal can execute
YELLOW - COUNSEL REVIEWMinor deviationsAttorney quick review
RED - FULL REVIEWSignificant issuesFull legal analysis

Example Output

## NDA TRIAGE RESULTS

**Document**: Acme Corp Mutual NDA (v2.1)
**Type**: Mutual Non-Disclosure Agreement
**Direction**: Two-way protection

### TRIAGE RESULT: COUNSEL REVIEW

**Reason**: Contains 2 non-standard provisions requiring attorney review

### FLAGGED ITEMS:

1. **Non-Solicit Clause (Section 6)**
   - Not typically included in standard NDA
   - 24-month restriction on hiring
   - May need business approval

2. **Jurisdiction (Section 9)**
   - Specifies Texas courts exclusive jurisdiction
   - Our standard: Delaware or mutual agreement
   - Acceptable but note for negotiation if sensitive deal

### STANDARD ITEMS (No Issues):
- Definition of Confidential Information
- Mutual obligations
- 3-year term
- Standard exclusions
- Return/destruction requirement

### RECOMMENDATION:
Route to associate for 15-minute review of flagged items.
If non-solicit is acceptable to business, can proceed.

运营影响

分流工作流可在很大程度上减少审查时间,具体取决于文件质量、playbook 成熟度和团队流程。对于标准路径的 NDA,通常可在律师预先设定检查项后转交 paralegal 签署执行。


/vendor-check - 供应商协议状态

Purpose:检查与已知供应商签订协议的状态

Syntax

/vendor-check [vendor name]

需要 MCP

此命令需要连接到你的文档管理系统的 MCP。

Example

/vendor-check Salesforce

## VENDOR STATUS: Salesforce

**Active Agreements**:
1. Master Subscription Agreement - Expires: Dec 2026
2. Data Processing Addendum - Current
3. Professional Services SOW #3 - Completed

**Upcoming**:
- Renewal negotiation due: October 2026
- Auto-renewal date: November 15, 2026

**Historical Notes**:
- Last negotiated liability cap increase (2024)
- Standard DPA accepted without modification

**Recommended Actions**:
- Begin renewal prep 90 days out (September 2026)
- Review new AI features for data processing implications

/brief - 生成上下文化简报

Purpose:针对不同需求创建简报文档

Syntax

/brief [type] [topic/context]

Brief Types

  • daily - 待办事项的每日简报
  • topic - 特定主题的研究简报
  • incident - 事件响应简报

Example

/brief incident data-breach-notification

## INCIDENT RESPONSE BRIEF: Data Breach Notification

**Prepared**: [Date/Time]
**Classification**: Attorney-Client Privileged

### IMMEDIATE ACTIONS (0-24 Hours)
1. Preserve all relevant logs and communications
2. Engage incident response team
3. Notify cyber insurance carrier
4. Begin notification timeline tracking

### NOTIFICATION REQUIREMENTS BY JURISDICTION

**Federal**:
- HIPAA: 60 days (if PHI involved)
- GLBA: "As soon as reasonably practicable"
- SEC: 4 business days (material events, public companies)

**State Requirements** (Selected):
| State | Deadline | AG Notice? | Content Requirements |
|-------|----------|------------|---------------------|
| CA | "Expedient" | Yes >500 | Specific format |
| NY | "Most expedient" | Yes | Format specified |
| TX | 60 days | Yes >250 | Toll-free number |

### TEMPLATE RESOURCES
- Customer notification template: [Link]
- AG notification template: [Link]
- Board briefing outline: [Link]

### KEY CONTACTS
- Outside Counsel: [Name, Number]
- Forensics Vendor: [Name, Number]
- PR/Communications: [Name, Number]

/respond - 模板化法律回复

Purpose:为常见请求生成标准回复

Syntax

/respond [request-type]

Request Types

  • dsar - 数据主体访问请求回复
  • deletion - 数据删除请求回复
  • hold - 诉讼保全通知
  • subpoena - 传票确认函

Example

/respond dsar

## DATA SUBJECT ACCESS REQUEST RESPONSE

**Template Version**: 2.1 (GDPR/CCPA Compliant)

---

Dear [Requestor Name],

We are writing in response to your data subject access request
dated [Request Date]. We have verified your identity and are
pleased to provide the following information:

**Personal Data We Hold About You:**

| Category | Data Elements | Source | Purpose |
|----------|---------------|--------|---------|
| Identity | [Name, Email] | [Source] | [Purpose] |
| [Continue for all categories] |

**Third Parties With Whom Data Was Shared:**
- [List recipients and purposes]

**Your Rights:**
You have the right to:
- Request correction of inaccurate data
- Request deletion (subject to legal retention requirements)
- Object to processing for certain purposes
- Data portability in machine-readable format

**How to Exercise Additional Rights:**
Contact our Privacy Team at [privacy@company.com]

We must retain certain data for [legal/regulatory reasons].
Please see attached schedule for applicable retention periods.

If you have concerns about our handling of your data, you may
contact [relevant supervisory authority].

Sincerely,
[Company Name] Privacy Team

---

**Internal Notes** (Do not include in response):
- Verify identity before sending
- Log request in DSAR tracker
- 30-day response deadline: [Date]
- Fees applicable: No (first request)

命令速查表

CommandPurposeWhen to Use
/review-contractFull contract analysisNew contracts, renewals
/triage-ndaQuick NDA categorizationHigh-volume NDA processing
/vendor-checkVendor agreement statusRenewal prep, due diligence
/brief dailyDaily matter summaryMorning briefings
/brief topicTopic researchNew legal issues
/brief incidentIncident responseBreaches, litigation
/respond dsarPrivacy request responseGDPR/CCPA requests
/respond holdLitigation holdNew litigation matters


第 3 部分:配置你的 Playbook

playbook 驱动每一次风险评估和 redline 建议。通用 playbook 只会产生通用结果,因此请投入时间完善你的立场、阈值和审批矩阵(模板见教程 05)。

Practice profile(Claude for Legal)

Claude for Legal README(检查日期:2026-09-02)说明,每个 plugin 通过纯英文的 practice profile 配置,而不是 JSON file:

  1. 在 Claude Code 中安装 plugin(/plugin marketplace add/plugin install commercial-legal@claude-for-legal)或在 Cowork 中安装
  2. 运行 /commercial-legal:cold-start-interview(10 到 20 分钟;也有 quick-start 选项)。它会询问已签署的 MSA、playbook 或先前审查备忘录等种子文件
  3. 访谈会写入 ~/.claude/plugins/config/claude-for-legal/<plugin>/CLAUDE.md;plugin 中的每个 skill 都会从中读取
  4. 小幅修正可直接编辑该文件;它在 plugin 更新后仍会保留

marketplace Legal plugin 将其配置描述为一个“local settings file”,用于设置标准立场、可接受范围和升级触发条件。本教程的早期版本展示过一个 ~/.claude/legal-playbook.json file;该文件不是当前仓库的一部分,因此应视为 legacy。

按你的需求定制

在依赖任何工作流输出前,请投入时间根据你所在组织的风险承受能力和标准谈判立场来定制这些立场。


第 4 部分:连接你的工具

Claude for Legal 中的 MCP connectors

README 的 connector 表(检查日期:2026-09-02)包括:

ConnectorWhat it gives ClaudeNotes
SlackRead channels, search, send messages and canvasesYour workspace
Google Drive, BoxRead docs, sheets, slides, VDR filesYour account or tenant
iManageMatter workspaces, document versionsCustomer subscription
Ironclad, DocuSign / DocuSign CLMContract register, renewal dates, envelope statusCustomer subscription
EverlawE-discovery productions, tagged sets, chronologiesCustomer subscription
CourtListenerFederal dockets and opinionsPublic; optional API key
Trellis, Descrybe, Solve IntelligenceState dockets, case law research, patent draftingCustomer subscription
CoCounsel Legal (Thomson Reuters)Westlaw Deep Research with cited reportsCustomer subscription; OAuth

在每个 plugin 的 .mcp.json 中,或在 Claude Code 中使用 claude mcp 配置 connectors。

Official Claude Code Slack screenshot showing task coordination in Slack

来自 Claude Code 的官方 Claude 截图。如果某个法律工作流会发送 Slack 通知,请不要在频道可见的状态文本中包含客户名称、特权事实或对事项敏感的细节。

先连接研究工具。 README 说明,通过 research connector 获取的 citations 会标注其来源;仅来自模型知识的 citations 会被标记为 [verify];如果未连接研究工具,则交付物上方的 reviewer note 会记录来源未经验证。


第 5 部分:工作流示例

下面的步骤使用 Claude 命令命名;在 Codex 或 custom GPT 中,请在每一步运行第 2 部分中的对应 prompt。

工作流 1:端到端合同审查

1. Receive contract from business team

2. Initial triage:
   /triage-nda (if NDA)
   OR
   Upload contract to Contract Review Project

3. Full review:
   /review-contract

4. Review output:
   - Check risk ratings
   - Review suggested redlines
   - Verify against your judgment

5. Generate response:
   /respond [type]
   OR
   Manual drafting based on suggestions

6. Document in matter management:
   /vendor-check [vendor] (to log)

工作流 2:批量 NDA 处理

Day starts: 15 NDAs in queue

1. Batch triage:
   For each NDA:
   /triage-nda

2. Sort results:
   GREEN STANDARD (6): Send to paralegal for execution
   YELLOW COUNSEL (7): Quick 10-min reviews
   RED FULL REVIEW (2): Schedule detailed analysis

3. Process YELLOW queue:
   Quick review flagged items
   Accept or request changes

4. Process RED queue:
   /review-contract for full analysis
   Draft redlines
   Negotiate as needed

Total time: ~2 hours vs. 6+ hours manually

工作流 3:事件响应

1. Incident reported (potential data breach)

2. Generate immediate briefing:
   /brief incident data-breach

3. Review notification requirements:
   - Federal requirements
   - State-by-state deadlines
   - Industry-specific rules

4. Prepare communications:
   /respond [various notification types]

5. Document privileged analysis:
   All work within privileged Project

6. Generate status updates:
   /brief daily [incident matters]

第 6 部分:最佳实践

建议做法

  • Do 在大量使用前先配置你的 playbook
  • Do 核实所有 citations 和法律结论
  • Do 使用 matter workspace 实现事项隔离
  • Do 在接受建议前仔细审查 RED 项目
  • Do 根据你的司法辖区定制模板

不建议做法

  • Don't 仅依赖 plugin 输出作出法律决定
  • Don't 跳过对案例 citations 的核实
  • Don't 在专业事项中使用通用 playbook
  • Don't 未经审查就将 plugin 输出分享给客户
  • Don't 假设工作流能捕捉到所有问题

需要专业判断

plugin 或 skill 是强大的效率工具,但不能替代律师判断。请始终核实关键建议,尤其是被标记为 RED 的项目和建议的 redlines。

质量控制清单

对于每一次由 plugin 辅助的审查:

  • 已核实合同类型识别正确
  • 已确认我方角色(customer/vendor)正确
  • 已手动检查每个 RED 项目
  • 已核实建议措辞适当
  • 已确认特定司法辖区要求
  • 已审查 plugin 可能遗漏的问题
  • 已对建议运用专业判断

现在就做

  • 配置你的 playbook:运行 cold-start interview(Claude),或将 playbook 粘贴到你的 skill 或 GPT instructions 中(OpenAI)
  • 在一份示例合同上运行合同审查工作流,并查看风险评级
  • 在一份 NDA 上运行 NDA 分流工作流,并确认结果与你的判断一致
  • 连接一个研究来源,并检查 citations 的标记方式
  • 将一个工作流加入你下周的个人清单

相关内容


下一步

继续阅读 Tutorial 07: MCP Integrations for Legal Work,了解如何将你的助手连接到外部法律数据源。

上一页:Tutorial 05: Building Custom Negotiation Playbooks

来源

延伸阅读