Best for
- Produce a structured, attorney-ready legal issues register for a product feature that uses artificial intelligence or machine learning. This skill spots legal exposure across training-data rights, output ownership and i…
zgbrenner/agentcounsel/skills/product-legal/ai-feature-review/SKILL.md
Use when conducting a legal issue-spotting review for a product feature that uses AI or machine learning to produce a structured issues register and recommendations for attorney review.
Decision brief
Use when conducting a legal issue-spotting review for a product feature that uses AI or machine learning to produce a structured issues register and recommendations for attorney review.
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/zgbrenner/agentcounsel --skill "skills/product-legal/ai-feature-review"Inspect the Agent Skill "AI Feature Review" from https://github.com/zgbrenner/agentcounsel/blob/b036d17a23125d51b9714a736481865a87eee226/skills/product-legal/ai-feature-review/SKILL.md at commit b036d17a23125d51b9714a736481865a87eee226. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
1. Confirm inputs. Verify that all required inputs are present. List what was received and flag anything missing or assumed. If the feature description is not provided, stop.
[ ] All required inputs have been received and accurately describe the feature as it will be deployed.
Produce a structured, attorney-ready legal issues register for a product feature that uses artificial intelligence or machine learning. This skill spots legal exposure across training-data rights, output ownership and infringement, transparency and disclosure obligations, privac…
A team is building, shipping, or updating a feature that uses an AI model, machine learning system, or algorithmic decision-making component.
If the feature description and model type are not provided, stop and request them. Do not fabricate technical details, data practices, or vendor terms.
Permission review
No configured static risk pattern was detected
This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.
Evidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 93/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 17 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Produce a structured, attorney-ready legal issues register for a product feature that uses artificial intelligence or machine learning. This skill spots legal exposure across training-data rights, output ownership and infringement, transparency and disclosure obligations, privacy and data use, automated-decision concerns, vendor terms, and high-risk use cases. It routes AI-vendor contract questions to ai-vendor-terms-review and broader AI risk triage to model-risk-triage. It produces draft legal work product for attorney review — not legal advice, not a regulatory clearance, and not a determination that the feature is lawful.
launch-review) has flagged an AI or algorithmic component for deeper analysis.ai-vendor-terms-review).If the feature description and model type are not provided, stop and request them. Do not fabricate technical details, data practices, or vendor terms.
ai-vendor-terms-review).launch-review, which will route AI issues here).model-risk-triage).core/source-and-citation-discipline.md. Never invent legal authority, citations, quotations, statutes, cases, regulations, filing deadlines, or procedural rules. Label what is a provided source, a user-provided fact, an assumption, a legal inference, or an item requiring attorney verification, and use a citation placeholder such as [Attorney to insert authority] when no source is available.[CONFIRM: ...] marker.Confirm inputs. Verify that all required inputs are present. List what was received and flag anything missing or assumed. If the feature description is not provided, stop.
Characterize the feature. Summarize the AI feature type (generative, classification, recommendation, scoring, decision-automation, or other), its position in the user experience, and whether outputs are directly user-facing or used internally.
Training-data rights and IP. Assess whether the training data used (if in-house) or the vendor's training data (if vendor-supplied and disclosed) raises rights issues: licensed data, scraped data, copyrighted works, personal data used for training, and applicable consent or contractual restrictions. Flag for IP and privacy counsel.
Output ownership and infringement risk. Assess who owns the AI outputs, whether the outputs could infringe third-party IP (copyright, trademark, trade dress), and whether the feature's output use case is consistent with the applicable model license or vendor terms. Route detailed vendor contract analysis to ai-vendor-terms-review.
Accuracy, reliability, and disclaimer needs. Assess whether the feature makes representations — express or implied — about the accuracy, completeness, or reliability of AI outputs. Flag: hallucination risk, outputs presented as factual without verification, medical/legal/financial advice risk, and whether existing disclaimers adequately disclose limitations.
Transparency and disclosure to users. Review what the product currently discloses about AI use. Flag: absence of disclosure that a feature is AI-powered, failure to disclose when outputs are AI-generated (particularly for content, recommendations, or decisions), and obligations under applicable AI transparency laws [CONFIRM: applicable jurisdictions].
Privacy and data use. Assess how personal data flows through the feature: data collected at inference, data sent to a vendor model API, data used for model improvement or retraining, and applicable consent, data minimization, and data retention obligations. Route detailed privacy analysis to privacy counsel.
Automated decision-making and algorithmic accountability. Assess whether the feature makes or substantially influences consequential decisions affecting users. Flag: absence of human review, failure to provide explanations or rights of contestation, and applicable automated-decision laws [CONFIRM: EU GDPR Art. 22, state AI laws, sector-specific requirements].
Vendor terms and model license. Flag whether the vendor's API terms, model license, or acceptable use policy permits the intended use case. Identify provisions that restrict output use, impose disclosure obligations, or limit commercial use. Route detailed vendor contract review to ai-vendor-terms-review.
High-risk use cases. Assess whether the feature operates in a high-risk domain: healthcare or wellness advice, employment screening, credit or insurance decisions, housing, education, legal advice, law enforcement, or critical infrastructure. Flag each domain for specialist counsel and note applicable regulatory frameworks.
Open-source model considerations. If an open-source model is used, flag: the model license type and commercial use permissions, any attribution or disclosure requirements, and whether fine-tuning or distribution triggers additional obligations.
Compile the issues register. Assemble every flagged issue into the structured table described in the Output Format section. Assign severity (High / Medium / Low / Unknown), practice area owner, routing (attorney or sibling skill), and whether the issue is blocking for launch.
Draft recommendations. For High-severity issues, draft a brief recommended action (disclosure language, contractual protection, human-oversight design change, or specialist escalation), framed as options for attorney review — not final guidance.
List assumptions and open items. State every assumption and every [CONFIRM: ...] item that must be resolved before the review can be relied upon.
Deliver the following sections, in order, labeled as DRAFT — FOR ATTORNEY REVIEW ONLY:
Review Summary: feature name, model type (in-house / vendor), target markets, review date, inputs received, and inputs missing or assumed.
Feature Characterization: brief description of the AI feature type, user-facing behavior, and output use.
AI Feature Issues Register (one row per issue): a table with columns — Issue Description | Legal Area | Severity (High / Medium / Low / Unknown) | Recommended Owner / Skill | Blocking? (Yes / No / TBD) | Status.
High-Risk Domain Flags: a separate callout for any issues in healthcare, employment, credit, housing, education, or other high-risk domains, with recommended escalation path.
Routing Map: a brief list linking each High or blocking issue to the recommended next step (specialist attorney, ai-vendor-terms-review, model-risk-triage, or other sibling skill).
Recommended Actions (draft for attorney review): for each High-severity issue, a brief recommended action or options framed as drafts for attorney review.
Assumptions and Open Items: numbered list of every assumption and [CONFIRM: ...] item.
Attorney Verification Checklist: checkbox items (see below).
When the output will be used to brief a non-lawyer business stakeholder — a product owner, deal lead, people manager, founder, or executive — add a Business Stakeholder Summary as a clearly separated, plainly labeled section, following core/business-stakeholder-communication.md. Produce it only when the user requests it or when the audience is plainly a business decision-maker. It is an addition to the deliverable above — never a replacement for it, and never a substitute for attorney review. It contains:
ai-vendor-terms-review or by counsel with vendor contract expertise.[CONFIRM: ...] items have been resolved.