tos-clause-scanner skill
Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues. Trigger when a user asks to review, audit, or analyze a ToS, privacy policy, or user agreement, or mentions specific concerns like auto-renewal or data authorization.
Is the tos-clause-scanner skill safe?
Clean: nothing in its files matched our rules. We read 2 files in the folder on 2026-09-28.
No findings.
Install the tos-clause-scanner skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/zebbern/claude-code-guide.git /tmp/claude-code-guide mkdir -p ~/.claude/skills cp -r /tmp/claude-code-guide/skills/tos-clause-scanner ~/.claude/skills/tos-clause-scanner
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Terms of Service Auditor (Consumer Perspective)
Systematically audit the Terms of Service, User Agreements, and Privacy Policies of apps, SaaS products, and platforms from an ordinary consumer's standpoint. Identify clauses that may harm consumer rights and produce an actionable audit report.
Quick Start
Paste the terms text directly to the Agent or provide a file path. The Agent will automatically complete the audit and output a structured report.
Example prompts:
- "Review this user agreement for any unfair or one-sided clauses"
- "Analyze this app's privacy policy and flag any covert data authorizations"
- "Does this ToS have auto-renewal traps?"
1. Audit Framework
1.1 Risk Category Definitions
The audit covers seven major risk categories, each with common problem patterns:
1.2 Typical Problem Patterns per Category
R1 Unfair Clauses
Look for these patterns:
- Unilateral termination rights: Platform may terminate a user's account at any time without cause
- Asymmetric breach liability: Users face heavy penalties for violations, but the platform's only remedy is a refund—or nothing at all
- Irrevocable authorizations: Requiring "irrevocable," "perpetual," "worldwide" broad-scope grants from the user
- Deemed consent: Continued use is treated as agreement to all terms with no option-by-option consent
- "Final interpretation right" reserved by the platform
Review checklist:
- Do the terms contain one-sided language such as "we reserve the right" or "we may at our sole discretion"?
- Are the user's obligations proportionate to the platform's obligations?
- Are there catch-all "blanket consent" clauses?
R2 Covert Data Authorization
Look for these patterns:
- Excessive data collection: Collecting data unrelated to the core service (e.g., a calculator app requesting contacts access)
- Vague third-party sharing: Using terms like "partners," "affiliates," or "third-party service providers" without specifying recipients
- Opt-out-by-default data collection: Personalized ads and behavioral tracking enabled by default rather than opt-in
- High opt-out friction: Difficult to disable data collection, or requires toggling off settings one by one
- Vague data retention periods: No clear retention timeframe, or use of phrases like "as long as necessary"
- Cross-border data transfers: Inadequate disclosure of where data is stored and transferred
Review checklist:
- Does the policy follow the principle of data minimization?
- Are third-party data recipients and purposes specifically listed?
- Does the user have a meaningful opt-out option?
- Is the data deletion process clear and actionable?
R3 Auto-Renewal Traps
Look for these patterns:
- Trial-to-paid auto-conversion: Automatic charges after a free trial ends, with no reminder before the trial expires
- Complex cancellation process: Canceling requires a phone call, email, or multi-step process, while subscribing takes a single click
- Early billing window: Renewal is locked in well before expiration (e.g., 24–72 hours ahead)
- No pro-rata refunds: No partial refund after an auto-renewal charge
- Silent price changes: Renewal price may change without prior notice
Review checklist:
- Is auto-renewal prominently disclosed during sign-up or purchase?
- Is canceling as easy as subscribing?
- Is there a pre-renewal reminder?
- Is the refund policy reasonable?
R4 Unilateral Amendment Rights
Look for these patterns:
- No-notice modifications: Platform reserves the right to change terms at any time without notifying users
- Continued use equals consent: Continued use after changes is treated as acceptance of the new terms
- Retroactive effect: New terms apply retroactively to past transactions or behavior
Review checklist:
- Is there a reasonable notification mechanism for changes (email, in-app message, push notification)?
- Is there a grace period for users to decide whether to continue using the service?
- Do material changes require fresh, explicit consent from users?
R5 Excessive Liability Disclaimers
Look for these patterns:
- Blanket disclaimers: "Under no circumstances shall we be liable for any direct, indirect, incidental, special, or consequential damages"
- Extremely low liability caps: Caps set at a trivially small amount (e.g., "fees paid in the past 12 months" or a fixed small sum)
- Core obligation exclusions: Disclaiming liability for defects in the service's core functionality
- Overbroad force majeure: Classifying system failures or cyberattacks as force majeure events
Review checklist:
- Is the scope of the disclaimer reasonable?
- Is the liability cap proportionate to the service fees?
- Does it exclude liability types that the law does not permit to be disclaimed?
R6 Dispute Resolution Restrictions
Look for these patterns:
- Mandatory arbitration: All disputes must be resolved through arbitration, with court litigation excluded
- Class-action waivers: Users are prohibited from joining class actions or class arbitrations
- Jurisdiction restrictions: Specifying a forum disadvantageous to consumers (e.g., the company's place of incorporation or a foreign court)
Review checklist:
- Does the consumer retain the right to sue in a local court?
- Who bears the arbitration costs?
- Is there a small-claims exception?
R7 IP Overreach
Look for these patterns:
- Broad content licenses: Requiring users to grant a "worldwide, perpetual, irrevocable, sublicensable" license to their content
- Uses beyond the service: Platform may use user content for advertising, AI training, or other purposes unrelated to the service itself
- Rights asymmetry: Platform retains usage rights even after the user deletes content
Review checklist:
- Is the content license limited to what is necessary to provide the service?
- Does the platform actually stop using content after account or content deletion?
- Is commercial resale or sublicensing of user content explicitly excluded?
2. Audit Workflow
2.1 Input Processing
After receiving the terms text submitted by the user, follow these steps:
- Identify document type: Determine whether it is a Terms of Service, Privacy Policy, or a combined agreement
- Extract key clauses: Categorize and extract relevant passages under the seven risk categories
- Analyze each clause: Assess the risk of every extracted clause
- Cross-check: Look for contradictions or conflicts between different clauses
2.2 Evaluation Criteria
For each identified risky clause, evaluate three dimensions:
3. Output Format: Audit Report
3.1 Report Structure
# Terms of Service Audit Report
## Basic Information
- **Subject**: [Platform / App name]
- **Document Type**: [Terms of Service / Privacy Policy / Combined Agreement]
- **Audit Date**: [Date]
## Overall Rating
[⭐⭐⭐⭐⭐ to ⭐ — five-tier scale]
| Metric | Rating |
|--------|--------|
| Overall Consumer-Friendliness | ⭐⭐⭐ |
| Data Privacy Protection | ⭐⭐ |
| Fee Transparency | ⭐⭐⭐⭐ |
| Clause Fairness | ⭐⭐ |
## Risk Findings
### 🔴 High-Risk (Requires Immediate Attention)
#### Finding 1: [Risk Title]
- **Risk Category**: R1 Unfair Clauses / R2 Covert Data Authorization / ...
- **Original Text**: > [Direct quote from the terms]
- **Risk Analysis**: [Plain-language explanation of why this clause is harmful to consumers]
- **Severity**: High | **Concealment**: High | **Actionability**: None
- **Recommendation**: [Actions the consumer can take]
### 🟠 Medium-High Risk
...(same structure as above)
### 🟡 Medium Risk
...(same structure as above)
## Consumer Action Items
1. [Specific action recommendations, ordered by priority]
2. ...
## Comparison with Industry Peers (if applicable)
[Brief note on whether the clause is standard industry practice]3.2 Plain-Language Explanation Principles
When analyzing each risk, follow these principles so that ordinary consumers can understand:
- Lead with the conclusion: What does this clause actually mean for the consumer?
- Use an analogy: Compare it to an everyday scenario (e.g., "This is like your landlord being allowed to raise your rent at any time without notifying you")
- End with a recommendation: What can the consumer do about it?
4. Regulatory Reference Framework
The audit references the following regulations (this does not constitute legal advice):
4.1 Chinese Regulations
More skills from zebbern/claude-code-guide
- Aacademic-paper-reviewerSimulates academic peer review, evaluating papers across Originality, Methodology, Results, and Writing to provide Major/Minor Revision recommendations with actionable feedback. Triggers when a user asks to \"review my paper,\" \"simulate peer review,\" or \"give my paper a peer review.
- Aactive-directory-attacksThis skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP roasting", "NTLM relay", or needs guidance on Windows domain penetration testing.
- Capi-fuzzing-bug-bountyThis skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
- Aapi-shape-explorerGenerate multiple radically different interface designs for a module using parallel sub-agents. Use when user wants to design an API, explore interface options, compare module shapes, or mentions "design it twice".
- Aaudit-flowInteractive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document flow, security review, debug flow, brainstorm, architecture review, post-mortem, incident review.
- Aauthentication-patternsAuthentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.
- Aaws-penetration-testingThis skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.
- Abroken-authenticationThis skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password policies", "test for session fixation", or "identify authentication bypass flaws". It provides comprehensive techniques for identifying authentication and session management weaknesses in web applications.
- Cburp-suite-testingThis skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using Burp Suite's core features for web application security testing.
- AcachingCaching strategies — invalidation, TTL guidelines, cache keys, cache layers, and when not to cache. Use when implementing or reviewing caching logic.
- Achart-imageGenerate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts. Triggers when the user asks to visualize data, create a graph, plot a time series, or generate a chart for a report, alert, or dashboard. Runs as a lightweight, headless Node.js process without a browser.
- Dcloud-penetration-testingThis skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud resources", "exploit cloud misconfigurations", "test O365 security", "extract secrets from cloud environments", or "audit cloud infrastructure". It provides comprehensive techniques for security assessment across major cloud platforms.