Skip to content
Back to skills

Legal Docs Stinger

ASecurity

Draft SaaS legal documents with lawyer review. Use for Terms, Privacy Policy, DPA, MSA, cookie notice, or generator choice. Read guides/ for the decision path.

  • 85 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 9, 2026
businessgo

Works with

  • cli

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 27, 2026

npx -y skills add legioncodeinc/vibe-coding-tools --skill legal-docs-stinger --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Legal Docs Stinger?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Legal Docs Stinger
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/legioncodeinc-legal-docs-stinger/badge)](https://www.skillsdirectory.com/skills/legioncodeinc-legal-docs-stinger)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: legal-docs-stinger
description: "Draft SaaS legal documents with lawyer review. Use for Terms, Privacy Policy, DPA, MSA, cookie notice, or generator choice. Read guides/ for the decision path."
license: AGPL-3.0-or-later
---

# Legal Docs Stinger

The practitioner arsenal for generating and maintaining the five core SaaS legal documents. Read `guides/00-generator-selection.md` first to orient to the generator landscape, then navigate to the document-specific guide that matches the current task.

---

## Quick-start routing

| Task | Guide |
|---|---|
| Choose Termly vs Iubenda vs Osano | `guides/00-generator-selection.md` |
| Draft or audit Terms of Service | `guides/01-terms-of-service.md` |
| Draft or audit Privacy Policy | `guides/02-privacy-policy.md` |
| Draft or audit DPA (as data processor) | `guides/03-dpa.md` |
| Draft or audit MSA | `guides/04-msa.md` |
| Draft or audit Cookie Notice | `guides/05-cookie-notice.md` |
| Multi-regime compliance check | `guides/06-compliance-posture-matrix.md` |
| Receive and respond to a customer DPA redline | `guides/07-customer-dpa-workflow.md` |

---

## File index

### Principles and procedures (guides/)

- `guides/00-generator-selection.md` — Termly vs Iubenda vs Osano vs Contractbook decision matrix, pricing tiers, jurisdiction coverage, CMP bundling
- `guides/01-terms-of-service.md` — canonical ToS section checklist (10 required clauses), clickwrap vs browse-wrap enforcement, EULA vs SaaS ToS distinction
- `guides/02-privacy-policy.md` — required sections by regime, data-inventory input process, cookie disclosure, right-to-deletion workflow
- `guides/03-dpa.md` — GDPR Article 28 mandatory clauses, four-schedule structure, DPF vs SCCs transfer mechanism, sub-processor approval
- `guides/04-msa.md` — SaaS MSA structure (9 required sections), startup defaults, enterprise negotiation pressure points, MSA vs ToS decision
- `guides/05-cookie-notice.md` — cookie category taxonomy, consent banner mechanics, IAB TCF v2.3, GPC signal (CPRA 2026 requirement), GDPR vs CCPA consent standards
- `guides/06-compliance-posture-matrix.md` — GDPR / CCPA / Quebec Law 25 / LGPD side-by-side requirements table with minimum-viable-compliance tier
- `guides/07-customer-dpa-workflow.md` — Red Flag / Fallback Matrix, triage protocol, timing rules, response memo structure

### Worked examples (examples/)

- `examples/data-inventory-example.md` — completed data-inventory input for a typical B2B SaaS (CRM + analytics + payment)
- `examples/customer-dpa-response-example.md` — annotated DPA response memo showing the Red Flag / Fallback Matrix applied to a real redline

### Output templates (templates/)

- `templates/privacy-policy-data-inventory.md` — fillable input form for mapping personal data categories to purposes, retention, and third parties
- `templates/sub-processor-list.md` — the living sub-processor table required by GDPR Article 28(2)
- `templates/customer-dpa-response-memo.md` — clause-by-clause response memo for customer DPA negotiations

### Reports (reports/)

- `reports/README.md` — report accumulation policy; dated audit reports go here

### Research trail (research/)

- `research/research-plan.md` — depth tier, time window, query plan
- `research/research-summary.md` — executive summary, 5 most influential sources, 5 open questions
- `research/index.md` — manifest of all source files
- `research/internal/command-brief-notes.md` — brief extraction and scope decisions
- `research/external/` — 9 source notes (ToS, generator comparison, DPA, MSA, Quebec Law 25, DPF/SCCs, customer-DPA negotiation)

---

## The attorney-review invariant

Every output from this stinger is a **best-effort starting point**, not a compliance certification. The canonical closing line for all outputs is:

> "This is a generated draft for reference. Have a qualified attorney licensed in your jurisdiction review all legal documents before publishing or countersigning."

No exceptions. Including this line is a critical directive for `legal-docs-wasp-drone`.

---

## Refresh triggers

Re-run scripture-historian at `shallow` tier when any of the following occur:

- New EU SCCs version published by the European Commission
- CCPA/CPRA implementing regulations amended
- Quebec Law 25 enforcement action or new CAI guidance
- LGPD (ANPD) material enforcement action or new guidance
- New IAB TCF major version
- EU-US DPF adequacy decision challenged or revoked (Schrems III risk)
- A new data category or sub-processor added to the product (partial refresh)
- Termly or Iubenda pricing / jurisdiction-coverage changes materially

---

*Paired Angel: `ai-tools/agents/legal-docs-wasp-drone.md`*
*Command Brief: `ai-tools/command-briefs/legal-docs-wasp-drone-command-brief.md`*
*Research: `ai-tools/skills/legal-docs-stinger/research/`*

Files in this skill

  • SKILL.md5.3 KB
  • examples/customer-dpa-response-example.md4.9 KB
  • examples/data-inventory-example.md3.3 KB
  • guides/00-generator-selection.md4.4 KB
  • guides/01-terms-of-service.md4.8 KB
  • guides/02-privacy-policy.md4.7 KB
  • guides/03-dpa.md6.5 KB
  • guides/04-msa.md5.2 KB
  • guides/05-cookie-notice.md3.5 KB
  • guides/06-compliance-posture-matrix.md5.4 KB
  • guides/07-customer-dpa-workflow.md5.5 KB
  • reports/README.md1.1 KB
  • research/external/2026-05-20-customer-dpa-negotiation.md5.8 KB
  • research/external/2026-05-20-dpa-gdpr-art28-template.md4.9 KB
  • research/external/2026-05-20-eu-us-dpf-cross-border-transfers.md4.9 KB
  • research/external/2026-05-20-generator-landscape-2026.md3.7 KB
  • research/external/2026-05-20-msa-saas-template-structure.md4.7 KB
  • research/external/2026-05-20-quebec-law25-saas-compliance.md5.8 KB
  • research/external/2026-05-20-saas-contracts-guide-legal-firm.md2.6 KB
  • research/external/2026-05-20-saas-tos-checklist.md2.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…