Claude for Legal: why it is not safe to use
We found disclosed connector-based data access and deployment choices that warrant careful review before using this legal workflow skill.
What we found
Our review did not find hidden instructions, hardcoded secrets, destructive shell behavior, privilege escalation, undisclosed network destinations, or hidden code download paths in the inspected repository materials. The documentation also states that retrieved connector content should be treated as data, not commands, and describes confirmation gates before anything is filed, sent, or relied on.
We marked this skill with a warning because its intended use depends on connecting external systems such as Slack, Google Drive, Ironclad, DocuSign, and iManage, and on Anthropic managed-agent or API deployment paths. That means potentially sensitive legal and business information may flow through the accounts and connectors an organization chooses to enable. In our scan, those access paths were disclosed rather than hidden, but they still merit a privacy and governance review before adoption.
What to do instead
Use this skill only with a documented connector allowlist, least-privilege account scopes, and client-side confirmation for any write action. Review what data each connected system can expose, limit access to approved matters or repositories, and confirm your retention, logging, and vendor approval requirements before deployment.
Source: https://github.com/anthropics/claude-for-legal
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.