Agent Skillslawve-ai/awesome-legal-skills › lawve-agentic-delegation-audit-ignacio-adrian-lerer

lawve-agentic-delegation-audit-ignacio-adrian-lerer

GitHub

用于评估AI代理在LegalOps中的安全性。针对具备发送、执行等行动能力的AI,提供授权、监督、问责与控制审计框架,涵盖自主性分类、权限映射及可观测性等步骤,确保合规与风险控制。

skills/agentic-delegation-audit-adrian-lerer/SKILL.md lawve-ai/awesome-legal-skills

触发场景

律师或客户需评估具有行动能力的AI代理工作流 产品或法务团队将AI接入邮件、支付等外部系统 需要解释Agentic AI在治理层面的风险

安装

npx skills add lawve-ai/awesome-legal-skills --skill lawve-agentic-delegation-audit-ignacio-adrian-lerer -g -y
更多选项

不安装直接使用

npx skills use lawve-ai/awesome-legal-skills@lawve-agentic-delegation-audit-ignacio-adrian-lerer

指定 Agent (Claude Code)

npx skills add lawve-ai/awesome-legal-skills --skill lawve-agentic-delegation-audit-ignacio-adrian-lerer -a claude-code -g -y

安装 repo 全部 skill

npx skills add lawve-ai/awesome-legal-skills --all -g -y

预览 repo 内 skill

npx skills add lawve-ai/awesome-legal-skills --list

SKILL.md

Frontmatter
{
    "name": "lawve-agentic-delegation-audit-ignacio-adrian-lerer",
    "metadata": {
        "author": "Ignacio Adrián Lerer",
        "license": "agpl-3.0",
        "version": "2026-06-05"
    },
    "description": "Use when a lawyer, legal team, or client needs to assess AI agents that can act on someone's behalf: send messages, search, draft, file, pay, delete, connect to accounts, use tools, or rely on external data. Produces a practical delegation, oversight, accountability, and control audit for legal operations."
}

Lawve Agentic Delegation Audit

Use this skill to help lawyers evaluate whether an AI agent workflow is safe enough to use in legal or business operations.

Core idea:

When AI only answers, the user evaluates an output.
When AI acts, the user delegates authority.
Delegated authority needs controls, logs, revocation, and accountability.

Use When

  • A client wants to use an AI agent for legal, compliance, business, or administrative work.
  • A product, law firm, or legal ops team is connecting an agent to email, files, CRM, court portals, payments, messaging, calendars, databases, browser tools, or code execution.
  • A lawyer needs to explain the risks of agentic AI in practical governance terms.
  • A workflow may send, file, delete, approve, purchase, publish, sign, deploy, or change access.
  • A system claims to be "autonomous", "agentic", "assistant with tools", "AI employee", "legal copilot", or "workflow agent".

Do Not Use For

  • Pure doctrinal legal research with no agentic action.
  • Final legal opinions without jurisdiction-specific legal review.
  • Technical implementation of an agent runtime.
  • Approving production use of an agent without evidence, logs, and controls.

Intake

Collect only what is necessary:

  • What task does the agent perform?
  • Who is the human principal?
  • Who deploys or operates the agent?
  • What systems, accounts, files, channels, or tools can it access?
  • What actions can it take without step-by-step approval?
  • Which actions are irreversible, external, financial, legal, confidential, or reputation-sensitive?
  • What logs exist and who can read them?
  • How can the user pause, revoke, appeal, or correct the agent?
  • What data can influence the agent, including emails, webpages, chats, files, tickets, and prompts?

Audit Steps

  1. Classify the autonomy level

    • answer_only: produces information only.
    • draft_only: drafts but does not send or change records.
    • approval_gated_actor: acts only after explicit approval.
    • policy_bounded_actor: acts within predefined limits.
    • long_running_actor: continues across time, sessions, or triggers.
  2. Map delegated authority

    • Name the principal.
    • Name the deployer/operator.
    • List what authority the agent has.
    • Separate read, draft, internal write, external write, financial, legal-sensitive, and privileged actions.
  3. Check observability

    • Can the user see what the agent did?
    • Are tool calls and external actions logged?
    • Are logs understandable by a non-developer?
    • Are source data and model inference separated?
  4. Check control and revocation

    • Can the user pause the agent?
    • Can permissions be narrowed?
    • Can access be revoked quickly?
    • Are irreversible actions previewed before execution?
  5. Check accountability

    • Who is responsible if harm occurs?
    • Is responsibility split across vendor, deployer, user, professional, and client?
    • Is there a human review point before legal reliance or external action?
  6. Check attack surface

    • Can untrusted content influence the agent?
    • Does the agent process emails, webpages, chats, documents, tickets, or social posts as instructions?
    • Are external content and system instructions separated?
    • Are prompt injection, data exfiltration, and tool misuse considered?
  7. Apply legal uncertainty gate

    • Use PASS, ESCALATE, or BLOCK for downstream legal/business reliance.
    • Do not hide material uncertainty in disclaimer text.

Output

Use this compact format:

## Agentic Delegation Audit

### Verdict
PASS | NEEDS CONTROLS | BLOCK

### Why
[2-5 sentences]

### Delegated Authority
- Principal:
- Deployer/operator:
- Autonomy level:
- Systems/tools:
- Highest-risk action:

### Control Checklist
- Permission scope: adequate | weak | missing
- Human approval before external/legal/financial action: yes | partial | no
- User-readable logs: yes | partial | no
- Revocation/pause: yes | partial | no
- Prompt-injection/data-boundary controls: yes | partial | no
- Accountability owner: clear | partial | unclear

### Required Controls
- [control 1]
- [control 2]
- [control 3]

### Legal Reliance Gate
PASS | ESCALATE | BLOCK

### Next Step
[smallest practical next step]

Decision Rules

  • PASS: agent is draft-only or tightly approval-gated, logs are clear, permissions are scoped, and no material legal/client risk remains unmanaged.
  • NEEDS CONTROLS: agent may be useful, but missing controls prevent safe operational reliance.
  • BLOCK: agent can perform external, legal, financial, confidential, destructive, or privileged actions without adequate approval, logging, revocation, or accountability.

版本历史

  • 8e51264 当前 2026-07-31 02:33

同 Skill 集合

skills/agent-authority-charter-builder-arkadiy-miteiko/SKILL.md
skills/ai-audit-trail-larissa-meredith-flister/SKILL.md
skills/assignation-refere-recouvrement-creance-selim-brihi/SKILL.md
skills/canned-response-generator-anthropic/SKILL.md
skills/canned-responses-anthropic/SKILL.md
skills/code-security-review-openai/SKILL.md
skills/compliance-anthropic/SKILL.md
skills/contract-review-anthropic/SKILL.md
skills/contract-risk-analyzer-sneha-ganapavarapu/SKILL.md
skills/cookie-policy-generator-malik-taiar/SKILL.md
skills/court-of-bih-war-crimes-chamber-jeanne-sulzer/SKILL.md
skills/data-processing-agreement-art-28-gdpr-oliver-schmidt-prietz/SKILL.md
skills/decision-ownership-audit-adrian-lerer/SKILL.md
skills/disclosure-strategy-mapper-larissa-meredith-flister/SKILL.md
skills/docx-processing-lawvable/SKILL.md
skills/docx-processing-openai/SKILL.md
skills/docx-processing-superdoc/SKILL.md
skills/dpdpa-gdpr-compliance-review-parth-desai/SKILL.md
skills/dpdpa-gdpr-review-parth-desai/SKILL.md
skills/dpia-sentinel-oliver-schmidt-prietz/SKILL.md
skills/due-diligence-gate-adrian-lerer/SKILL.md
skills/eccc-khmer-rouge-tribunal-jeanne-sulzer/SKILL.md
skills/epistemic-fault-line-audit-adrian-lerer/SKILL.md
skills/eu-ai-act-examination-report-generator-oliver-schmidt-prietz/SKILL.md
skills/eu-ai-act-high-risk-classifier-oliver-schmidt-prietz/SKILL.md
skills/eu-ai-act-quick-assessment-oliver-schmidt-prietz/SKILL.md
skills/eu-ai-act-report-oliver-schmidt-prietz/SKILL.md
skills/eu-ai-act-role-determination-oliver-schmidt-prietz/SKILL.md
skills/eu-ai-act-roles-oliver-schmidt-prietz/SKILL.md
skills/eu-ai-act-triage-oliver-schmidt-prietz/SKILL.md
skills/eu-legislation-malik-taiar/SKILL.md
skills/excel-editor-openai/SKILL.md
skills/financial-comparison-glossary-adrian-lerer/SKILL.md
skills/french-text-proofreading-christophe-quezel-ambrunaz/SKILL.md
skills/icelandic-company-formation-magnus-smarason/SKILL.md
skills/icelandic-company-formation-magnus-smari-smarason/SKILL.md
skills/icelandic-contract-review-magnus-smarason/SKILL.md
skills/icelandic-contract-review-magnus-smari-smarason/SKILL.md
skills/icelandic-court-case-finder-magnus-smarason/SKILL.md
skills/icelandic-eea-gap-analysis-magnus-smarason/SKILL.md
skills/icelandic-eea-gap-analysis-magnus-smari-smarason/SKILL.md
skills/icelandic-labour-law-magnus-smarason/SKILL.md
skills/icelandic-labour-law-magnus-smari-smarason/SKILL.md
skills/icelandic-legal-terminology-magnus-smarason/SKILL.md
skills/icelandic-legal-terminology-magnus-smari-smarason/SKILL.md
skills/icelandic-privacy-review-magnus-smarason/SKILL.md
skills/icelandic-privacy-review-magnus-smari-smarason/SKILL.md
skills/icty-ictr-irmct-jeanne-sulzer/SKILL.md
skills/indian-dpdp-act-consent-notice-siddhi-kudalkar/SKILL.md

元信息

文件数
0
版本
8e51264
Hash
556bb94f
收录时间
2026-07-31 02:33

首页 - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-01 08:41
浙ICP备14020137号-1 $访客地图$