Verified against Claude · 2026-07-22
Audit a full contract for risk using Claude's whole context window, not a skim
A long-context prompt that forces a clause-by-clause, quote-grounded risk audit of an entire pasted contract or policy document, ranked by severity and tied to one party's actual position, instead of a general summary of what the document is about.
The prompt
Ready to copy — highlighted parts are example details you can swap.
You have the complete document below, not an excerpt — read all of it before producing anything. This is a risk audit, not a summary: the deliverable is a list of specific risks tied to specific clauses, not a paragraph describing what the document is generally about. CONTRACT TYPE SaaS vendor master services agreement, 3-year term WHOSE INTEREST YOU ARE AUDITING FOR We are the customer (buyer), a 40-person startup with no in-house legal counsel reviewing this before signature. Every risk you flag should be evaluated from this party's position specifically — a clause that is a reasonable risk allocation for the other party is still a risk for this one if it shifts exposure onto them. RISK CATEGORIES TO CHECK, AT MINIMUM Termination and exit rights, liability caps and indemnification, data ownership and deletion on termination, auto-renewal and price-increase mechanics, SLA remedies. Do not stop at these if the document contains a clear risk outside this list — add it, clearly labeled as outside the requested categories so it is not mistaken for one you were specifically asked to check. DEAL CONTEXT This vendor is replacing a tool we're actively migrating off of under time pressure, so a long termination notice period matters more than usual. WHAT TO PRODUCE, FOR EACH RISK FOUND 1. The exact clause or section reference, quoted directly, not paraphrased — a risk audit built on a paraphrase cannot be checked against the real document without redoing the work. 2. A one-line statement of what the risk actually is, in plain language a non-lawyer on We are the customer (buyer), a 40-person startup with no in-house legal counsel reviewing this before signature.'s side could act on. 3. A severity label — high, medium, or low — with one sentence justifying the label against the actual exposure (dollar amount, timeline, or irreversibility), not a vibe-based rating. 4. If a reasonable mitigation or redline exists, name it in one sentence; if none does, say explicitly that this risk is likely accepted as-is rather than leaving the reader to assume a fix exists that was never stated. AFTER THE PER-RISK LIST - A short section naming any place two clauses in the document conflict with or partially undermine each other — name both by section number, do not silently resolve the conflict into one smooth reading. - A short section naming anything the document is silent on that a document of this type would normally address, since an omission can itself be the risk. CONSTRAINTS - Every quote must be exact, not a close paraphrase presented as a quote. - Do not import risk assumptions from how this type of contract usually reads in general — ground every finding in what this specific document actually says. If you note that a clause is unusually favorable or unfavorable compared to typical terms for this contract type, label that comparison explicitly as general knowledge, separate from the document-grounded findings. - Rank the per-risk list by severity, highest first, not by the order clauses appear in the document — a reader triaging risk should see the worst thing first. DOCUMENT [Full 22-page MSA text pasted here]
Customize
Optional — swap in your own details for the highlighted parts above.
Why this works
Claude's long context window is long enough to hold an entire contract at once, but an unstructured 'find the risks' ask still invites a recency and salience bias in long-document synthesis — the model weights what it read most recently or most memorably, which for a 22-page agreement means the termination and boilerplate sections near the end can get shortchanged relative to the definitions and payment terms up front. Forcing structured, per-clause output with an exact quote, a severity label, and a stated justification converts 'did you actually check every section' into something checkable against the source: a quote either exists in the document at that location or it doesn't, which is a much harder thing to fake convincingly than a paraphrased summary. Naming the requesting party's position explicitly matters because the same clause is a risk for one side and a non-issue for the other — an indemnification cap is protective for the vendor and exposure for the customer — and a neutral 'audit this contract' framing gives the model no signal for which lens to apply, so it defaults to whichever reading is more common in its training data for this contract type, which is not necessarily the reading that matches the actual party asking. Requiring the model to name material risks outside the given category list, clearly labeled as such, guards against the specific over-literal-instruction-following failure current Claude models exhibit where a checklist gets treated as exhaustive rather than a floor — without this instruction, a genuinely serious risk sitting just outside the five named categories can go completely unmentioned simply because it wasn't on the list. Separating 'general knowledge about how this contract type usually reads' from 'document-grounded finding' addresses a real contamination risk: because contracts of a given type follow known patterns, an unconstrained model can blend 'this looks like the standard indemnification clause' — a prior — with 'this document's indemnification clause actually says X' — a grounded fact — into one confident-sounding sentence, and a reader has no way to tell which kind of claim they're reading without that label attached.
Verified against
Claude Opus 4.6 (1M context) · 2026-07-22
Changelog
- 2026-07-22 — Initial publish, verified against Claude Opus 4.6 with a 22-page test contract.
Building this for real?
This is a free starting point. If you'd rather have what Scult builds built and running for your business, that's Scult's day job.
EXPLORE WHAT SCULT BUILDS
