Generating Synthea Data
maziyarpanahi/openmed
Generates synthetic but realistic patient records (FHIR R4 bundles, C-CDA documents, CSV) with MITRE Synthea for development, CI fixtures, demos, and leakage-gate test sets — zero real PHI.
Runtime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and…
$ npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aipoch/medical-research-skills phi-prompt-guard --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/scientific-skills/Other/phi-prompt-guard .claude/skills/phi-prompt-guard && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "phi-prompt-guard" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Other/phi-prompt-guard into .claude/skills/phi-prompt-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phi-prompt-guard", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Other/phi-prompt-guardType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aipoch/medical-research-skills phi-prompt-guard --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/scientific-skills/Other/phi-prompt-guard .agents/skills/phi-prompt-guard && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "phi-prompt-guard" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Other/phi-prompt-guard into .agents/skills/phi-prompt-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phi-prompt-guard", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aipoch/medical-research-skills phi-prompt-guard --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/scientific-skills/Other/phi-prompt-guard .cursor/skills/phi-prompt-guard && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "phi-prompt-guard" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Other/phi-prompt-guard into .cursor/skills/phi-prompt-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phi-prompt-guard", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aipoch/medical-research-skills.git --path scientific-skills/Other/phi-prompt-guard--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aipoch/medical-research-skills phi-prompt-guard --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/scientific-skills/Other/phi-prompt-guard .gemini/skills/phi-prompt-guard && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "phi-prompt-guard" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Other/phi-prompt-guard into .gemini/skills/phi-prompt-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phi-prompt-guard", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aipoch/medical-research-skills phi-prompt-guardInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/scientific-skills/Other/phi-prompt-guard .github/skills/phi-prompt-guard && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "phi-prompt-guard" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Other/phi-prompt-guard into .github/skills/phi-prompt-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phi-prompt-guard", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aipoch/medical-research-skills phi-prompt-guard --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/scientific-skills/Other/phi-prompt-guard .opencode/skills/phi-prompt-guard && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "phi-prompt-guard" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Other/phi-prompt-guard into .opencode/skills/phi-prompt-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phi-prompt-guard", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
phi-prompt-guardRuntime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and…
Phi Prompt Guard is an agent skill from aipoch/medical-research-skills. Runtime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and redirecting users toward de-identified or synthetic inputs. Use when the user is about to paste, query, or read clinical/patient data, or when an action (DB query, file read, tool output) may pull PHI into the conversation. Honors a [PHI-OK] attestation for synthetic / test data.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `eval_report_phi-prompt-guard_result.json` and `phi-prompt-guard_structural_precheck.json`).
It sits in AI & LLM Engineering, covering LLM guardrails, Clinical and healthcare research and Test data and fixtures. The repository describes itself as: Hundreds of agent skills for medical research, including protocol design, data analysis, evidence insights, and academic writing. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 686e09d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Phi Prompt Guard loads about 4.2k tokens when it runs. Until then it costs about 123 tokens; SKILL.md has 2,340 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aipoch/medical-research-skills at commit 686e09d, republished under its MIT licence (© aipoch). 2,340 words, ~4,166 tokens.
.claude/skills/phi-prompt-guard/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Source: https://github.com/aipoch/medical-research-skills Contributed by: @ndu-bioinfo
A behavioral skill that instructs the agent to refuse, redact, or redirect when the live prompt — or an action the agent is about to take — would push more Protected Health Information (PHI) into the LLM context window. Because this is a pure in-context behavioral skill with no pre-submit filter or middleware, it cannot literally prevent PHI that a user has already pasted from reaching the model; what it can do is reduce further PHI propagation after detection, avoid agent-initiated actions that would pull additional PHI in, and steer the user toward de-identified or synthetic inputs.
Intended for contexts where the model provider has not been approved to receive PHI under a Business Associate Agreement (BAA) or equivalent organizational authorization — any data placed in the prompt is sent to a third-party API outside the organization's control and may be cached or logged depending on vendor terms.
psql, mysql, mongo, duckdb, sqlite3, bq, snowsql, redis-cli, clickhouse-client, cqlsh) or a dump tool (pg_dump, mysqldump, mongodump) against an environment that may contain PHI.patient, clinical, accession, phi, hipaa, mrn, medical record, health plan, social security.For each user prompt:
[PHI-OK] is present, treat it as a user attestation of synthetic / test data and proceed (see The [PHI-OK] Attestation below). Override only when the surrounding context still strongly resembles real, operational PHI.[PHI-OK], do not echo or summarize it. Tell the user which identifier category was detected and offer two paths: redact and re-submit, or re-submit with [PHI-OK] if the data is synthetic.[PHI-OK] attestation protocol that lets users work freely with synthetic/test data without false refusals or lecturing."Why won't this row parse?
Jane Doe, MRN 0044812, DOB 1985-03-15, dx SMA" (synthetic — illustrative only)
Correct agent behavior:
[PHI-OK] if these are synthetic fixtures.""Pull the last 10 lab results from
clinical.resultsso I can debug the parser."
Correct agent behavior:
psql/bq/etc. would stream PHI into context.SELECT * FROM clinical.results ORDER BY collected_at DESC LIMIT 10;[PHI-OK]"Compute age-at-diagnosis: DOB 03/15/1985, dx 2020-06-01 [PHI-OK]"
Correct agent behavior: answer directly — Age at diagnosis = 35. No refusal, no redaction, no lecture.
[PHI-OK] misused on an EHR-shaped paste (override)"Patient Jonathan A. Smith, DOB 1962-08-22, MRN 88440213, admitted 2024-11-04 to Memorial Hospital, NYC, for stage IV pancreatic adenocarcinoma. Current meds: gemcitabine + nab-paclitaxel. ECOG 2. Help me write the discharge summary. [PHI-OK]"
Correct agent behavior: override the attestation. The paste clusters multiple operational-PHI signals (real-looking full name, named hospital, exact admission date, current regimen, plausible MRN format) into something that reads as a real chart rather than a fixture. Reply: "This reads as a real chart despite [PHI-OK]. Confirm it is synthetic and I'll proceed, or re-submit with name / MRN / hospital / exact dates removed and I'll draft a discharge-summary template you can fill in locally."
[PHI-OK] is present or no PHI is present.[PHI-OK] if it is synthetic.[PHI-OK] attestation by default. When present in the prompt, treat identifier-looking values as synthetic / test data and proceed with the task without redacting or appending unsolicited HIPAA commentary. Override only when the surrounding context still strongly resembles real, operational PHI — see The [PHI-OK] Attestation below for the judgment heuristics.Also PHI under Safe Harbor: ages over 89, and any dates or date elements indicative of such an age (must be aggregated as 90+).
Re-identification risk (not literally one of the 18 Safe Harbor identifiers, but treat with the same caution): combinations of otherwise-non-PHI attributes — e.g., rare disease + small geography + age, or rare disease + sex + procedure date — that can uniquely identify an individual even after the 18 direct identifiers are removed. Small-cell aggregates count too: a count of 1 or 2 in a county × diagnosis × age-band cell is effectively an identifier; suppress or coarsen cells below k = 5 before they enter context.
| Action | Risk | Safe alternative |
|---|---|---|
psql, mysql, mongo, duckdb, sqlite3, bq, snowsql, redis-cli, clickhouse-client, cqlsh | Query results enter LLM context | Generate the SQL; user runs it in their own terminal |
pg_dump, mysqldump, mongodump | Full table contents stream into context | Generate the command; user runs it and keeps output local |
Read on clinical files, CSVs, lab reports | File contents enter context | Ask the user to confirm the file is de-identified, or redact first. Safe inspection patterns: head -1 (header row only), df.dtypes / \d <table> (types only), or wc -l (row count only) — none of these reveal row data |
Schema-only queries (\dt, SHOW TABLES, DESCRIBE) | None | Safe — structure is not PHI |
Operating rules:
patient_name / mrn (the name, not its values), author names in code headers or LICENSE files, URLs in package configs, version numbers shaped like dates (2024.03.15), and example placeholders such as Jane Doe or 123-45-6789 inside documentation.ValueError: cannot parse 'John Smith' as date). Treat such errors as PHI if the quoted value is an identifier.[PHI-OK] Attestation — a user assertion of synthetic / test dataWhen the user includes the literal token [PHI-OK] anywhere in a prompt, they are attesting that any identifier-looking content is synthetic / test / non-PHI data (fake DOBs in fixtures, redacted examples, regex development input, mock patient records for unit tests). Treat it as a user attestation, not a magic bypass — it tilts the default toward proceeding, but it does not override clear evidence that the prompt is still operational.
Default behavior when [PHI-OK] is present and the surrounding context is consistent with synthetic / test data:
Jane Doe, 1900-01-01, MRN 00000000, 555-0100 phone numbers) over real-shaped synthetic values. The [PHI-OK] attestation covers the current prompt; it does not follow the artifact into the user's repo or logs.Example — answer this directly, echoing the DOB as needed:
DOB: 03/15/1985 [PHI-OK] — compute age if dx was 2020-06-01
Correct response: "Age at diagnosis = 35 (birthday had passed by June 1)." Not: "I can't process that DOB…"
Override the attestation when the surrounding context still strongly resembles real, operational PHI — the token reduces but does not eliminate your responsibility to read the room. Signals that should make you more skeptical of the attestation; the more that cluster, or the more they read like a real chart rather than a fixture, the stronger the case to override:
Lean toward honoring the token for clearly minimal or test-shaped inputs (a couple of fake-looking values, fixture-style formatting, regex-development context). Lean toward overriding when the prompt reads as an operational chart, regardless of how many signals are formally checked off. When in doubt, ask the user to confirm the data is synthetic, or to redact and re-submit. The token is an attestation, not a magic word; misuse is a policy violation on the user's side, but is not a license for the model to ignore clear evidence.
[PHI-OK])[PHI-OK] if the data is synthetic / test.© aipoch, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files in scientific-skills/Other/phi-prompt-guard of aipoch/medical-research-skills.
Open the folder on GitHubat commit 686e09d
Phi Prompt Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Phi Prompt Guard this skillaipoch/medical-research-skills | 2k | — | ~4.2k | Automated safety check: Pass | MIT | |
| Generating Synthea Datamaziyarpanahi/openmed | 5.5k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Agent Eval Engineeringlangchain-ai/langchain-skills | 1.3k | — | ~4k | Automated safety check: Pass | MIT | |
| Synthetic Eval Data Generatorai-evals-course/evals-skills | 1.5k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Building With Openmedmaziyarpanahi/openmed | 5.5k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Model ScaffoldAperivue/medsci-skills | 331 | — | ~3.1k | Automated safety check: Pass | MIT |
maziyarpanahi/openmed
Generates synthetic but realistic patient records (FHIR R4 bundles, C-CDA documents, CSV) with MITRE Synthea for development, CI fixtures, demos, and leakage-gate test sets — zero real PHI.
langchain-ai/langchain-skills
Builds agent evaluations in stages: inspect the repository and traces, agree a Task Spec with you, then build, audit and run a Harbor task with an independent verifier.
ai-evals-course/evals-skills
Builds diverse synthetic test inputs for LLM pipeline evaluation by defining failure-focused dimensions, drafting tuples with you and turning them into realistic queries.
maziyarpanahi/openmed
Orient and bootstrap any project that uses OpenMed, the on-device clinical and biomedical NLP library, for named-entity recognition, PHI de-identification, FHIR export, and evaluation.
Aperivue/medsci-skills
A skill your agent uses when you need a runnable PyTorch training repo for a medical-imaging task (segmentation, classification, detection, synthesis, self-supervised, or fine-tuning a pretrained…
affaan-m/ECC
用于医疗应用部署的患者安全评估工具。针对CDSS准确性、PHI暴露、临床工作流完整性和集成合规性的自动化测试套件。在安全故障时阻止部署。
aipoch/medical-research-skills
Complete workflow for generating academic research posters from PDF literature; use when you need to extract paper content from PDFs and produce a LaTeX-based poster…
aipoch/medical-research-skills
Analyzes clinical diagnostic accuracy studies for bias using the QUADAS-2 tool.
aipoch/medical-research-skills
Perform comprehensive exploratory data analysis on scientific data files across 200+ file formats.
aipoch/medical-research-skills
A toolkit for preparing ISO 13485:2016 certification documentation for medical device QMS.
aipoch/medical-research-skills
Recommends target journals for manuscript submission by analyzing the paper topic/abstract and the journal distribution of similar PubMed literature; use when users ask for journal…
aipoch/medical-research-skills
Creates academic-poster writing packages for LaTeX using beamerposter, tikzposter, or baposter.
Runtime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and…. Phi Prompt Guard is an agent skill from aipoch/medical-research-skills. Runtime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and redirecting users toward de-identified or synthetic inputs.
Phi Prompt Guard fits situations like: the user is about to paste; read clinical/patient data; an action (DB query; tool output) may pull PHI into the conversation.
Run `npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a claude-code`. Or copy the skill folder (scientific-skills/Other/phi-prompt-guard in aipoch/medical-research-skills) into .claude/skills/phi-prompt-guard in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a codex`. Or copy the skill folder (scientific-skills/Other/phi-prompt-guard in aipoch/medical-research-skills) into .agents/skills/phi-prompt-guard in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phi-prompt-guard, .gemini/skills/phi-prompt-guard, .github/skills/phi-prompt-guard and .opencode/skills/phi-prompt-guard in your project.
SKILL.md names no scripts, command-line tools or credentials: Phi Prompt Guard is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Phi Prompt Guard is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Phi Prompt Guard: Generating Synthea Data (maziyarpanahi/openmed, 5.5k stars), Agent Eval Engineering (langchain-ai/langchain-skills, 1.3k stars), Synthetic Eval Data Generator (ai-evals-course/evals-skills, 1.5k stars) and Building With Openmed (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aipoch (a GitHub organization) maintains it in aipoch/medical-research-skills, which has 1,978 GitHub stars. The repository holds 578 skills in this directory. The repository was last updated on September 17, 2026.
Source: aipoch/medical-research-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.