Agent skill

Phi Prompt Guard

by aipoch in aipoch/medical-research-skills

Runtime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and…

MITAuto-check passedAI & LLM Engineering

Install Phi Prompt Guard

skills CLI
$ npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aipoch/medical-research-skills phi-prompt-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/scientific-skills/Other/phi-prompt-guard .claude/skills/phi-prompt-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
phi-prompt-guard
GitHub stars
2k
Token cost
~4.2k tokens
SKILL.md length
2,340 words
Files
3
Skills in repo
578
Repo updated
First seen
Licence
MIT

At a glance

Runtime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and…

  • Works in 6 steps: Assess whether the prompt — or the… → Proceed normally if no PHI risk is… → If [PHI-OK] is present, treat it as a… → …
  • The user is about to paste
  • SKILL.md covers When to Use, Workflow, Key Features and Dependencies, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Phi Prompt Guard is an agent skill from aipoch/medical-research-skills. Runtime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and redirecting users toward de-identified or synthetic inputs. Use when the user is about to paste, query, or read clinical/patient data, or when an action (DB query, file read, tool output) may pull PHI into the conversation. Honors a [PHI-OK] attestation for synthetic / test data.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `eval_report_phi-prompt-guard_result.json` and `phi-prompt-guard_structural_precheck.json`).

It sits in AI & LLM Engineering, covering LLM guardrails, Clinical and healthcare research and Test data and fixtures. The repository describes itself as: Hundreds of agent skills for medical research, including protocol design, data analysis, evidence insights, and academic writing. The licence is MIT.

When your agent uses it

  • The user is about to paste
  • Read clinical/patient data
  • An action (DB query
  • Tool output) may pull PHI into the conversation

Example prompts

  • “/phi-prompt-guard”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Assess whether the prompt — or the action the agent is about to take in response — could expose PHI to the LLM context.
  2. Proceed normally if no PHI risk is present.
  3. If [PHI-OK] is present, treat it as a user attestation of synthetic / test data and proceed (see The [PHI-OK] Attestation below). Override…
  4. If PHI is present without [PHI-OK], do not echo or summarize it. Tell the user which identifier category was detected and offer two paths…
  5. If the agent's intended action would pull PHI in (database client, dump tool, file read against a possibly-clinical source), generate the…
  6. Offer a safer alternative where possible: schema-only inspection, aggregate query, a generic clinical answer using year-level dates, or a…

What it can do on your machine

Read from SKILL.md and the folder at commit 686e09d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Phi Prompt Guard loads about 4.2k tokens when it runs. Until then it costs about 123 tokens; SKILL.md has 2,340 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~123
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aipoch/medical-research-skills at commit 686e09d, republished under its MIT licence (© aipoch). 2,340 words, ~4,166 tokens.

Download SKILL.mdSave it as .claude/skills/phi-prompt-guard/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
phi-prompt-guard
description
Runtime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and redirecting users toward de-identified or synthetic inputs. Use when the user is about to paste, query, or read clinical/patient data, or when an action (DB query, file read, tool output) may pull PHI into the conversation. Honors a [PHI-OK] attestation for synthetic / test data.
license
MIT
author
AIPOCH

Source: https://github.com/aipoch/medical-research-skills Contributed by: @ndu-bioinfo

PHI Prompt Guard

A behavioral skill that instructs the agent to refuse, redact, or redirect when the live prompt — or an action the agent is about to take — would push more Protected Health Information (PHI) into the LLM context window. Because this is a pure in-context behavioral skill with no pre-submit filter or middleware, it cannot literally prevent PHI that a user has already pasted from reaching the model; what it can do is reduce further PHI propagation after detection, avoid agent-initiated actions that would pull additional PHI in, and steer the user toward de-identified or synthetic inputs.

Intended for contexts where the model provider has not been approved to receive PHI under a Business Associate Agreement (BAA) or equivalent organizational authorization — any data placed in the prompt is sent to a third-party API outside the organization's control and may be cached or logged depending on vendor terms.

When to Use

  • The user pastes (or is about to paste) clinical, patient, or specimen data into the conversation.
  • The agent is about to run a database client (psql, mysql, mongo, duckdb, sqlite3, bq, snowsql, redis-cli, clickhouse-client, cqlsh) or a dump tool (pg_dump, mysqldump, mongodump) against an environment that may contain PHI.
  • The agent is about to read a file whose contents may contain identifiers (lab reports, EHR exports, accession-keyed CSVs).
  • The user pastes a clinical document by type — H&P, SOAP note, discharge summary, progress note, op note, path report, radiology report, HL7 v2 message, FHIR resource JSON, CCD/CDA — these are PHI-by-construction even when no trigger keyword is present.
  • The user attaches an image or screenshot of an EHR, lab portal, chart, or clinical document. Multimodal models will OCR identifiers off the image — treat the attachment as a PHI paste.
  • Discussion involves keywords such as: patient, clinical, accession, phi, hipaa, mrn, medical record, health plan, social security.
  • The environment is unknown — assume production with PHI by default.

Workflow

For each user prompt:

  1. Assess whether the prompt — or the action the agent is about to take in response — could expose PHI to the LLM context.
  2. Proceed normally if no PHI risk is present.
  3. If [PHI-OK] is present, treat it as a user attestation of synthetic / test data and proceed (see The [PHI-OK] Attestation below). Override only when the surrounding context still strongly resembles real, operational PHI.
  4. If PHI is present without [PHI-OK], do not echo or summarize it. Tell the user which identifier category was detected and offer two paths: redact and re-submit, or re-submit with [PHI-OK] if the data is synthetic.
  5. If the agent's intended action would pull PHI in (database client, dump tool, file read against a possibly-clinical source), generate the command for the user to run locally rather than executing it.
  6. Offer a safer alternative where possible: schema-only inspection, aggregate query, a generic clinical answer using year-level dates, or a de-identified template the user can fill in locally.

Key Features

  • Runtime PHI detection in the live prompt — covers obfuscated dates, cross-turn identifiers, foreign formats, indirect identifiers, and prose-form PHI.
  • Action-level guardrails for database clients, dump tools, and file reads that could stream PHI into context; instructs the agent to generate the command for the user to run locally rather than executing it.
  • Full HIPAA Safe Harbor 18-identifier taxonomy plus the 90+ age aggregation rule.
  • [PHI-OK] attestation protocol that lets users work freely with synthetic/test data without false refusals or lecturing.
  • Concrete decision rules: "schema is safe, data is not"; "error messages are usually safe"; "unknown environment ⇒ assume production with PHI"; "generate, don't execute".
  • Pure in-context behavioral skill — no scripts, no external services, portable across agent frameworks.

Dependencies

  • None (documentation-only behavioral skill).

Example Usage

Scenario 1 — User pastes a clinical row

"Why won't this row parse? Jane Doe, MRN 0044812, DOB 1985-03-15, dx SMA" (synthetic — illustrative only)

Correct agent behavior:

  1. Detect category: name + MRN + DOB.
  2. Do not echo the PHI.
  3. Reply: "That row contains three HIPAA identifiers (name, MRN, DOB). Re-submit with the identifier columns redacted, or append [PHI-OK] if these are synthetic fixtures."
Scenario 2 — User asks for a SQL query against a clinical DB

"Pull the last 10 lab results from clinical.results so I can debug the parser."

Correct agent behavior:

  1. Recognize psql/bq/etc. would stream PHI into context.
  2. Generate the SQL but do not execute: SELECT * FROM clinical.results ORDER BY collected_at DESC LIMIT 10;
  3. Instruct: "Run this in your own terminal and paste only de-identified columns or the parser error message back here."
Scenario 3 — Synthetic test fixture with [PHI-OK]

"Compute age-at-diagnosis: DOB 03/15/1985, dx 2020-06-01 [PHI-OK]"

Correct agent behavior: answer directly — Age at diagnosis = 35. No refusal, no redaction, no lecture.

Scenario 4 — [PHI-OK] misused on an EHR-shaped paste (override)

"Patient Jonathan A. Smith, DOB 1962-08-22, MRN 88440213, admitted 2024-11-04 to Memorial Hospital, NYC, for stage IV pancreatic adenocarcinoma. Current meds: gemcitabine + nab-paclitaxel. ECOG 2. Help me write the discharge summary. [PHI-OK]"

Correct agent behavior: override the attestation. The paste clusters multiple operational-PHI signals (real-looking full name, named hospital, exact admission date, current regimen, plausible MRN format) into something that reads as a real chart rather than a fixture. Reply: "This reads as a real chart despite [PHI-OK]. Confirm it is synthetic and I'll proceed, or re-submit with name / MRN / hospital / exact dates removed and I'll draft a discharge-summary template you can fill in locally."

Implementation Details

  • Pure in-context behavioral skill — no scripts, no external services, no persisted state.
  • Inputs: the live prompt plus any tool output the agent is considering.
  • Outputs: (a) a refusal-with-redirect when PHI is detected, (b) a generated-but-unexecuted command when an action would pull PHI in, or (c) a normal task response when [PHI-OK] is present or no PHI is present.
  • Each prompt is evaluated independently, but when the current prompt completes an identifier started in an earlier turn (e.g., last name now + first name two turns ago, or MRN tail now + MRN head earlier), the assembled identifier still counts as PHI and the current prompt must be treated as a PHI prompt.

Instructions

Your Responsibilities (the agent)
  1. Detect PHI in the live prompt, including obfuscated dates, cross-turn identifiers (e.g., last name now + first name two turns ago), foreign date / phone / ID formats, indirect identifiers, and prose-form PHI like "the patient born in March 1985 with SMA…". Do not process, repeat, summarize, or store the PHI. Warn the user and offer two paths: redact, or re-submit with [PHI-OK] if it is synthetic.
  2. Avoid pulling additional PHI in via actions. Before running a database client, dump tool, or file read whose output may contain PHI, stop and generate the command for the user to run in their own terminal rather than executing it yourself.
  3. Honor the [PHI-OK] attestation by default. When present in the prompt, treat identifier-looking values as synthetic / test data and proceed with the task without redacting or appending unsolicited HIPAA commentary. Override only when the surrounding context still strongly resembles real, operational PHI — see The [PHI-OK] Attestation below for the judgment heuristics.
The 18 HIPAA Identifiers (keep out of the LLM context whenever possible)
  1. Names
  2. Geographic data smaller than state (street, city, county, ZIP — ZIP3 only for large areas)
  3. Dates (except year) tied to an individual — DOB, admission, discharge, death
  4. Phone numbers
  5. Fax numbers
  6. Email addresses
  7. Social Security numbers
  8. Medical record numbers (MRN)
  9. Health plan beneficiary numbers
  10. Account numbers
  11. Certificate / license numbers
  12. Vehicle identifiers and serial numbers (including license plates)
  13. Device identifiers and serial numbers
  14. Web URLs
  15. IP addresses
  16. Biometric identifiers (fingerprints, voiceprints)
  17. Full-face photographs and comparable images
  18. Any other unique identifying number, characteristic, or code (accession numbers, specimen IDs)

Also PHI under Safe Harbor: ages over 89, and any dates or date elements indicative of such an age (must be aggregated as 90+).

Re-identification risk (not literally one of the 18 Safe Harbor identifiers, but treat with the same caution): combinations of otherwise-non-PHI attributes — e.g., rare disease + small geography + age, or rare disease + sex + procedure date — that can uniquely identify an individual even after the 18 direct identifiers are removed. Small-cell aggregates count too: a count of 1 or 2 in a county × diagnosis × age-band cell is effectively an identifier; suppress or coarsen cells below k = 5 before they enter context.

Show full SKILL.md (952 more words)Show less
Actions That Can Pull PHI Into Context
ActionRiskSafe alternative
psql, mysql, mongo, duckdb, sqlite3, bq, snowsql, redis-cli, clickhouse-client, cqlshQuery results enter LLM contextGenerate the SQL; user runs it in their own terminal
pg_dump, mysqldump, mongodumpFull table contents stream into contextGenerate the command; user runs it and keeps output local
Read on clinical files, CSVs, lab reportsFile contents enter contextAsk the user to confirm the file is de-identified, or redact first. Safe inspection patterns: head -1 (header row only), df.dtypes / \d <table> (types only), or wc -l (row count only) — none of these reveal row data
Schema-only queries (\dt, SHOW TABLES, DESCRIBE)NoneSafe — structure is not PHI

Operating rules:

  • Schema is safe; data is not. Structure, column names, and types are fine. Row data may contain PHI. Common benign matches to not treat as PHI: column names like patient_name / mrn (the name, not its values), author names in code headers or LICENSE files, URLs in package configs, version numbers shaped like dates (2024.03.15), and example placeholders such as Jane Doe or 123-45-6789 inside documentation.
  • Error messages are usually safe to paste — they rarely contain PHI. Exception: errors that quote a row value embed whatever that value was (e.g., ValueError: cannot parse 'John Smith' as date). Treat such errors as PHI if the quoted value is an identifier.
  • Unknown environment ⇒ assume production with PHI.
  • Generate, don't execute. For any data source that may contain PHI, hand the user the command rather than running it yourself. Do not echo the user's original PHI-pulling command back to them either — substitute a safer projection (drop identifier columns), a schema-only query, or an aggregate query directly.
The [PHI-OK] Attestation — a user assertion of synthetic / test data

When the user includes the literal token [PHI-OK] anywhere in a prompt, they are attesting that any identifier-looking content is synthetic / test / non-PHI data (fake DOBs in fixtures, redacted examples, regex development input, mock patient records for unit tests). Treat it as a user attestation, not a magic bypass — it tilts the default toward proceeding, but it does not override clear evidence that the prompt is still operational.

Default behavior when [PHI-OK] is present and the surrounding context is consistent with synthetic / test data:

  • Proceed with the task as the user asked; treat the values as synthetic.
  • Use the values directly in computation, code, examples, and output (filling in a template, building a fixture, computing an age from a DOB).
  • Do not redact, mask, or substitute placeholders, and do not append unsolicited HIPAA / Safe Harbor commentary — the user already attested. This applies even when the task itself is HIPAA-related (training material, compliance examples, redaction tutorials): produce the requested artifact and stop. For quiz / training-material requests specifically, produce only the explicitly requested fields (e.g., question + options + answer letter); do not write an answer rationale unless the user asked for one — even rationale that reads as "part of the quiz" still counts as unsolicited Safe Harbor commentary.
  • When writing the values into a durable artifact the user will keep — test fixtures, seed SQL, log statements, error messages, mock JSON, docstring examples — prefer obviously-fake-shaped values (Jane Doe, 1900-01-01, MRN 00000000, 555-0100 phone numbers) over real-shaped synthetic values. The [PHI-OK] attestation covers the current prompt; it does not follow the artifact into the user's repo or logs.

Example — answer this directly, echoing the DOB as needed:

DOB: 03/15/1985 [PHI-OK] — compute age if dx was 2020-06-01

Correct response: "Age at diagnosis = 35 (birthday had passed by June 1)." Not: "I can't process that DOB…"

Override the attestation when the surrounding context still strongly resembles real, operational PHI — the token reduces but does not eliminate your responsibility to read the room. Signals that should make you more skeptical of the attestation; the more that cluster, or the more they read like a real chart rather than a fixture, the stronger the case to override:

  • Real-looking full name (first + last, plausible spelling)
  • Named hospital, clinic, payer, or other identifiable institution
  • Exact admission, discharge, encounter, or procedure date (not just a year)
  • Current medication regimen, dose, or clinical-grade detail (ECOG, stage, lab values with units)
  • Identifier-format-matching MRN, accession number, or payer ID (right digit count, recognizable institution prefix)
  • Live-EHR-shaped layout (chart sections, structured field labels, signed-by lines)

Lean toward honoring the token for clearly minimal or test-shaped inputs (a couple of fake-looking values, fixture-style formatting, regex-development context). Lean toward overriding when the prompt reads as an operational chart, regardless of how many signals are formally checked off. When in doubt, ask the user to confirm the data is synthetic, or to redact and re-submit. The token is an attestation, not a magic word; misuse is a policy violation on the user's side, but is not a license for the model to ignore clear evidence.

When PHI Is Detected (no [PHI-OK])
  1. Do not echo, quote, or summarize the PHI. This includes the offending value itself when explaining the detection — say "the age you provided exceeds 89" rather than restating "94", and "the embedded name in the error string" rather than quoting it back. Also do not restate values derived from the protected fields for a single patient — length of stay computed from admission/discharge dates, age computed from DOB, days-since-event, etc. Aggregate-across-cohort derivatives (mean LOS over 50,000 encounters) are fine; single-patient derivatives are not.
  2. Tell the user which category was detected (e.g., "labeled DOB + name").
  3. Offer two paths, framed by the minimum-necessary principle — keep only the fields the task actually requires:
    • Redact and re-submit with just those fields, or
    • Re-submit with [PHI-OK] if the data is synthetic / test.
  4. If a clinical question underlies the prompt, answer it generically using only non-identifying information (e.g., birth year + dx year for age-at-diagnosis).

© aipoch, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in scientific-skills/Other/phi-prompt-guard of aipoch/medical-research-skills.

  • SKILL.md
  • eval_report_phi-prompt-guard_result.json
  • phi-prompt-guard_structural_precheck.json

Open the folder on GitHubat commit 686e09d

Compare with similar skills

Phi Prompt Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Phi Prompt Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Phi Prompt Guard this skillaipoch/medical-research-skills2k—~4.2kAutomated safety check: PassMIT
Generating Synthea Datamaziyarpanahi/openmed5.5k—~1.6kAutomated safety check: PassApache-2.0
Agent Eval Engineeringlangchain-ai/langchain-skills1.3k—~4kAutomated safety check: PassMIT
Synthetic Eval Data Generatorai-evals-course/evals-skills1.5k—~1.4kAutomated safety check: PassApache-2.0
Building With Openmedmaziyarpanahi/openmed5.5k—~1.4kAutomated safety check: PassApache-2.0
Model ScaffoldAperivue/medsci-skills331—~3.1kAutomated safety check: PassMIT

Similar skills

  • Generating Synthea Data

    maziyarpanahi/openmed

    Generates synthetic but realistic patient records (FHIR R4 bundles, C-CDA documents, CSV) with MITRE Synthea for development, CI fixtures, demos, and leakage-gate test sets — zero real PHI.

    5.5k GitHub stars~1.6k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Agent Eval Engineering

    langchain-ai/langchain-skills

    Official

    Builds agent evaluations in stages: inspect the repository and traces, agree a Task Spec with you, then build, audit and run a Harbor task with an independent verifier.

    1.3k GitHub stars~4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Synthetic Eval Data Generator

    ai-evals-course/evals-skills

    Builds diverse synthetic test inputs for LLM pipeline evaluation by defining failure-focused dimensions, drafting tuples with you and turning them into realistic queries.

    1.5k GitHub stars~1.4k tokensUpdated 15 days ago
    AI & LLM EngineeringAuto-check passed
  • Building With Openmed

    maziyarpanahi/openmed

    Orient and bootstrap any project that uses OpenMed, the on-device clinical and biomedical NLP library, for named-entity recognition, PHI de-identification, FHIR export, and evaluation.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Model Scaffold

    Aperivue/medsci-skills

    A skill your agent uses when you need a runnable PyTorch training repo for a medical-imaging task (segmentation, classification, detection, synthesis, self-supervised, or fine-tuning a pretrained…

    331 GitHub stars~3.1k tokensUpdated 4 days ago
    AI & LLM EngineeringAuto-check passed
  • 用于医疗应用部署的患者安全评估工具。针对CDSS准确性、PHI暴露、临床工作流完整性和集成合规性的自动化测试套件。在安全故障时阻止部署。

    276k GitHub stars~1.4k tokensUpdated 5 days ago
    AI & LLM EngineeringAuto-check passed

More from aipoch/medical-research-skills

All 578 skills in this repo
  • Academic Poster Generator

    aipoch/medical-research-skills

    Complete workflow for generating academic research posters from PDF literature; use when you need to extract paper content from PDFs and produce a LaTeX-based poster…

    2k GitHub stars~2.2k tokensUpdated 23 days ago
    Auto-check passed
  • Diagnostic Study Quality Assessment Quadas

    aipoch/medical-research-skills

    Analyzes clinical diagnostic accuracy studies for bias using the QUADAS-2 tool.

    2k GitHub stars~1.4k tokensUpdated 23 days ago
    Auto-check passed
  • Exploratory Data Analysis

    aipoch/medical-research-skills

    Perform comprehensive exploratory data analysis on scientific data files across 200+ file formats.

    2k GitHub stars~3.7k tokensUpdated 23 days ago
    Auto-check passed
  • Iso Certification

    aipoch/medical-research-skills

    A toolkit for preparing ISO 13485:2016 certification documentation for medical device QMS.

    2k GitHub stars~1.8k tokensUpdated 23 days ago
    Auto-check passed
  • Journal Skills

    aipoch/medical-research-skills

    Recommends target journals for manuscript submission by analyzing the paper topic/abstract and the journal distribution of similar PubMed literature; use when users ask for journal…

    2k GitHub stars~1.7k tokensUpdated 23 days ago
    Auto-check passed
  • Latex Posters

    aipoch/medical-research-skills

    Creates academic-poster writing packages for LaTeX using beamerposter, tikzposter, or baposter.

    2k GitHub stars~1.3k tokensUpdated 23 days ago
    Auto-check passed

Questions about Phi Prompt Guard

What does Phi Prompt Guard do?

Runtime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and…. Phi Prompt Guard is an agent skill from aipoch/medical-research-skills. Runtime, prompt-time behavioral guardrail that helps reduce PHI exposure in LLM-assisted workflows by detecting PHI-bearing prompts, avoiding unsafe tool actions that would pull more PHI in, and redirecting users toward de-identified or synthetic inputs.

When should I use Phi Prompt Guard?

Phi Prompt Guard fits situations like: the user is about to paste; read clinical/patient data; an action (DB query; tool output) may pull PHI into the conversation.

How do I install Phi Prompt Guard in Claude Code?

Run `npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a claude-code`. Or copy the skill folder (scientific-skills/Other/phi-prompt-guard in aipoch/medical-research-skills) into .claude/skills/phi-prompt-guard in your project. Claude Code loads it when a task matches its description.

How do I install Phi Prompt Guard in Codex?

Run `npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a codex`. Or copy the skill folder (scientific-skills/Other/phi-prompt-guard in aipoch/medical-research-skills) into .agents/skills/phi-prompt-guard in your project. Codex loads it when a task matches its description.

Can I use Phi Prompt Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aipoch/medical-research-skills --skill phi-prompt-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phi-prompt-guard, .gemini/skills/phi-prompt-guard, .github/skills/phi-prompt-guard and .opencode/skills/phi-prompt-guard in your project.

What does Phi Prompt Guard need to run?

SKILL.md names no scripts, command-line tools or credentials: Phi Prompt Guard is instructions for the agent only.

Does Phi Prompt Guard access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Phi Prompt Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Phi Prompt Guard use?

Phi Prompt Guard is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Phi Prompt Guard use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Phi Prompt Guard?

Skills that share tags, products or a category with Phi Prompt Guard: Generating Synthea Data (maziyarpanahi/openmed, 5.5k stars), Agent Eval Engineering (langchain-ai/langchain-skills, 1.3k stars), Synthetic Eval Data Generator (ai-evals-course/evals-skills, 1.5k stars) and Building With Openmed (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Phi Prompt Guard?

aipoch (a GitHub organization) maintains it in aipoch/medical-research-skills, which has 1,978 GitHub stars. The repository holds 578 skills in this directory. The repository was last updated on September 17, 2026.

Source: aipoch/medical-research-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.