HIPAA Safe Harbor Coverage Audit
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
公开 workflow:创建、修改或迁移项目拥有的 Agent Skill package,或对现有/外部 package 做用户明确要求、零执行的只读验证与 readiness 报告时使用;也用于按已接受的 audit finding 修复 source skill。不要用于一次性回答、解释/总结/翻译、普通代码 review、第三方 Skill 纯安装或导入、跨仓批量修改,或直接修补…
$ npx skills add leo-kuang-ai/spec-first --skill spec-write-skill -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install leo-kuang-ai/spec-first spec-write-skill --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/leo-kuang-ai/spec-first.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spec-write-skill .claude/skills/spec-write-skill && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "spec-write-skill" agent skill from https://github.com/leo-kuang-ai/spec-first/tree/master/skills/spec-write-skill into .claude/skills/spec-write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spec-write-skill", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/leo-kuang-ai/spec-first/tree/master/skills/spec-write-skillType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add leo-kuang-ai/spec-first --skill spec-write-skill -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install leo-kuang-ai/spec-first spec-write-skill --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/leo-kuang-ai/spec-first.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/spec-write-skill .agents/skills/spec-write-skill && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "spec-write-skill" agent skill from https://github.com/leo-kuang-ai/spec-first/tree/master/skills/spec-write-skill into .agents/skills/spec-write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spec-write-skill", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add leo-kuang-ai/spec-first --skill spec-write-skill -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install leo-kuang-ai/spec-first spec-write-skill --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/leo-kuang-ai/spec-first.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/spec-write-skill .cursor/skills/spec-write-skill && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "spec-write-skill" agent skill from https://github.com/leo-kuang-ai/spec-first/tree/master/skills/spec-write-skill into .cursor/skills/spec-write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spec-write-skill", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/leo-kuang-ai/spec-first.git --path skills/spec-write-skill--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add leo-kuang-ai/spec-first --skill spec-write-skill -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install leo-kuang-ai/spec-first spec-write-skill --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/leo-kuang-ai/spec-first.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/spec-write-skill .gemini/skills/spec-write-skill && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "spec-write-skill" agent skill from https://github.com/leo-kuang-ai/spec-first/tree/master/skills/spec-write-skill into .gemini/skills/spec-write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spec-write-skill", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install leo-kuang-ai/spec-first spec-write-skillInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add leo-kuang-ai/spec-first --skill spec-write-skill -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/leo-kuang-ai/spec-first.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/spec-write-skill .github/skills/spec-write-skill && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "spec-write-skill" agent skill from https://github.com/leo-kuang-ai/spec-first/tree/master/skills/spec-write-skill into .github/skills/spec-write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spec-write-skill", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add leo-kuang-ai/spec-first --skill spec-write-skill -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install leo-kuang-ai/spec-first spec-write-skill --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/leo-kuang-ai/spec-first.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/spec-write-skill .opencode/skills/spec-write-skill && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "spec-write-skill" agent skill from https://github.com/leo-kuang-ai/spec-first/tree/master/skills/spec-write-skill into .opencode/skills/spec-write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spec-write-skill", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
spec-write-skill公开 workflow:创建、修改或迁移项目拥有的 Agent Skill package,或对现有/外部 package 做用户明确要求、零执行的只读验证与 readiness 报告时使用;也用于按已接受的 audit finding 修复 source skill。不要用于一次性回答、解释/总结/翻译、普通代码 review、第三方 Skill 纯安装或导入、跨仓批量修改,或直接修补…
Spec Write Skill is an agent skill from leo-kuang-ai/spec-first. 公开 workflow:创建、修改或迁移项目拥有的 Agent Skill package,或对现有/外部 package 做用户明确要求、零执行的只读验证与 readiness 报告时使用;也用于按已接受的 audit finding 修复 source skill。不要用于一次性回答、解释/总结/翻译、普通代码 review、第三方 Skill 纯安装或导入、跨仓批量修改,或直接修补 generated runtime mirrors。
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 35 other files, including scripts and reference files (for example `agents/openai.yaml`, `evals/README.md` and `evals/cases/mirror-patch-refused.yaml`).
It sits in Legal & Compliance, covering Audit readiness. The repository describes itself as: 仓库原生 AI Coding Harness —— 把一次性 AI 对话变成可治理、可验证、可沉淀的工程闭环 · spec-first.cn. The licence is MIT.
Read from SKILL.md and the folder at commit 74655dc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript and Shell, from the files we listed), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Spec Write Skill loads about 1.6k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 487 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from leo-kuang-ai/spec-first at commit 74655dc, republished under its MIT licence (© leo-kuang-ai). 487 words, ~1,616 tokens.
.claude/skills/spec-write-skill/SKILL.md (or your agent's skills folder). This skill also uses 27 other files; get the full folder from GitHub.把可复用目标转成 portable、source-first 的 Skill patch,或在零写入模式下报告 package readiness;交付正确分支的结果、匹配证据与 residual risks,不把 source bytes、fixture pass 或模型自述当成语义改善。
Follows docs/contracts/workflows/scenario-capability-matrix.md (default).
Overrides: none
validate-only report、preview 后的单 repo source patch 或 source-resolution blocker;每个结果带验证状态与 residual risks。base_operation=create|revise 只区分新建 package 与处理现有 package;effect=apply|validate-only 决定副作用,只有 effect=apply 才允许修改已确认的 canonical source,effect=validate-only 即使面对现有或外部 package 也保持零写入。modifier=migrate|audit-remediation|none 只补充输入分析,不形成新 workflow/effect。layer_result 是 runtime 输出合同:near-neighbor-route|refuse-generated-runtime-patch|portable-core-only|portable-core-with-behavior-contract|portable-readiness-report|trust-preflight-blocked|blocked-source-owner|spec-first-project-profile。新增值必须同步更新 source、consumer 和 tests,不能只写入 maintainer fixture。先根据用户请求和已确认事实选择一个 disposition;只读取会改变该 disposition 判断的 reference,并在下列 done signal 达成后停止。
| Disposition | Entry signal and result | Required action / evidence | Done signal and failure behavior |
|---|---|---|---|
| Near-neighbor | 非 authoring/readiness,或只请求 audit-only quality review、纯安装、runtime mirror。已接受 finding 的 remediation 不属于本分支。输出 base_operation=null、effect=not-entered、modifier=none;结果为 near-neighbor-route 或 refuse-generated-runtime-patch。 | 只给 owning route / next action;安装交给 skill-installer,mirror 交给 runtime-maintenance。 | 路由后停止;不得 inventory、validator、preview 或 mutation。 |
| Owner blocked | create/revise 的 owner 不唯一、跨 repo、repo-external、generated-only 或 containment 未确认。保留 `base_operation=create | revise与effect=apply,结果为 blocked-source-owner`。 | 读 Authoring Method,给 candidate-only preview、空 would-change/command list 和唯一下一步。 |
| Validate-only | 用户明确检查现有/外部 package;现有 package 使用 base_operation=revise + effect=validate-only,结果为 portable-readiness-report 或 trust-preflight-blocked。 | no-follow inventory、bundled validator 与 Delivery Gates。 | 报告后停止;不得执行目标 scripts、validator、hooks、binaries 或 lifecycle,不得跟随 symlink、读 secret-like 内容、复制、安装或写入。 |
| Tier A apply | 已确认 owner 的 behavior-preserving revise,具体条件由 workbench 定义。 | 读 Authoring Workbench,确认当前授权覆盖 exact write set、preview binding 与最窄结构验证。 | receipt/验证后 close out;承重行为变化转 full apply。 |
| Full apply | 已确认 owner 的 create/revise apply,结果为 portable-core-only、portable-core-with-behavior-contract 或 spec-first-project-profile。 | 依次读 Authoring Method、Authoring Workbench 与 Shape-Aware Evaluation Design;写 core 前完成紧凑 Design Record 与最小 pre-patch eval plan。Capability Map、显式 shape/module decision 或 topology 只在它们改变 owner、consumer、resource/runtime carrier、架构或风险时展开。 | preview、授权、风险匹配验证和 source update 后 close out;缺 baseline/eval plan 时停止,缺 semantic/comparative evidence 时降级对应 claim。 |
not-ready 并停止。.claude/、.codex/、.agents/skills/、.cursor/、.kiro/、.qoder/ 由 generator 投影;先更新 source/governance,再 init/sync,不手改 mirror。incomplete validator、缺 semantic evidence/receipt 或未运行 target/runtime 检查必须在 closeout 降级,不能声称 package-ready 或行为改善。| When this fact is needed | Read | It supports | If unavailable or inapplicable |
|---|---|---|---|
| 判定 workflow、owner/effect 或 portable core | Authoring Method | qualification、resolution、resource ownership | near-neighbor 路由;owner 不明时 preview-only / blocked。 |
| Tier A 或 full apply | Authoring Workbench | Tier A,或紧凑 Design Record、按风险展开的 map/topology、preview handoff | 未完成必要 design record/preview 不得 apply。 |
| prose、persona、few-shot、输出合同或 agentic loop 承重 | Behavior Contract Design | 行为 delta、authority、examples、checkpoint/stop | 纯工具/schema 不读;不以 persona prose 代替行为合同。 |
| Full apply 需要 baseline、protected behavior 或 eval family | Shape-Aware Evaluation Design | 最小 pre-patch eval plan 与风险匹配的 evidence family | 未读不得开始 full apply source patch;Tier A 不触发。 |
| measurable optimization 或 field feedback 改变 disposition | Optimization And Feedback Handoff | optimization handoff、feedback-to-regression | optimization 主意图路由 spec-optimize;未复现 feedback 保持 observation。 |
| package/写前/closeout 验证或风险信号 | Delivery Gates | validator、preview、risk checks、五轴 readiness | 记录 not-run / degraded,不伪造 gate。 |
| target metadata/invocation 或本地治理/catalog/generator 改变 patch | Target Profiles 或 Project Profiles | target/project facts 和 projection | portable-only 不读 profile;owner 不明不 apply。 |
apply 先更新 canonical source、必要 tests/docs/Changelog;catalog 由 generator 重建,runtime 由项目 init/sync 重建。
closeout 固定报告 base_operation、effect、modifier、layer_result、target/source owner、changed surfaces、deterministic/semantic evidence、portable/target/project/semantic/mutation 五轴 readiness、runtime 状态、not-run reason 和 residual risks。
agents/openai.yaml 仅是 Codex target metadata;evals/ 仅是维护者证据,二者都不是 portable 行为真相源。
© leo-kuang-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 27 other files (scripts, references) in skills/spec-write-skill of leo-kuang-ai/spec-first.
Open the folder on GitHubat commit 74655dc
Spec Write Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Spec Write Skill this skillleo-kuang-ai/spec-first | 107 | — | ~1.6k | Automated safety check: Pass | MIT | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~4.6k | Automated safety check: Notes | MIT | |
| Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Fleet Triagegoogle-labs-code/jules-sdk | 137 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| PCI DSS Compliancewshobson/agents | 40k | 11 repos | ~1.9k | Automated safety check: Pass | MIT |
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
K-Dense-AI/scientific-agent-skills
Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
google-labs-code/jules-sdk
Cognitive triage of fleet audit findings. An agent skill from google-labs-code/jules-sdk.
wshobson/agents
Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.
GRCEngClub/claude-grc-engineering
Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.
leo-kuang-ai/spec-first
Audit mobile App PRD/Figma/local-source consistency across page routes, KMP/Clean Architecture, components, analytics, i18n, engineering quality, and industry lenses before runtime validation; use…
leo-kuang-ai/spec-first
Create a durable cross-session handoff or resume from a user-selected continuity source.
leo-kuang-ai/spec-first
Give a decisive, project-grounded verdict on an external input — judged against the current project, not in the abstract.
leo-kuang-ai/spec-first
Resolve PR review feedback by evaluating validity and fixing issues with conflict-aware resolver dispatch.
leo-kuang-ai/spec-first
Analyze explicit Riffrec product-feedback captures, including riffrec-.zip, the Riffrec session.json + events.json + recording.webm + voice.webm bundle, or media/notes the user identifies as a…
leo-kuang-ai/spec-first
Document a recently solved problem or durable project vocabulary in docs/solutions/ or CONCEPTS.md.
Categories
公开 workflow:创建、修改或迁移项目拥有的 Agent Skill package,或对现有/外部 package 做用户明确要求、零执行的只读验证与 readiness 报告时使用;也用于按已接受的 audit finding 修复 source skill。不要用于一次性回答、解释/总结/翻译、普通代码 review、第三方 Skill 纯安装或导入、跨仓批量修改,或直接修补…. Spec Write Skill is an agent skill from leo-kuang-ai/spec-first.
Spec Write Skill fits situations like: tasks that involve Audit readiness.
Run `npx skills add leo-kuang-ai/spec-first --skill spec-write-skill -a claude-code`. Or copy the skill folder (skills/spec-write-skill in leo-kuang-ai/spec-first) into .claude/skills/spec-write-skill in your project. Claude Code loads it when a task matches its description.
Run `npx skills add leo-kuang-ai/spec-first --skill spec-write-skill -a codex`. Or copy the skill folder (skills/spec-write-skill in leo-kuang-ai/spec-first) into .agents/skills/spec-write-skill in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add leo-kuang-ai/spec-first --skill spec-write-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spec-write-skill, .gemini/skills/spec-write-skill, .github/skills/spec-write-skill and .opencode/skills/spec-write-skill in your project.
Going by SKILL.md and its folder, Spec Write Skill needs JavaScript and a shell for the scripts in its folder. Our summary lists: Node.js; A Bash shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Spec Write Skill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Spec Write Skill: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Fleet Triage (google-labs-code/jules-sdk, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
leo-kuang-ai (a GitHub user) maintains it in leo-kuang-ai/spec-first, which has 107 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 8, 2026.
Source: leo-kuang-ai/spec-first on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.