Module Authoring
dna-seq/just-dna-lite
Author, resolve, compile and publish a just-dna annotation module — the spec directory layout, the CSV column contracts and vocabularies, the enrich→compile pipeline, and the checks that decide…
Generates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings.
$ npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install maziyarpanahi/openmed auditing-part11-trails --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auditing-part11-trails .claude/skills/auditing-part11-trails && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auditing-part11-trails" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/auditing-part11-trails into .claude/skills/auditing-part11-trails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-part11-trails", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/maziyarpanahi/openmed/tree/master/skills/auditing-part11-trailsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install maziyarpanahi/openmed auditing-part11-trails --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/auditing-part11-trails .agents/skills/auditing-part11-trails && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auditing-part11-trails" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/auditing-part11-trails into .agents/skills/auditing-part11-trails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-part11-trails", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install maziyarpanahi/openmed auditing-part11-trails --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/auditing-part11-trails .cursor/skills/auditing-part11-trails && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auditing-part11-trails" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/auditing-part11-trails into .cursor/skills/auditing-part11-trails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-part11-trails", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/maziyarpanahi/openmed.git --path skills/auditing-part11-trails--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install maziyarpanahi/openmed auditing-part11-trails --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/auditing-part11-trails .gemini/skills/auditing-part11-trails && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auditing-part11-trails" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/auditing-part11-trails into .gemini/skills/auditing-part11-trails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-part11-trails", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install maziyarpanahi/openmed auditing-part11-trailsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/auditing-part11-trails .github/skills/auditing-part11-trails && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auditing-part11-trails" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/auditing-part11-trails into .github/skills/auditing-part11-trails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-part11-trails", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install maziyarpanahi/openmed auditing-part11-trails --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/auditing-part11-trails .opencode/skills/auditing-part11-trails && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auditing-part11-trails" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/auditing-part11-trails into .opencode/skills/auditing-part11-trails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-part11-trails", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auditing-part11-trailsGenerates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings.
Auditing Part11 Trails is an agent skill from maziyarpanahi/openmed. Generates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings. Use when the user runs OpenMed in a regulated/validated environment and needs an attributable, time-stamped, tamper-evident record of each processing action, electronic-signature manifestations, or computer-system-validation (CSV) evidence. Trigger keywords: 21 CFR Part 11, Part 11, audit trail, electronic signature, e-signature…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Documents & Office, covering Clinical and healthcare research and CSV and tabular files. It works with Google Cloud. The repository describes itself as: Local-first healthcare AI: clinical NER and HIPAA PII de-identification on hardware you control. 2,200+ medical models, 35 model-backed PII languages, and Python, MLX, Android… The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 34d7b8c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
fda.govecfr.govispe.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Auditing Part11 Trails loads about 2.2k tokens when it runs. Until then it costs about 232 tokens; SKILL.md has 727 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from maziyarpanahi/openmed at commit 34d7b8c, republished under its Apache-2.0 licence (© maziyarpanahi). 727 words, ~2,222 tokens.
.claude/skills/auditing-part11-trails/SKILL.md (or your agent's skills folder).In FDA-regulated GxP work (GCP clinical trials, GLP, GMP) any electronic record used to support a regulatory decision must meet 21 CFR Part 11: it has to be attributable (who), contemporaneous and time-stamped (when), describe what changed, be tamper-evident, and — where a signing event occurs — carry a controlled electronic signature. These map onto the ALCOA+ data-integrity expectations (Attributable, Legible, Contemporaneous, Original, Accurate, +Complete/Consistent/Enduring/Available).
OpenMed's deidentify(..., audit=True) already emits a deterministic,
PHI-free AuditReport that you can .sign() (HMAC-SHA256) and later
.verify(). That gives you the tamper-evidence and attribution primitives;
this skill wraps them in the who/when/what/e-signature envelope Part 11 wants.
This is a compliance-enablement aid. Part 11 compliance also requires validated systems (CSV), SOPs, and access controls that live outside any single library — a QA/validation lead signs off.
AuditReport with who/when/what + an
e-signature manifestation (meaning, signer, timestamp).| Part 11 expectation | 21 CFR cite | OpenMed mechanism |
|---|---|---|
| Tamper-evident, accurate copies | 11.10(b),(c) | AuditReport.to_json() + repro_hash over the canonical payload |
| Audit trail: what changed, when | 11.10(e) | AuditReport.spans (action per identifier), input_hash/deidentified_text_hash, openmed_version, manifest_hash |
| Operational/authority checks; attribution | 11.10(d),(g) | AuditSignature.key_id (signer/key identity) + your envelope's user id |
| Signature manifestation (name, date, meaning) | 11.50 | Your envelope fields signer, signed_at, meaning |
| Signature/record linking, non-repudiation | 11.70, 11.200 | HMAC-SHA256 over the canonical payload via .sign() / .verify() |
The HMAC binds the signature to that exact report content: any later edit to a
span, hash, or field changes repro_hash, so .verify() fails — that is the
tamper-evidence.
import openmed, json, datetime as dt
note = "Subject S-014 (DOB 1962-08-09) reported headache on 2024-05-01."
# 1) Produce the deterministic, PHI-free audit record for this processing step.
report = openmed.deidentify(note, policy="hipaa_safe_harbor", audit=True)
# 2) Sign it with a controlled release key (stored in a vault / HSM, never in code).
report.sign(b"<release-hmac-key>", key_id="omv-signer-2026")
# 3) Wrap in a Part 11 envelope: who / when / what / signature meaning.
trail = {
"record": report.to_dict(), # tamper-evident, no PHI
"who": "j.smith@sponsor.example", # authenticated user (your IdP)
"when": dt.datetime.now(dt.timezone.utc).isoformat(),
"what": "PHI de-identification of source narrative (study X, subject S-014)",
"signature_manifestation": { # 21 CFR 11.50
"signer_printed_name": "Jane Smith",
"meaning": "reviewed and approved",
"signed_at": dt.datetime.now(dt.timezone.utc).isoformat(),
},
"system": {"openmed_version": report.openmed_version,
"manifest_hash": report.manifest_hash},
}
with open("part11_trail.json", "w") as fh:
json.dump(trail, fh, indent=2, sort_keys=True)
# 4) Later — verify integrity (optionally bind to the exact source/output text).
ok = report.verify(b"<release-hmac-key>", original_text=note)
assert ok, "AUDIT TRAIL TAMPERED OR KEY MISMATCH"audit=True to get the deterministic record.key_id.
Never embed the key in source or the trail..verify(key, original_text=..., deidentified_text=...)
to confirm neither the record nor the bound texts changed.auditing-deidentification-runs
(deidentify(audit=True) → AuditReport) is the source of the signed,
PHI-free trail this skill envelopes.auditing-safe-harbor-checklist documents that the
18 identifier categories were handled — useful as a CSV artifact.enforcing-nophi-logging ensures the surrounding
application logs don't leak identifiers into the trail.checking-hipaa-compliance — Part 11 audit controls and the
HIPAA Security Rule audit-controls standard (164.312(b)) reinforce each other.AuditReport gives tamper-evidence and
attribution, but Part 11 also requires validated systems (CSV), SOPs, training,
and access controls you implement around it. Don't claim "Part 11 compliant"
from the audit object alone..sign() is a deliberate step; signature
is None until called. Empty/None keys are rejected.key_id, and never store the key with the trail.AuditReport is hash-and-offset only; don't
reintroduce identifiers in the what/who free-text fields.report.to_json().openmed/core/audit.py.© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/auditing-part11-trails of maziyarpanahi/openmed.
Open the folder on GitHubat commit 34d7b8c
Auditing Part11 Trails next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auditing Part11 Trails this skillmaziyarpanahi/openmed | 5.5k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Module Authoringdna-seq/just-dna-lite | 141 | — | ~4.8k | Automated safety check: Notes | AGPL-3.0 | |
| Vdjdb Extractantigenomics/vdjdb-db | 157 | — | ~1.5k | Automated safety check: Pass | Custom licence | |
| Nwb ConversionK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Generate CodebookAperivue/medsci-skills | 333 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Marker Dominance MapperClawBio/ClawBio | 1.2k | — | ~1.6k | Automated safety check: Pass | MIT |
dna-seq/just-dna-lite
Author, resolve, compile and publish a just-dna annotation module — the spec directory layout, the CSV column contracts and vocabularies, the enrich→compile pipeline, and the checks that decide…
antigenomics/vdjdb-db
Extract TCR:pMHC specificity records from raw submission sources - supplementary XLS/CSV tables, PDF manuscripts, 10x Genomics contig and clonotype files, AIRR Rearrangement TSVs, Adaptive ImmunoSEQ…
K-Dense-AI/scientific-agent-skills
Converts neuroscience acquisition data to Neurodata Without Borders files with NeuroConv and PyNWB, preserves metadata and timebases, checks evidence-based clock alignment, and produces schema…
Aperivue/medsci-skills
A skill your agent uses when a tabular dataset (CSV, Excel, Parquet, Stata, SAS) needs a data dictionary.
ClawBio/ClawBio
Deterministic marker-dominance region mapping from local spot-count CSVs
ClawBio/ClawBio
Query metadata and download data from EMBL-EBI BioStudies, the database that describes biological studies and links their data across collections (ArrayExpress, BioImages, BioModels, EGA-linked…
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
maziyarpanahi/openmed
Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
maziyarpanahi/openmed
Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.
maziyarpanahi/openmed
Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.
maziyarpanahi/openmed
Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.
Works with
Generates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings. Auditing Part11 Trails is an agent skill from maziyarpanahi/openmed. Generates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings.
Auditing Part11 Trails fits situations like: the user runs OpenMed in a regulated/validated environment and needs an attributable; tamper-evident record of each processing action; electronic-signature manifestations; computer-system-validation (CSV) evidence.
Run `npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a claude-code`. Or copy the skill folder (skills/auditing-part11-trails in maziyarpanahi/openmed) into .claude/skills/auditing-part11-trails in your project. Claude Code loads it when a task matches its description.
Run `npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a codex`. Or copy the skill folder (skills/auditing-part11-trails in maziyarpanahi/openmed) into .agents/skills/auditing-part11-trails in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-part11-trails, .gemini/skills/auditing-part11-trails, .github/skills/auditing-part11-trails and .opencode/skills/auditing-part11-trails in your project.
SKILL.md names no scripts, command-line tools or credentials: Auditing Part11 Trails is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 3 domains. As links in the text: fda.gov, ecfr.gov and ispe.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Auditing Part11 Trails is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Auditing Part11 Trails: Module Authoring (dna-seq/just-dna-lite, 141 stars), Vdjdb Extract (antigenomics/vdjdb-db, 157 stars), Nwb Conversion (K-Dense-AI/scientific-agent-skills, 48k stars) and Generate Codebook (Aperivue/medsci-skills, 333 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,506 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 11, 2026.
Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.