Agent skill

Auditing Part11 Trails

by maziyarpanahi in maziyarpanahi/openmed

Generates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings.

Apache-2.0Auto-check passedDocuments & Office

Install Auditing Part11 Trails

skills CLI
$ npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maziyarpanahi/openmed auditing-part11-trails --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auditing-part11-trails .claude/skills/auditing-part11-trails && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auditing-part11-trails
GitHub stars
5.5k
Token cost
~2.2k tokens
SKILL.md length
727 words
Files
1
Skills in repo
74
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings.

  • Works in 7 steps: Authenticate the actor in your own… → Run the processing step with audit=True… → Sign with a controlled release key from… → …
  • The user runs OpenMed in a regulated/validated environment and needs an attributable
  • SKILL.md covers When to use, How OpenMed's AuditReport maps…, Quick start and Workflow, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Auditing Part11 Trails is an agent skill from maziyarpanahi/openmed. Generates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings. Use when the user runs OpenMed in a regulated/validated environment and needs an attributable, time-stamped, tamper-evident record of each processing action, electronic-signature manifestations, or computer-system-validation (CSV) evidence. Trigger keywords: 21 CFR Part 11, Part 11, audit trail, electronic signature, e-signature…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Clinical and healthcare research and CSV and tabular files. It works with Google Cloud. The repository describes itself as: Local-first healthcare AI: clinical NER and HIPAA PII de-identification on hardware you control. 2,200+ medical models, 35 model-backed PII languages, and Python, MLX, Android… The licence is Apache-2.0.

When your agent uses it

  • The user runs OpenMed in a regulated/validated environment and needs an attributable
  • Tamper-evident record of each processing action
  • Electronic-signature manifestations
  • Computer-system-validation (CSV) evidence

Example prompts

  • “Use the auditing-part11-trails skill to generate and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and…”
  • “/auditing-part11-trails”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Authenticate the actor in your own IdP/access system (Part 11 needs unique
  2. Run the processing step with audit=True to get the deterministic record.
  3. Sign with a controlled release key from a vault/HSM; record key_id.
  4. Build the Part 11 envelope — who, when (UTC, contemporaneous), what, and
  5. Append, never overwrite. Store trails write-once (WORM / append-only
  6. Verify on retrieval with .verify(key, original_text=..., deidentified_text=...)
  7. Retain per the study/retention schedule; keep keys and any reversible

What it can do on your machine

Read from SKILL.md and the folder at commit 34d7b8c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • fda.gov
    • ecfr.gov
    • ispe.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auditing Part11 Trails loads about 2.2k tokens when it runs. Until then it costs about 232 tokens; SKILL.md has 727 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~232
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from maziyarpanahi/openmed at commit 34d7b8c, republished under its Apache-2.0 licence (© maziyarpanahi). 727 words, ~2,222 tokens.

Download SKILL.mdSave it as .claude/skills/auditing-part11-trails/SKILL.md (or your agent's skills folder).
name
auditing-part11-trails
description
Generates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings. Use when the user runs OpenMed in a regulated/validated environment and needs an attributable, time-stamped, tamper-evident record of each processing action, electronic-signature manifestations, or computer-system-validation (CSV) evidence. Trigger keywords: 21 CFR Part 11, Part 11, audit trail, electronic signature, e-signature, GxP, GCP, GLP, GMP, CSV, computer system validation, data integrity, ALCOA, tamper-evident, contemporaneous. Pairs adjacent to OpenMed: maps directly onto OpenMed deidentify(audit=True) -> signed AuditReport with .sign(key)/.verify(key), whose repro_hash + HMAC give the tamper-evidence and attribution Part 11 expects. This is a compliance-enablement aid, not a validation certification.
license
Apache-2.0
metadata.project
OpenMed
metadata.category
compliance-regulatory
metadata.pairs
adjacent
metadata.version
1.0

Auditing 21 CFR Part 11 trails for OpenMed pipelines

In FDA-regulated GxP work (GCP clinical trials, GLP, GMP) any electronic record used to support a regulatory decision must meet 21 CFR Part 11: it has to be attributable (who), contemporaneous and time-stamped (when), describe what changed, be tamper-evident, and — where a signing event occurs — carry a controlled electronic signature. These map onto the ALCOA+ data-integrity expectations (Attributable, Legible, Contemporaneous, Original, Accurate, +Complete/Consistent/Enduring/Available).

OpenMed's deidentify(..., audit=True) already emits a deterministic, PHI-free AuditReport that you can .sign() (HMAC-SHA256) and later .verify(). That gives you the tamper-evidence and attribution primitives; this skill wraps them in the who/when/what/e-signature envelope Part 11 wants.

This is a compliance-enablement aid. Part 11 compliance also requires validated systems (CSV), SOPs, and access controls that live outside any single library — a QA/validation lead signs off.

When to use

  • OpenMed runs inside a validated/GxP environment and each run must leave an attributable, tamper-evident record.
  • You need to wrap an OpenMed AuditReport with who/when/what + an e-signature manifestation (meaning, signer, timestamp).
  • You must verify a stored trail hasn't been altered, or produce CSV evidence for an inspection.

How OpenMed's AuditReport maps to Part 11

Part 11 expectation21 CFR citeOpenMed mechanism
Tamper-evident, accurate copies11.10(b),(c)AuditReport.to_json() + repro_hash over the canonical payload
Audit trail: what changed, when11.10(e)AuditReport.spans (action per identifier), input_hash/deidentified_text_hash, openmed_version, manifest_hash
Operational/authority checks; attribution11.10(d),(g)AuditSignature.key_id (signer/key identity) + your envelope's user id
Signature manifestation (name, date, meaning)11.50Your envelope fields signer, signed_at, meaning
Signature/record linking, non-repudiation11.70, 11.200HMAC-SHA256 over the canonical payload via .sign() / .verify()

The HMAC binds the signature to that exact report content: any later edit to a span, hash, or field changes repro_hash, so .verify() fails — that is the tamper-evidence.

Quick start

python
import openmed, json, datetime as dt

note = "Subject S-014 (DOB 1962-08-09) reported headache on 2024-05-01."

# 1) Produce the deterministic, PHI-free audit record for this processing step.
report = openmed.deidentify(note, policy="hipaa_safe_harbor", audit=True)

# 2) Sign it with a controlled release key (stored in a vault / HSM, never in code).
report.sign(b"<release-hmac-key>", key_id="omv-signer-2026")

# 3) Wrap in a Part 11 envelope: who / when / what / signature meaning.
trail = {
    "record": report.to_dict(),              # tamper-evident, no PHI
    "who": "j.smith@sponsor.example",        # authenticated user (your IdP)
    "when": dt.datetime.now(dt.timezone.utc).isoformat(),
    "what": "PHI de-identification of source narrative (study X, subject S-014)",
    "signature_manifestation": {             # 21 CFR 11.50
        "signer_printed_name": "Jane Smith",
        "meaning": "reviewed and approved",
        "signed_at": dt.datetime.now(dt.timezone.utc).isoformat(),
    },
    "system": {"openmed_version": report.openmed_version,
               "manifest_hash": report.manifest_hash},
}
with open("part11_trail.json", "w") as fh:
    json.dump(trail, fh, indent=2, sort_keys=True)

# 4) Later — verify integrity (optionally bind to the exact source/output text).
ok = report.verify(b"<release-hmac-key>", original_text=note)
assert ok, "AUDIT TRAIL TAMPERED OR KEY MISMATCH"

Workflow

  1. Authenticate the actor in your own IdP/access system (Part 11 needs unique IDs and operational checks — outside the library). Capture the user id.
  2. Run the processing step with audit=True to get the deterministic record.
  3. Sign with a controlled release key from a vault/HSM; record key_id. Never embed the key in source or the trail.
  4. Build the Part 11 envelope — who, when (UTC, contemporaneous), what, and the signature manifestation (printed name, meaning, timestamp) per 11.50.
  5. Append, never overwrite. Store trails write-once (WORM / append-only store). The audit trail itself must be protected and retained.
  6. Verify on retrieval with .verify(key, original_text=..., deidentified_text=...) to confirm neither the record nor the bound texts changed.
  7. Retain per the study/retention schedule; keep keys and any reversible mapping in a separate, access-controlled store.
Show full SKILL.md (305 more words)Show less

Hand-off to / from OpenMed

  • Produce the record: auditing-deidentification-runs (deidentify(audit=True) → AuditReport) is the source of the signed, PHI-free trail this skill envelopes.
  • Coverage evidence: auditing-safe-harbor-checklist documents that the 18 identifier categories were handled — useful as a CSV artifact.
  • No-PHI logging: enforcing-nophi-logging ensures the surrounding application logs don't leak identifiers into the trail.
  • HIPAA overlap: checking-hipaa-compliance — Part 11 audit controls and the HIPAA Security Rule audit-controls standard (164.312(b)) reinforce each other.
  • OpenMed runs on-device, so the record-generating step stays inside your validated boundary.

Edge cases & gotchas

  • Part 11 ≠ one library. The signed AuditReport gives tamper-evidence and attribution, but Part 11 also requires validated systems (CSV), SOPs, training, and access controls you implement around it. Don't claim "Part 11 compliant" from the audit object alone.
  • Unsigned = not tamper-evident. .sign() is a deliberate step; signature is None until called. Empty/None keys are rejected.
  • Key management is the crux. The HMAC is only as trustworthy as the key. Use a vault/HSM, rotate via key_id, and never store the key with the trail.
  • Contemporaneous timestamps. Use a synchronized, trusted clock (UTC) at the moment of the action — back-dating breaks ALCOA "Contemporaneous".
  • Append-only retention. A trail you can silently overwrite isn't an audit trail. Use WORM/append-only storage and protect it from the operators it audits.
  • No PHI in the envelope. The AuditReport is hash-and-offset only; don't reintroduce identifiers in the what/who free-text fields.
  • HMAC is symmetric. It proves integrity to holders of the key, not public non-repudiation. If you need third-party non-repudiation, layer an asymmetric signature over report.to_json().

Standards & references

© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/auditing-part11-trails of maziyarpanahi/openmed.

Open the folder on GitHubat commit 34d7b8c

Compare with similar skills

Auditing Part11 Trails next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auditing Part11 Trails compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auditing Part11 Trails this skillmaziyarpanahi/openmed5.5k—~2.2kAutomated safety check: PassApache-2.0
Module Authoringdna-seq/just-dna-lite141—~4.8kAutomated safety check: NotesAGPL-3.0
Vdjdb Extractantigenomics/vdjdb-db157—~1.5kAutomated safety check: PassCustom licence
Nwb ConversionK-Dense-AI/scientific-agent-skills48k1 repos~1.9kAutomated safety check: PassMIT
Generate CodebookAperivue/medsci-skills333—~1.1kAutomated safety check: PassMIT
Marker Dominance MapperClawBio/ClawBio1.2k—~1.6kAutomated safety check: PassMIT

Similar skills

  • Module Authoring

    dna-seq/just-dna-lite

    Author, resolve, compile and publish a just-dna annotation module — the spec directory layout, the CSV column contracts and vocabularies, the enrich→compile pipeline, and the checks that decide…

    141 GitHub stars~4.8k tokensUpdated today
    Documents & OfficeAuto-check: notes
  • Vdjdb Extract

    antigenomics/vdjdb-db

    Extract TCR:pMHC specificity records from raw submission sources - supplementary XLS/CSV tables, PDF manuscripts, 10x Genomics contig and clonotype files, AIRR Rearrangement TSVs, Adaptive ImmunoSEQ…

    157 GitHub stars~1.5k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Nwb Conversion

    K-Dense-AI/scientific-agent-skills

    Converts neuroscience acquisition data to Neurodata Without Borders files with NeuroConv and PyNWB, preserves metadata and timebases, checks evidence-based clock alignment, and produces schema…

    48k GitHub starsUsed in 1 repo~1.9k tokens
    Documents & OfficeAuto-check passed
  • Generate Codebook

    Aperivue/medsci-skills

    A skill your agent uses when a tabular dataset (CSV, Excel, Parquet, Stata, SAS) needs a data dictionary.

    333 GitHub stars~1.1k tokensUpdated 5 days ago
    Documents & OfficeAuto-check passed
  • Deterministic marker-dominance region mapping from local spot-count CSVs

    1.2k GitHub stars~1.6k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • Biostudies Fetch

    ClawBio/ClawBio

    Query metadata and download data from EMBL-EBI BioStudies, the database that describes biological studies and links their data across collections (ArrayExpress, BioImages, BioModels, EGA-linked…

    1.2k GitHub stars~4.2k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed

More from maziyarpanahi/openmed

All 74 skills in this repo
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • OpenMed Model Card Writer

    maziyarpanahi/openmed

    Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.

    5.5k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • ICD-10 Coding Assistant

    maziyarpanahi/openmed

    Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • OpenMed ETL to OMOP CDM

    maziyarpanahi/openmed

    Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.

    5.5k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Extracting SDOH and Z-Codes

    maziyarpanahi/openmed

    Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.

    5.5k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Questions about Auditing Part11 Trails

What does Auditing Part11 Trails do?

Generates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings. Auditing Part11 Trails is an agent skill from maziyarpanahi/openmed. Generates and verifies 21 CFR Part 11-style audit trails — who/what/when, electronic signatures, and tamper-evidence — for OpenMed pipelines in GxP and clinical-trial (GCP) settings.

When should I use Auditing Part11 Trails?

Auditing Part11 Trails fits situations like: the user runs OpenMed in a regulated/validated environment and needs an attributable; tamper-evident record of each processing action; electronic-signature manifestations; computer-system-validation (CSV) evidence.

How do I install Auditing Part11 Trails in Claude Code?

Run `npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a claude-code`. Or copy the skill folder (skills/auditing-part11-trails in maziyarpanahi/openmed) into .claude/skills/auditing-part11-trails in your project. Claude Code loads it when a task matches its description.

How do I install Auditing Part11 Trails in Codex?

Run `npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a codex`. Or copy the skill folder (skills/auditing-part11-trails in maziyarpanahi/openmed) into .agents/skills/auditing-part11-trails in your project. Codex loads it when a task matches its description.

Can I use Auditing Part11 Trails in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill auditing-part11-trails -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-part11-trails, .gemini/skills/auditing-part11-trails, .github/skills/auditing-part11-trails and .opencode/skills/auditing-part11-trails in your project.

What does Auditing Part11 Trails need to run?

SKILL.md names no scripts, command-line tools or credentials: Auditing Part11 Trails is instructions for the agent only. Our summary lists: Python 3.

Does Auditing Part11 Trails access the network?

SKILL.md names 3 domains. As links in the text: fda.gov, ecfr.gov and ispe.org. This is read from the text; nothing was executed.

Is Auditing Part11 Trails safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auditing Part11 Trails use?

Auditing Part11 Trails is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auditing Part11 Trails use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auditing Part11 Trails?

Skills that share tags, products or a category with Auditing Part11 Trails: Module Authoring (dna-seq/just-dna-lite, 141 stars), Vdjdb Extract (antigenomics/vdjdb-db, 157 stars), Nwb Conversion (K-Dense-AI/scientific-agent-skills, 48k stars) and Generate Codebook (Aperivue/medsci-skills, 333 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auditing Part11 Trails?

maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,506 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 11, 2026.

Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.