Agent skill

Enforcing Nophi Logging

by maziyarpanahi in maziyarpanahi/openmed

Add a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment.

Apache-2.0Auto-check passedDevOps & Cloud

Install Enforcing Nophi Logging

skills CLI
$ npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maziyarpanahi/openmed enforcing-nophi-logging --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/enforcing-nophi-logging .claude/skills/enforcing-nophi-logging && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
enforcing-nophi-logging
GitHub stars
5.5k
Token cost
~1.9k tokens
SKILL.md length
563 words
Files
1
Skills in repo
74
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment.

  • Works in 6 steps: Inventory sinks. List every place a… → Install the regex pre-filter for… → Add the model fallback… → …
  • The user wants a Python logging.Filter that redacts protected health information before records are emitted
  • SKILL.md covers When to use this skill, Quick start — a redacting…, Prefer structured, no-PHI fields and OpenTelemetry / error trackers, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Enforcing Nophi Logging is an agent skill from maziyarpanahi/openmed. Add a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment. Use when the user wants a Python logging.Filter that redacts protected health information before records are emitted, wants to keep PHI out of OpenTelemetry spans or error trackers, needs structured no-PHI log fields, or is worried that logs and stack traces are leaking patient data. Trigger on "scrub logs", "redact PHI from logs", "no-PHI logging", "logging filter", "telemetry…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Observability and Debugging. It works with OpenTelemetry and Python. The repository describes itself as: Local-first healthcare AI: clinical NER and HIPAA PII de-identification on hardware you control. 2,200+ medical models, 35 model-backed PII languages, and Python, MLX, Android… The licence is Apache-2.0.

When your agent uses it

  • The user wants a Python logging.Filter that redacts protected health information before records are emitted
  • Wants to keep PHI out of OpenTelemetry spans
  • Needs structured no-PHI log fields
  • Is worried that logs and stack traces are leaking patient data

Example prompts

  • “scrub logs”
  • “redact PHI from logs”
  • “no-PHI logging”
  • “/enforcing-nophi-logging”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Inventory sinks. List every place a clinical string can reach: app logs,
  2. Install the regex pre-filter for structured identifiers (SSN, card, email,
  3. Add the model fallback (openmed.extract_pii) for free-text PHI on the
  4. Switch to structured fields. Replace "log the text" with "log counts,
  5. Fail closed. On any scrub error, drop the message content, not the
  6. Test it. Unit-test that known PHI strings never survive a round trip

What it can do on your machine

Read from SKILL.md and the folder at commit 34d7b8c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • hhs.gov
    • cheatsheetseries.owasp.org
    • opentelemetry.io
    • docs.python.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Enforcing Nophi Logging loads about 1.9k tokens when it runs. Until then it costs about 157 tokens; SKILL.md has 563 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~157
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from maziyarpanahi/openmed at commit 34d7b8c, republished under its Apache-2.0 licence (© maziyarpanahi). 563 words, ~1,900 tokens.

Download SKILL.mdSave it as .claude/skills/enforcing-nophi-logging/SKILL.md (or your agent's skills folder).
name
enforcing-nophi-logging
description
Add a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment. Use when the user wants a Python logging.Filter that redacts protected health information before records are emitted, wants to keep PHI out of OpenTelemetry spans or error trackers, needs structured no-PHI log fields, or is worried that logs and stack traces are leaking patient data. Trigger on "scrub logs", "redact PHI from logs", "no-PHI logging", "logging filter", "telemetry redaction", "logs leaking patient data", or "OpenTelemetry redaction" in an OpenMed deployment.
license
Apache-2.0
metadata.project
OpenMed
metadata.category
deployment-ops
metadata.pairs
adjacent
metadata.version
1.0

Enforcing No-PHI Logging

Logs are a top breach vector: a clinical string lands in a log line, gets shipped to a centralized log store and an error tracker, and is now PHI sitting outside the de-id boundary. OpenMed's local-first stance says no raw PHI in logs, caches, or error reports — this skill enforces it with a redaction guard that runs before any record is emitted.

When to use this skill

  • An OpenMed service logs request text, model output, or exception messages.
  • You ship logs/traces to a centralized store or error tracker (Sentry, ELK).
  • You need a logging.Filter (or OTel processor) that redacts PHI pre-emit.
  • You want structured, no-PHI log fields (offsets, hashes, counts) for debugging.

Quick start — a redacting logging.Filter

python
import logging
import re
import openmed

# Cheap regex pre-filter for the highest-risk structured identifiers. This runs
# on every record, so keep it fast; the model is the fallback for free-text PHI.
_FAST_PATTERNS = [
    (re.compile(r"\b\d{3}-\d{2}-\d{4}\b"), "[SSN]"),
    (re.compile(r"\b\d{16}\b"), "[CARD]"),
    (re.compile(r"\b[\w.+-]+@[\w-]+\.[\w.-]+\b"), "[EMAIL]"),
    (re.compile(r"\b(?:\+?\d[\d().\-\s]{7,}\d)\b"), "[PHONE]"),
]

class NoPHIFilter(logging.Filter):
    """Redact PHI from a log record before it is emitted. Fail closed."""

    def __init__(self, model_name: str | None = None, use_model: bool = True):
        super().__init__()
        self.model_name = model_name
        self.use_model = use_model

    def filter(self, record: logging.LogRecord) -> bool:
        try:
            message = record.getMessage()
            record.msg = self._scrub(message)
            record.args = ()                 # message already rendered & scrubbed
        except Exception:
            # Never let the logger leak on error — drop the message, keep the level.
            record.msg = "[REDACTED: scrub error]"
            record.args = ()
        return True                          # keep the (now-clean) record

    def _scrub(self, text: str) -> str:
        for pattern, tag in _FAST_PATTERNS:
            text = pattern.sub(tag, text)
        if not self.use_model:
            return text
        # Model fallback for free-text PHI (names, locations, dates). Replace by
        # offset, right-to-left, so earlier offsets stay valid.
        spans = openmed.extract_pii(text, model_name=self.model_name) \
            if self.model_name else openmed.extract_pii(text)
        for e in sorted(spans.entities, key=lambda s: s.start, reverse=True):
            text = text[:e.start] + f"[{e.label}]" + text[e.end:]
        return text

# Attach to every handler that might emit clinical text.
handler = logging.StreamHandler()
handler.addFilter(NoPHIFilter(model_name="OpenMed/Privacy-PII-Detection"))
logging.getLogger("openmed.service").addHandler(handler)

Prefer structured, no-PHI fields

Don't log the note and scrub it — log about it without the text in the first place:

python
logger.info(
    "deidentified note",
    extra={
        "doc_id": doc_id,                       # opaque id, not the text
        "phi_entity_count": len(result.entities),
        "phi_labels": sorted({e.label for e in result.entities}),
        "char_len": len(text),
        # offsets/hashes for debugging; never the plaintext span
        "phi_offsets": [(e.start, e.end) for e in result.entities],
    },
)

Redaction is the safety net; not logging PHI is the actual fix.

OpenTelemetry / error trackers

  • Spans: add a SpanProcessor.on_end (or attribute hook) that runs the same _scrub over string span attributes and events before export.
  • Error trackers: register a before_send hook (e.g. Sentry) that scrubs exception messages, breadcrumbs, and request bodies. Stack traces often embed the offending input — scrub the message, not just the frames.

Workflow

  1. Inventory sinks. List every place a clinical string can reach: app logs, access logs, OTel spans, error tracker, crash reports, request/response dumps.
  2. Install the regex pre-filter for structured identifiers (SSN, card, email, phone) — fast, runs on every record.
  3. Add the model fallback (openmed.extract_pii) for free-text PHI on the sinks that carry clinical narrative; skip it on hot paths where regex suffices.
  4. Switch to structured fields. Replace "log the text" with "log counts, labels, offsets, ids".
  5. Fail closed. On any scrub error, drop the message content, not the redaction.
  6. Test it. Unit-test that known PHI strings never survive a round trip through the filter, including in exception messages.
Show full SKILL.md (243 more words)Show less

Hand-off to / from OpenMed

  • Uses openmed.extract_pii (and optionally the regex pre-filter) as the PHI detector — the same engine documented in extracting-pii-entities.
  • From building-with-openmed: this is the runtime guard for the local-first, no-PHI-in-artifacts rule.
  • Pairs with gating-deid-leakage: the gate proves the model doesn't leak; this guard proves your logs and traces don't leak.
  • To auditing-deidentification-runs: route audit output through the same no-PHI discipline (offsets/hashes, never plaintext).

Edge cases & gotchas

  • record.args must be cleared after scrubbing. If you rewrite record.msg but leave %s args, the formatter re-injects raw PHI downstream.
  • Scrub before fan-out. Filters on one handler don't protect others — attach to every handler, or scrub at the record/formatter layer.
  • Latency budget. The model fallback costs inference per record; gate it behind a level threshold or reserve it for narrative-bearing sinks.
  • Regex alone is not de-id. It catches structured identifiers; names, locations, and dates need the model. Use both, model last.
  • Exception messages are PHI carriers. f"failed on {note}" leaks; scrub exception text and error-tracker payloads, not just logger.info calls.
  • Fail closed, never open. A scrub error must redact the content, never emit the unscrubbed original.
  • No raw PHI even in DEBUG. "It's only debug logs" is how breaches happen; the guard applies at every level.

Standards & references

© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/enforcing-nophi-logging of maziyarpanahi/openmed.

Open the folder on GitHubat commit 34d7b8c

Compare with similar skills

Enforcing Nophi Logging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Enforcing Nophi Logging compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Enforcing Nophi Logging this skillmaziyarpanahi/openmed5.5k—~1.9kAutomated safety check: PassApache-2.0
Motel Debugkitlangton/motel298—~2.2kAutomated safety check: PassMIT
Agent Kill Switchvivekchand/clawmetry426—~1.1kAutomated safety check: PassMIT
Clawmetry Selfcheckvivekchand/clawmetry426—~515Automated safety check: PassMIT
Logfire Instrumentationbasicmachines-co/basic-memory4.1k—~2.3kAutomated safety check: PassAGPL-3.0
Clawmetryvivekchand/clawmetry426—~992Automated safety check: PassMIT

Similar skills

  • Motel Debug

    kitlangton/motel

    Debug applications with motel, a local OpenTelemetry ingest and query server.

    298 GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Agent Kill Switch

    vivekchand/clawmetry

    Give the human an off switch and a cost meter for the coding agents on this machine, using ClawMetry.

    426 GitHub stars~1.1k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Clawmetry Selfcheck

    vivekchand/clawmetry

    Read your own agent telemetry from ClawMetry (waste, progress, cost) and act on it before finishing a task.

    426 GitHub stars~515 tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Logfire Instrumentation

    basicmachines-co/basic-memory

    Adds Pydantic Logfire tracing, logging and metrics to Python, JavaScript or TypeScript and Rust projects, with the correct setup order and library extras.

    4.1k GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Clawmetry

    vivekchand/clawmetry

    Real-time observability for OpenClaw agents — local dashboard + optional encrypted cloud sync.

    426 GitHub stars~992 tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Official

    Azure Monitor OpenTelemetry Distro for Python. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~2k tokens
    DevOps & CloudAuto-check passed

More from maziyarpanahi/openmed

All 74 skills in this repo
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • OpenMed Model Card Writer

    maziyarpanahi/openmed

    Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.

    5.5k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • ICD-10 Coding Assistant

    maziyarpanahi/openmed

    Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • OpenMed ETL to OMOP CDM

    maziyarpanahi/openmed

    Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.

    5.5k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Extracting SDOH and Z-Codes

    maziyarpanahi/openmed

    Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.

    5.5k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Categories

Questions about Enforcing Nophi Logging

What does Enforcing Nophi Logging do?

Add a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment. Enforcing Nophi Logging is an agent skill from maziyarpanahi/openmed. Add a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment.

When should I use Enforcing Nophi Logging?

Enforcing Nophi Logging fits situations like: the user wants a Python logging.Filter that redacts protected health information before records are emitted; wants to keep PHI out of OpenTelemetry spans; needs structured no-PHI log fields; is worried that logs and stack traces are leaking patient data.

How do I install Enforcing Nophi Logging in Claude Code?

Run `npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a claude-code`. Or copy the skill folder (skills/enforcing-nophi-logging in maziyarpanahi/openmed) into .claude/skills/enforcing-nophi-logging in your project. Claude Code loads it when a task matches its description.

How do I install Enforcing Nophi Logging in Codex?

Run `npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a codex`. Or copy the skill folder (skills/enforcing-nophi-logging in maziyarpanahi/openmed) into .agents/skills/enforcing-nophi-logging in your project. Codex loads it when a task matches its description.

Can I use Enforcing Nophi Logging in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/enforcing-nophi-logging, .gemini/skills/enforcing-nophi-logging, .github/skills/enforcing-nophi-logging and .opencode/skills/enforcing-nophi-logging in your project.

What does Enforcing Nophi Logging need to run?

SKILL.md names no scripts, command-line tools or credentials: Enforcing Nophi Logging is instructions for the agent only. Our summary lists: Python 3.

Does Enforcing Nophi Logging access the network?

SKILL.md names 4 domains. As links in the text: hhs.gov, cheatsheetseries.owasp.org, opentelemetry.io and docs.python.org. This is read from the text; nothing was executed.

Is Enforcing Nophi Logging safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Enforcing Nophi Logging use?

Enforcing Nophi Logging is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Enforcing Nophi Logging use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Enforcing Nophi Logging?

Skills that share tags, products or a category with Enforcing Nophi Logging: Motel Debug (kitlangton/motel, 298 stars), Agent Kill Switch (vivekchand/clawmetry, 426 stars), Clawmetry Selfcheck (vivekchand/clawmetry, 426 stars) and Logfire Instrumentation (basicmachines-co/basic-memory, 4.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Enforcing Nophi Logging?

maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,506 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 11, 2026.

Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.