Motel Debug
kitlangton/motel
Debug applications with motel, a local OpenTelemetry ingest and query server.
Add a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment.
$ npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install maziyarpanahi/openmed enforcing-nophi-logging --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/enforcing-nophi-logging .claude/skills/enforcing-nophi-logging && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "enforcing-nophi-logging" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/enforcing-nophi-logging into .claude/skills/enforcing-nophi-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enforcing-nophi-logging", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/maziyarpanahi/openmed/tree/master/skills/enforcing-nophi-loggingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install maziyarpanahi/openmed enforcing-nophi-logging --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/enforcing-nophi-logging .agents/skills/enforcing-nophi-logging && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "enforcing-nophi-logging" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/enforcing-nophi-logging into .agents/skills/enforcing-nophi-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enforcing-nophi-logging", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install maziyarpanahi/openmed enforcing-nophi-logging --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/enforcing-nophi-logging .cursor/skills/enforcing-nophi-logging && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "enforcing-nophi-logging" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/enforcing-nophi-logging into .cursor/skills/enforcing-nophi-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enforcing-nophi-logging", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/maziyarpanahi/openmed.git --path skills/enforcing-nophi-logging--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install maziyarpanahi/openmed enforcing-nophi-logging --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/enforcing-nophi-logging .gemini/skills/enforcing-nophi-logging && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "enforcing-nophi-logging" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/enforcing-nophi-logging into .gemini/skills/enforcing-nophi-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enforcing-nophi-logging", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install maziyarpanahi/openmed enforcing-nophi-loggingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/enforcing-nophi-logging .github/skills/enforcing-nophi-logging && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "enforcing-nophi-logging" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/enforcing-nophi-logging into .github/skills/enforcing-nophi-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enforcing-nophi-logging", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install maziyarpanahi/openmed enforcing-nophi-logging --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/enforcing-nophi-logging .opencode/skills/enforcing-nophi-logging && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "enforcing-nophi-logging" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/enforcing-nophi-logging into .opencode/skills/enforcing-nophi-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "enforcing-nophi-logging", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
enforcing-nophi-loggingAdd a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment.
Enforcing Nophi Logging is an agent skill from maziyarpanahi/openmed. Add a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment. Use when the user wants a Python logging.Filter that redacts protected health information before records are emitted, wants to keep PHI out of OpenTelemetry spans or error trackers, needs structured no-PHI log fields, or is worried that logs and stack traces are leaking patient data. Trigger on "scrub logs", "redact PHI from logs", "no-PHI logging", "logging filter", "telemetry…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Observability and Debugging. It works with OpenTelemetry and Python. The repository describes itself as: Local-first healthcare AI: clinical NER and HIPAA PII de-identification on hardware you control. 2,200+ medical models, 35 model-backed PII languages, and Python, MLX, Android… The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 34d7b8c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
hhs.govcheatsheetseries.owasp.orgopentelemetry.iodocs.python.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Enforcing Nophi Logging loads about 1.9k tokens when it runs. Until then it costs about 157 tokens; SKILL.md has 563 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from maziyarpanahi/openmed at commit 34d7b8c, republished under its Apache-2.0 licence (© maziyarpanahi). 563 words, ~1,900 tokens.
.claude/skills/enforcing-nophi-logging/SKILL.md (or your agent's skills folder).Logs are a top breach vector: a clinical string lands in a log line, gets shipped to a centralized log store and an error tracker, and is now PHI sitting outside the de-id boundary. OpenMed's local-first stance says no raw PHI in logs, caches, or error reports — this skill enforces it with a redaction guard that runs before any record is emitted.
logging.Filter (or OTel processor) that redacts PHI pre-emit.import logging
import re
import openmed
# Cheap regex pre-filter for the highest-risk structured identifiers. This runs
# on every record, so keep it fast; the model is the fallback for free-text PHI.
_FAST_PATTERNS = [
(re.compile(r"\b\d{3}-\d{2}-\d{4}\b"), "[SSN]"),
(re.compile(r"\b\d{16}\b"), "[CARD]"),
(re.compile(r"\b[\w.+-]+@[\w-]+\.[\w.-]+\b"), "[EMAIL]"),
(re.compile(r"\b(?:\+?\d[\d().\-\s]{7,}\d)\b"), "[PHONE]"),
]
class NoPHIFilter(logging.Filter):
"""Redact PHI from a log record before it is emitted. Fail closed."""
def __init__(self, model_name: str | None = None, use_model: bool = True):
super().__init__()
self.model_name = model_name
self.use_model = use_model
def filter(self, record: logging.LogRecord) -> bool:
try:
message = record.getMessage()
record.msg = self._scrub(message)
record.args = () # message already rendered & scrubbed
except Exception:
# Never let the logger leak on error — drop the message, keep the level.
record.msg = "[REDACTED: scrub error]"
record.args = ()
return True # keep the (now-clean) record
def _scrub(self, text: str) -> str:
for pattern, tag in _FAST_PATTERNS:
text = pattern.sub(tag, text)
if not self.use_model:
return text
# Model fallback for free-text PHI (names, locations, dates). Replace by
# offset, right-to-left, so earlier offsets stay valid.
spans = openmed.extract_pii(text, model_name=self.model_name) \
if self.model_name else openmed.extract_pii(text)
for e in sorted(spans.entities, key=lambda s: s.start, reverse=True):
text = text[:e.start] + f"[{e.label}]" + text[e.end:]
return text
# Attach to every handler that might emit clinical text.
handler = logging.StreamHandler()
handler.addFilter(NoPHIFilter(model_name="OpenMed/Privacy-PII-Detection"))
logging.getLogger("openmed.service").addHandler(handler)Don't log the note and scrub it — log about it without the text in the first place:
logger.info(
"deidentified note",
extra={
"doc_id": doc_id, # opaque id, not the text
"phi_entity_count": len(result.entities),
"phi_labels": sorted({e.label for e in result.entities}),
"char_len": len(text),
# offsets/hashes for debugging; never the plaintext span
"phi_offsets": [(e.start, e.end) for e in result.entities],
},
)Redaction is the safety net; not logging PHI is the actual fix.
SpanProcessor.on_end (or attribute hook) that runs the same
_scrub over string span attributes and events before export.before_send hook (e.g. Sentry) that scrubs
exception messages, breadcrumbs, and request bodies. Stack traces often embed
the offending input — scrub the message, not just the frames.openmed.extract_pii) for free-text PHI on the
sinks that carry clinical narrative; skip it on hot paths where regex suffices.openmed.extract_pii (and optionally the regex pre-filter) as the PHI
detector — the same engine documented in extracting-pii-entities.building-with-openmed: this is the runtime guard for the local-first,
no-PHI-in-artifacts rule.gating-deid-leakage: the gate proves the model doesn't leak;
this guard proves your logs and traces don't leak.auditing-deidentification-runs: route audit output through the same
no-PHI discipline (offsets/hashes, never plaintext).record.args must be cleared after scrubbing. If you rewrite record.msg
but leave %s args, the formatter re-injects raw PHI downstream.f"failed on {note}" leaks; scrub
exception text and error-tracker payloads, not just logger.info calls.logging.Filter API:
https://docs.python.org/3/library/logging.html#filter-objectsopenmed.extract_pii (openmed/core/pii.py).© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/enforcing-nophi-logging of maziyarpanahi/openmed.
Open the folder on GitHubat commit 34d7b8c
Enforcing Nophi Logging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Enforcing Nophi Logging this skillmaziyarpanahi/openmed | 5.5k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Motel Debugkitlangton/motel | 298 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Agent Kill Switchvivekchand/clawmetry | 426 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Clawmetry Selfcheckvivekchand/clawmetry | 426 | — | ~515 | Automated safety check: Pass | MIT | |
| Logfire Instrumentationbasicmachines-co/basic-memory | 4.1k | — | ~2.3k | Automated safety check: Pass | AGPL-3.0 | |
| Clawmetryvivekchand/clawmetry | 426 | — | ~992 | Automated safety check: Pass | MIT |
kitlangton/motel
Debug applications with motel, a local OpenTelemetry ingest and query server.
vivekchand/clawmetry
Give the human an off switch and a cost meter for the coding agents on this machine, using ClawMetry.
vivekchand/clawmetry
Read your own agent telemetry from ClawMetry (waste, progress, cost) and act on it before finishing a task.
basicmachines-co/basic-memory
Adds Pydantic Logfire tracing, logging and metrics to Python, JavaScript or TypeScript and Rust projects, with the correct setup order and library extras.
vivekchand/clawmetry
Real-time observability for OpenClaw agents — local dashboard + optional encrypted cloud sync.
microsoft/skills
Azure Monitor OpenTelemetry Distro for Python. An agent skill from microsoft/skills.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
maziyarpanahi/openmed
Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
maziyarpanahi/openmed
Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.
maziyarpanahi/openmed
Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.
maziyarpanahi/openmed
Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.
Works with
Categories
Add a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment. Enforcing Nophi Logging is an agent skill from maziyarpanahi/openmed. Add a logging and telemetry guard that scrubs or blocks PHI from logs, traces, and error reports around an OpenMed deployment.
Enforcing Nophi Logging fits situations like: the user wants a Python logging.Filter that redacts protected health information before records are emitted; wants to keep PHI out of OpenTelemetry spans; needs structured no-PHI log fields; is worried that logs and stack traces are leaking patient data.
Run `npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a claude-code`. Or copy the skill folder (skills/enforcing-nophi-logging in maziyarpanahi/openmed) into .claude/skills/enforcing-nophi-logging in your project. Claude Code loads it when a task matches its description.
Run `npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a codex`. Or copy the skill folder (skills/enforcing-nophi-logging in maziyarpanahi/openmed) into .agents/skills/enforcing-nophi-logging in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill enforcing-nophi-logging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/enforcing-nophi-logging, .gemini/skills/enforcing-nophi-logging, .github/skills/enforcing-nophi-logging and .opencode/skills/enforcing-nophi-logging in your project.
SKILL.md names no scripts, command-line tools or credentials: Enforcing Nophi Logging is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 4 domains. As links in the text: hhs.gov, cheatsheetseries.owasp.org, opentelemetry.io and docs.python.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Enforcing Nophi Logging is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Enforcing Nophi Logging: Motel Debug (kitlangton/motel, 298 stars), Agent Kill Switch (vivekchand/clawmetry, 426 stars), Clawmetry Selfcheck (vivekchand/clawmetry, 426 stars) and Logfire Instrumentation (basicmachines-co/basic-memory, 4.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,506 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 11, 2026.
Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.