C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
Apply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later.
$ npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install maziyarpanahi/openmed pseudonymizing-for-gdpr --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pseudonymizing-for-gdpr .claude/skills/pseudonymizing-for-gdpr && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pseudonymizing-for-gdpr" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/pseudonymizing-for-gdpr into .claude/skills/pseudonymizing-for-gdpr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymizing-for-gdpr", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/maziyarpanahi/openmed/tree/master/skills/pseudonymizing-for-gdprType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install maziyarpanahi/openmed pseudonymizing-for-gdpr --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/pseudonymizing-for-gdpr .agents/skills/pseudonymizing-for-gdpr && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pseudonymizing-for-gdpr" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/pseudonymizing-for-gdpr into .agents/skills/pseudonymizing-for-gdpr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymizing-for-gdpr", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install maziyarpanahi/openmed pseudonymizing-for-gdpr --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/pseudonymizing-for-gdpr .cursor/skills/pseudonymizing-for-gdpr && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pseudonymizing-for-gdpr" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/pseudonymizing-for-gdpr into .cursor/skills/pseudonymizing-for-gdpr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymizing-for-gdpr", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/maziyarpanahi/openmed.git --path skills/pseudonymizing-for-gdpr--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install maziyarpanahi/openmed pseudonymizing-for-gdpr --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/pseudonymizing-for-gdpr .gemini/skills/pseudonymizing-for-gdpr && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pseudonymizing-for-gdpr" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/pseudonymizing-for-gdpr into .gemini/skills/pseudonymizing-for-gdpr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymizing-for-gdpr", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install maziyarpanahi/openmed pseudonymizing-for-gdprInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/pseudonymizing-for-gdpr .github/skills/pseudonymizing-for-gdpr && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pseudonymizing-for-gdpr" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/pseudonymizing-for-gdpr into .github/skills/pseudonymizing-for-gdpr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymizing-for-gdpr", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install maziyarpanahi/openmed pseudonymizing-for-gdpr --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/pseudonymizing-for-gdpr .opencode/skills/pseudonymizing-for-gdpr && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pseudonymizing-for-gdpr" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/pseudonymizing-for-gdpr into .opencode/skills/pseudonymizing-for-gdpr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pseudonymizing-for-gdpr", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pseudonymizing-for-gdprApply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later.
Pseudonymizing For Gdpr is an agent skill from maziyarpanahi/openmed. Apply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later. Use when the user must process EU personal/health data under GDPR, asks for pseudonymization vs anonymization, needs Art. 4(5) / Art. 9 / Recital 26 alignment, wants a reversible mapping/key vault held apart from the data, or needs controlled re-linkage. Covers openmed.deidentify(policy="gdprpseudonymization", keepmapping=True), storing the mapping in…
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Local-first healthcare AI: clinical NER & HIPAA PII de-identification that runs 100% on-device. 2,200+ medical models, 21 languages, Apple MLX + Python, no cloud, no patient data…. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6b1bb2c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
gdpr-info.euenisa.europa.euedpb.europa.euFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pseudonymizing For Gdpr loads about 2k tokens when it runs. Until then it costs about 173 tokens; SKILL.md has 785 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from maziyarpanahi/openmed at commit 6b1bb2c, republished under its Apache-2.0 licence (© maziyarpanahi). 785 words, ~1,973 tokens.
.claude/skills/pseudonymizing-for-gdpr/SKILL.md (or your agent's skills folder).Pseudonymization under the GDPR (Art. 4(5)) means processing personal data so it "can no longer be attributed to a specific data subject without the use of additional information" — provided that additional information (the re-linkage key) is "kept separately and is subject to technical and organisational measures." Crucially, pseudonymized data is still personal data (Recital 26): re-linkage is possible, so GDPR still applies. This is the opposite of anonymization, where re-identification is irreversibly prevented and the data falls outside the GDPR.
OpenMed implements this with a single reversible de-identification pass plus a mapping you store away from the data. This skill covers producing that mapping, vaulting the key separately, and re-linking under authorization.
Do not use this when the goal is irreversible anonymization for open release
— there, drop the mapping entirely and gate residual risk with
reviewing-reidentification-risk. Pseudonymization keeps a key; anonymization
must not.
import openmed
# Synthetic record — never run this skill's examples on real PHI.
note = "Patient Maria Schmidt (ID 4471) seen 2024-03-02; contact maria@example.de."
result = openmed.deidentify(
note,
method="replace", # realistic surrogates, not [LABEL] holes
policy="gdpr_pseudonymization", # bundled GDPR profile
keep_mapping=True, # produce the reversible re-linkage map
consistent=True, # same input -> same surrogate in the doc
seed=20240302, # cross-run reproducibility of surrogates
)
pseudonymized_text = result.deidentified_text # safe to process / analyze
relink_key = result.mapping # surrogate -> original; SECRETresult.deidentified_text is the pseudonymized payload. result.mapping is the
"additional information" GDPR Art. 4(5) requires be kept separately — it is the
key that makes re-linkage possible, and therefore the most sensitive artifact in
the whole flow.
method="replace"
with policy="gdpr_pseudonymization" and keep_mapping=True. Replacement
surrogates keep the text usable for downstream NLP while remaining
non-identifying. consistent=True (optionally with seed=) makes repeated
mentions resolve to one stable surrogate so intra-document linkage survives.deidentify returns,
route result.deidentified_text to your working store and result.mapping
to a separate, access-controlled key vault — different system, different
credentials, different backups. Never persist them in the same row, file,
bucket, or log line. This separation is the technical-and-organisational
measure that makes the data pseudonymized rather than just "personal data
with PII in it."analyze_text, analytics,
model training, or transfer on deidentified_text. The key never leaves the
vault during ordinary processing.openmed.reidentify(deidentified_text, mapping). Log that a re-linkage
happened (who, when, why, record id) — but never log the restored plaintext.reviewing-reidentification-risk before
relying on it.extracting-pii-entities / configuring-privacy-policies: confirm
the detector recall and the active policy profile before pseudonymizing, since
any identifier the detector misses leaks into deidentified_text.from openmed import deidentify, reidentify; the same
capability is exposed as MCP tool openmed_deidentify and REST /deidentify.
Pass policy="gdpr_pseudonymization", keep_mapping=True.auditing-deid-leakage: scan result.deidentified_text for residual
identifiers before it leaves the boundary — pseudonymization is only as strong
as detection.reviewing-reidentification-risk: quasi-identifier (age, ZIP, dates)
re-identification still applies to pseudonymized data; score k-anonymity on the
output and document residual risk.mapping exists anywhere, the data
is personal data under Recital 26. Do not market a keep_mapping=True output
as "anonymous."method="replace" swaps the
identifier text, but free-text age, rare diagnosis, ZIP, or admission dates
remain. Pseudonymization does not address singling-out; pair with QI risk
scoring.seed makes surrogates stable
across runs (good for linkage) but means an attacker who learns the seed and
algorithm can reproduce surrogates — keep the seed with the key, not the data.© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/pseudonymizing-for-gdpr of maziyarpanahi/openmed.
Open the folder on GitHubat commit 6b1bb2c
Pseudonymizing For Gdpr next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pseudonymizing For Gdpr this skillmaziyarpanahi/openmed | 5.5k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 586 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Pii Contract Analyzegregmos/PII-Shield | 149 | — | ~8.9k | Automated safety check: Notes | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
goSprinto/compliance-skills
Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
maziyarpanahi/openmed
Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
maziyarpanahi/openmed
Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.
maziyarpanahi/openmed
Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.
maziyarpanahi/openmed
Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.
Categories
Apply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later. Pseudonymizing For Gdpr is an agent skill from maziyarpanahi/openmed. Apply GDPR-grade pseudonymization to clinical or personal text with OpenMed, keeping a separately-held re-linkage key so the data can be controlled-re-linked later.
Pseudonymizing For Gdpr fits situations like: the user must process EU personal/health data under GDPR; asks for pseudonymization vs anonymization.
Run `npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a claude-code`. Or copy the skill folder (skills/pseudonymizing-for-gdpr in maziyarpanahi/openmed) into .claude/skills/pseudonymizing-for-gdpr in your project. Claude Code loads it when a task matches its description.
Run `npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a codex`. Or copy the skill folder (skills/pseudonymizing-for-gdpr in maziyarpanahi/openmed) into .agents/skills/pseudonymizing-for-gdpr in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill pseudonymizing-for-gdpr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pseudonymizing-for-gdpr, .gemini/skills/pseudonymizing-for-gdpr, .github/skills/pseudonymizing-for-gdpr and .opencode/skills/pseudonymizing-for-gdpr in your project.
SKILL.md names no scripts, command-line tools or credentials: Pseudonymizing For Gdpr is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 3 domains. As links in the text: gdpr-info.eu, enisa.europa.eu and edpb.europa.eu. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pseudonymizing For Gdpr is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pseudonymizing For Gdpr: C15t (c15t/c15t, 1.9k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars), Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars) and Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,493 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 9, 2026.
Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.