Agent skill

Setup Openmed

by maziyarpanahi in maziyarpanahi/openmed

Collect a bounded set of de-identification policy decisions and write a deterministic, reviewable DEID-POLICY.md from the versioned local template.

Apache-2.0Auto-check passedLegal & Compliance

Install Setup Openmed

skills CLI
$ npx skills add maziyarpanahi/openmed --skill setup-openmed -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maziyarpanahi/openmed setup-openmed --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/setup-openmed .claude/skills/setup-openmed && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
setup-openmed
GitHub stars
5.5k
Token cost
~1.8k tokens
SKILL.md length
893 words
Files
2 (incl. assets)
Skills in repo
74
Repo updated
First seen
Licence
Apache-2.0

At a glance

Collect a bounded set of de-identification policy decisions and write a deterministic, reviewable DEID-POLICY.md from the versioned local template.

  • Works in 6 steps: Explain that the result is a draft… → Normalize each answer for comparison by… → If an answer is missing or invalid, stop… → …
  • A project needs explicit jurisdiction
  • SKILL.md covers When to use this skill, Bounded decision contract, Setup workflow and Local-only model rule, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Setup Openmed is an agent skill from maziyarpanahi/openmed. Collect a bounded set of de-identification policy decisions and write a deterministic, reviewable DEID-POLICY.md from the versioned local template. Use when a project needs explicit jurisdiction, recall floor, surrogate strategy, model policy, audit location, and human approval before privacy work begins.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including assets (for example `assets/DEID-POLICY.template.md`).

It sits in Legal & Compliance. The repository describes itself as: Local-first healthcare AI: clinical NER & HIPAA PII de-identification that runs 100% on-device. 2,200+ medical models, 21 languages, Apple MLX + Python, no cloud, no patient data…. The licence is Apache-2.0.

When your agent uses it

  • A project needs explicit jurisdiction
  • Surrogate strategy
  • Human approval before privacy work begins

Example prompts

  • “/setup-openmed”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Explain that the result is a draft configuration and that human approval is
  2. Normalize each answer for comparison by trimming surrounding whitespace,
  3. If an answer is missing or invalid, stop before writing the artifact. Report
  4. Read the local DEID-POLICY.template.md
  5. Resolve the user-requested project directory and require it to be an
  6. Report only that DEID-POLICY.md was written in the requested project

What it can do on your machine

Read from SKILL.md and the folder at commit 6b1bb2c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Setup Openmed loads about 1.8k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 893 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from maziyarpanahi/openmed at commit 6b1bb2c, republished under its Apache-2.0 licence (© maziyarpanahi). 893 words, ~1,752 tokens.

Download SKILL.mdSave it as .claude/skills/setup-openmed/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
setup-openmed
description
Collect a bounded set of de-identification policy decisions and write a deterministic, reviewable DEID-POLICY.md from the versioned local template. Use when a project needs explicit jurisdiction, recall floor, surrogate strategy, model policy, audit location, and human approval before privacy work begins.
license
Apache-2.0
metadata.project
OpenMed
metadata.category
de-identification
metadata.pairs
adjacent
metadata.version
1.0

Set up an OpenMed de-identification policy

Use this skill before a de-identification pipeline when the privacy decisions are not already recorded. It creates a small policy document; it does not inspect, transform, upload, or retain clinical data. The setup is local-first, deterministic, and has no mandatory network call.

The output is a draft configuration contract, not a compliance certification, legal opinion, or guarantee of de-identification. A human must review and approve the draft before it controls a run.

When to use this skill

Use it when a project needs to turn implicit privacy choices into a reviewable DEID-POLICY.md file. Use the focused de-identification skills afterward to apply or audit the selected policy.

Do not use this skill to collect a note, dataset row, identifier, model output, secret, credential, or any other source payload. The setup questions accept policy choices only. Keep logs, exceptions, reports, and fixtures free of raw sensitive values.

Bounded decision contract

Collect these five decisions, one at a time. Do not invent a sixth field or silently choose a value. The value written to the artifact must be the lowercase canonical value in the right-hand column.

DecisionBounded choices (canonical value)
Jurisdiction or operating contextus, eu, canada, research, organization-defined
Recall floor0.90, 0.95, 0.99
Surrogate strategymask, remove, replace, hash
Model policylocal-preinstalled, local-user-supplied, rules-only
Audit locationseparate-local-directory, controlled-artifact-store, no-retention

The jurisdiction choices are context labels, not findings that a law applies. For example, us may be used for a US/HIPAA-context workflow and eu for an EU/GDPR-context workflow, but the generated document must not claim that the workflow is compliant. research and organization-defined require the project's own governance review.

The recall floor is a release target, not an observed score. Do not write a metric, benchmark result, dataset name, or model claim into this artifact. replace must use deterministic, synthetic surrogates when it is later implemented; any re-identification mapping remains a separately protected secret. hash is one-way for this policy document, but hashes can still be sensitive linkage material.

Setup workflow

Follow this order exactly:

  1. Explain that the result is a draft configuration and that human approval is required. Ask only for the five decisions in the table.

  2. Normalize each answer for comparison by trimming surrounding whitespace, folding case, and treating spaces or underscores as hyphens. Match the normalized answer against the bounded choices exactly. Do not accept a free-form value, and do not infer a jurisdiction from prose.

  3. If an answer is missing or invalid, stop before writing the artifact. Report only the field name and the allowed canonical choices; never echo the answer, a source value, or exception text.

  4. Read the local DEID-POLICY.template.md and replace only its five decision placeholders:

    • {{ jurisdiction }}
    • {{ recall_floor }}
    • {{ surrogate_strategy }}
    • {{ model_policy }}
    • {{ audit_location }}

    Before substitution, require Template version: 1.0, Policy schema: 1, and exactly one occurrence of each listed placeholder with no other placeholder. If that contract differs, stop before writing and report only that the template contract is invalid. Preserve the template version, section order, checkboxes, and line endings. Do not add a timestamp, random identifier, machine path, user identity, source text, detected span, model output, or free-form rationale.

  5. Resolve the user-requested project directory and require it to be an existing local directory. The output target is exactly its direct child DEID-POLICY.md; do not accept a different filename or derive one from an answer. Refuse a symlink or any existing non-regular target. If a regular file already exists, ask for explicit permission before replacing it; never overwrite it implicitly or write through a symlink. Render to a uniquely created sibling temporary file, flush and sync its bytes, recheck the resolved parent and target immediately before replacement, and atomically replace the target. If the target appeared after the first check and no replacement was approved, stop. Clean up the temporary file on every failure.

  6. Report only that DEID-POLICY.md was written in the requested project directory and that review is pending. Never print the absolute or parent directory path, the collected answers, a source payload, or exception text.

Show full SKILL.md (222 more words)Show less

The same five canonical choices and the same template version must produce byte-for-byte identical output. Do not use the current time, environment variables, network responses, or machine-specific paths in the artifact.

Local-only model rule

This setup does not download a model or call a hosted service. With local-preinstalled, stop and ask the project owner to install or provide the approved local model if it is absent. With local-user-supplied, record no secret or personal path in DEID-POLICY.md; the caller supplies the model outside the artifact. rules-only must remain deterministic and local. A later pipeline may have its own explicitly approved setup step, but it is not part of this skill and must never be mandatory here.

Human approval gate

The template always writes DRAFT — HUMAN APPROVAL REQUIRED. Stop after the draft is written. A human reviewer must inspect the five choices, verify that the intended local model and audit handling exist, and explicitly change the status to approved through the project's review process. The setup workflow must not self-approve, sign, certify, or claim a regulatory outcome.

Handoff

Those skills inherit this artifact's guardrails. Keep any audit report limited to offsets, hashes, provenance, counts, and risk summaries; never put raw identifiers into logs, exceptions, reports, fixtures, or the policy file.

© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (assets) in skills/setup-openmed of maziyarpanahi/openmed.

  • SKILL.md
  • assets/DEID-POLICY.template.md

Open the folder on GitHubat commit 6b1bb2c

Compare with similar skills

Setup Openmed next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Setup Openmed compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Setup Openmed this skillmaziyarpanahi/openmed5.5k—~1.8kAutomated safety check: PassApache-2.0
Paper to Chinese Patent DrafterYuan1z0825/nature-skills47k1 repos~1.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Legal Clinic Client Intakeanthropics/claude-for-legal9.6k3 repos~3.2kAutomated safety check: PassApache-2.0
Paper To Cn Patentsnipp-zha/Paper-to-patent-Skill1061 repos~959Automated safety check: PassNone

Similar skills

  • Paper to Chinese Patent Drafter

    Yuan1z0825/nature-skills

    Drafts Chinese invention patent applications and technical disclosures from research papers or inventor materials, tying each claim feature to source evidence.

    47k GitHub starsUsed in 1 repo~1.1k tokens
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Legal & ComplianceAuto-check passed
  • Paper To Cn Patent

    snipp-zha/Paper-to-patent-Skill

    Convert scientific papers, theses, technical reports, source code, figures, or research manuscripts into evidence-grounded Chinese invention patent drafts.

    106 GitHub starsUsed in 1 repo~959 tokens
    Legal & ComplianceAuto-check passed
  • Employment Contract Templates

    ynulihao/AgentSkillOS

    Create employment contracts, offer letters, and HR policy documents following legal best practices.

    617 GitHub starsUsed in 12 repos~4.1k tokens
    Legal & ComplianceAuto-check passed

More from maziyarpanahi/openmed

All 74 skills in this repo
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • OpenMed Model Card Writer

    maziyarpanahi/openmed

    Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.

    5.5k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • ICD-10 Coding Assistant

    maziyarpanahi/openmed

    Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • OpenMed ETL to OMOP CDM

    maziyarpanahi/openmed

    Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.

    5.5k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Extracting SDOH and Z-Codes

    maziyarpanahi/openmed

    Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.

    5.5k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Questions about Setup Openmed

What does Setup Openmed do?

Collect a bounded set of de-identification policy decisions and write a deterministic, reviewable DEID-POLICY.md from the versioned local template. Setup Openmed is an agent skill from maziyarpanahi/openmed.md from the versioned local template.

When should I use Setup Openmed?

Setup Openmed fits situations like: A project needs explicit jurisdiction; surrogate strategy; human approval before privacy work begins.

How do I install Setup Openmed in Claude Code?

Run `npx skills add maziyarpanahi/openmed --skill setup-openmed -a claude-code`. Or copy the skill folder (skills/setup-openmed in maziyarpanahi/openmed) into .claude/skills/setup-openmed in your project. Claude Code loads it when a task matches its description.

How do I install Setup Openmed in Codex?

Run `npx skills add maziyarpanahi/openmed --skill setup-openmed -a codex`. Or copy the skill folder (skills/setup-openmed in maziyarpanahi/openmed) into .agents/skills/setup-openmed in your project. Codex loads it when a task matches its description.

Can I use Setup Openmed in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill setup-openmed -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/setup-openmed, .gemini/skills/setup-openmed, .github/skills/setup-openmed and .opencode/skills/setup-openmed in your project.

What does Setup Openmed need to run?

SKILL.md names no scripts, command-line tools or credentials: Setup Openmed is instructions for the agent only.

Does Setup Openmed access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Setup Openmed safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Setup Openmed use?

Setup Openmed is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Setup Openmed use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Setup Openmed?

Skills that share tags, products or a category with Setup Openmed: Paper to Chinese Patent Drafter (Yuan1z0825/nature-skills, 47k stars), C15t (c15t/c15t, 1.9k stars), Contract Review (evolsb/claude-legal-skill, 464 stars) and Legal Clinic Client Intake (anthropics/claude-for-legal, 9.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Setup Openmed?

maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,493 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 9, 2026.

Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.