OP

openevidence-multi-env-setup

Provides configuration templates to manage development, staging, and production environments for HIPAA-compliant AI systems.

Install

mkdir -p .claude/skills/openevidence-multi-env-setup && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7620" && unzip -o skill.zip -d .claude/skills/openevidence-multi-env-setup && rm skill.zip

Installs to .claude/skills/openevidence-multi-env-setup

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Multi Env Setup for OpenEvidence.
33 charsno explicit “when” trigger
Advanced

Key capabilities

  • →Configure environment-specific API keys and base URLs
  • →Implement data classification policies
  • →Enforce environment validation at startup
  • →Manage HIPAA-compliant environment separation

How it works

The skill defines environment-specific configurations and validation logic to ensure that development, staging, and production environments maintain appropriate data classification and audit levels.

Inputs & outputs

You give it
Target environment name
You get back
Validated configuration object

When to use openevidence-multi-env-setup

  • →Configure environment-specific keys
  • →Setup data classification policies
  • →Implement HIPAA-compliant environment separation

About this skill

OpenEvidence Web and Mobile Workflow Parity

Overview

Define which surface supports each step and test handoff, device, consent, and export behavior. Keep inputs minimal, separate observed facts from assumptions, and leave consequential decisions with the named accountable owner.

Prerequisites

  • A clearly bounded workflow, accountable clinical owner, and organizational policy
  • Current first-party OpenEvidence documentation and applicable institution agreements
  • Synthetic or properly authorized minimum-necessary data

Tool Discipline

Use Read, Glob, and Grep to inspect supplied policies, plans, and evidence. Use WebFetch only for current first-party OpenEvidence documentation. Use Write or Edit only when the user requests a named deliverable with an approved destination. Never expose credentials, PHI, recordings, or unrestricted environment output.

Current Contract

  • The official guide documents web and mobile experiences for Ask and Visits workflows.
  • No public dev or staging domains are documented; environment separation belongs to the institution’s test-data and rollout process.
  • Browser-specific capabilities, such as some recording inputs, must be checked against current guidance.

Authentication

Use only the official OpenEvidence web/mobile sign-in or an institution-approved access path. Do not invent API keys, OAuth clients, SDK credentials, service accounts, or private endpoints. Never ask a user to reveal a password, session token, cookie, or recovery code.

Instructions

  1. Map the workflow steps, user role, device, browser/app, data class, and expected handoffs.
  2. Read the current feature page for web/mobile differences and supported-browser notes.
  3. Test with synthetic data on each authorized surface; record unavailable or divergent behavior.
  4. Verify that copied notes, citations, recordings, and notifications stay within approved systems.
  5. Define the supported surface, fallback, training note, and re-test trigger for each step.
  6. Return a parity matrix with evidence date, owners, gaps, and rollout impact.

Approval Boundaries

Do not create or share accounts; change access, roles, agreements, consent, retention, or security settings; enter PHI; record a conversation; copy content into another system; contact a patient; make a diagnosis or treatment decision; submit billing; transmit a support packet; run a production pilot; or represent vendor capabilities without explicit approval from the accountable owner. A qualified professional remains responsible for clinical decisions.

Output

Return scope, current first-party evidence and date, data classification, workflow or findings, citations reviewed, assumptions rejected, clinical and governance owners, approval state, unresolved risk, and the exact next action. Redact patient and credential data.

Error Handling

ConditionResponse
Feature absent on one surfaceDocument the supported route; do not invent parity.
Recording input unsupportedUse a documented supported browser/device or stop that test.
Cross-device data surprisePause and route the data flow to privacy/security review.

Examples

This compact example shows the minimum reviewable handoff; adapt fields to the approved workflow without adding sensitive data.

Input:

workflow=Visits note; surfaces=Chrome+iOS; data=synthetic

Expected handoff:

parity=partial; recording=web-supported; editing=both; gaps=1

Resources

When not to use it

  • →Single-environment deployments without compliance requirements

Prerequisites

Environment-specific API keysBAA ID for production

Limitations

  • →Production requires BAA verification
  • →PHI must be enabled in production to pass validation

How it compares

This approach enforces strict environment separation and HIPAA-compliant validation at startup, rather than relying on manual configuration management.

Compared to similar skills

openevidence-multi-env-setup side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
openevidence-multi-env-setup (this skill)12moCautionAdvanced
file-uploads48moNo flagsAdvanced
graphql68moNo flagsAdvanced
vercel-webhooks-events32moCautionIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore →

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

You might also like

file-uploads

davila7

Expert at handling file uploads and cloud storage. Covers S3, Cloudflare R2, presigned URLs, multipart uploads, and image optimization. Knows how to handle large files without blocking. Use when: file upload, S3, R2, presigned URL, multipart.

438

graphql

davila7

GraphQL gives clients exactly the data they need - no more, no less. One endpoint, typed schema, introspection. But the flexibility that makes it powerful also makes it dangerous. Without proper controls, clients can craft queries that bring down your server. This skill covers schema design, resolvers, DataLoader for N+1 prevention, federation for microservices, and client integration with Apollo/urql. Key insight: GraphQL is a contract. The schema is the API documentation. Design it carefully.

624

vercel-webhooks-events

jeremylongshore

Implement Vercel webhook signature validation and event handling. Use when setting up webhook endpoints, implementing signature verification, or handling Vercel event notifications securely. Trigger with phrases like "vercel webhook", "vercel events", "vercel webhook signature", "handle vercel events", "vercel notifications".

325

identify-vault-protocol

tradingstrategy-ai

Identify an unknown vault protocol based on its smart contract address

15

exa-policy-guardrails

jeremylongshore

Implement Exa lint rules, policy enforcement, and automated guardrails. Use when setting up code quality rules for Exa integrations, implementing pre-commit hooks, or configuring CI policy checks for Exa best practices. Trigger with phrases like "exa policy", "exa lint", "exa guardrails", "exa best practices check", "exa eslint".

11

documenso-security-basics

jeremylongshore

Implement security best practices for Documenso document signing integrations. Use when securing API keys, configuring webhooks securely, or implementing document security measures. Trigger with phrases like "documenso security", "secure documenso", "documenso API key security", "documenso webhook security".

10

Search skills

Search the agent skills registry