OP

openevidence-prod-checklist

Enforces security, HIPAA compliance, and performance standards for OpenEvidence clinical AI.

Install

mkdir -p .claude/skills/openevidence-prod-checklist && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4841" && unzip -o skill.zip -d .claude/skills/openevidence-prod-checklist && rm skill.zip

Installs to .claude/skills/openevidence-prod-checklist

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Prod Checklist for OpenEvidence.
32 charsno explicit “when” trigger
Advanced

Key capabilities

  • →Store API keys in a secrets manager with rotation
  • →Configure request timeouts and monitor response time SLAs
  • →Implement pagination for evidence result sets
  • →De-identify clinical query payloads before sending
  • →Validate citation URLs before displaying to clinicians
  • →Configure circuit breakers and retry logic for API calls

How it works

This skill provides a checklist and validation script to ensure an OpenEvidence integration meets production readiness standards, focusing on security, compliance, and resilience.

Inputs & outputs

You give it
OpenEvidence API integration
You get back
A production-ready OpenEvidence integration with secure authentication, reliable API integration, complete error handling, and HIPAA-compliant security

When to use openevidence-prod-checklist

  • →Conducting pre-deployment reviews
  • →Auditing integration for HIPAA compliance
  • →Setting up secrets management

About this skill

OpenEvidence Clinical Go-Live Checklist

Overview

Produce a binary, owner-signed readiness decision for one clearly bounded workflow. Keep inputs minimal, separate observed facts from assumptions, and leave consequential decisions with the named accountable owner.

Prerequisites

  • A clearly bounded workflow, accountable clinical owner, and organizational policy
  • Current first-party OpenEvidence documentation and applicable institution agreements
  • Synthetic or properly authorized minimum-necessary data

Tool Discipline

Use Read, Glob, and Grep to inspect supplied policies, plans, and evidence. Use WebFetch only for current first-party OpenEvidence documentation. Use Write or Edit only when the user requests a named deliverable with an approved destination. Never expose credentials, PHI, recordings, or unrestricted environment output.

Current Contract

  • Go-live approval belongs to the accountable institution, not this skill or the product output.
  • Current first-party terms, privacy, security, feature guidance, and institution agreements all matter.
  • A successful technical test does not waive clinical review or data obligations.

Authentication

Use only the official OpenEvidence web/mobile sign-in or an institution-approved access path. Do not invent API keys, OAuth clients, SDK credentials, service accounts, or private endpoints. Never ask a user to reveal a password, session token, cookie, or recovery code.

Instructions

  1. Freeze workflow scope, users, surfaces, data classes, dependencies, success measures, and exclusions.
  2. Verify account/access lifecycle, agreements, PHI boundary, consent, retention, approved exports, and security review.
  3. Complete synthetic acceptance tests and clinician-led evidence/citation review across normal and failure cases.
  4. Verify training, support contacts, incident response, downtime alternative, and rollback authority.
  5. Record unresolved items as blockers or explicitly accepted risks with named decision owners.
  6. Issue go, conditional-go, or no-go with evidence links, signatures, launch window, and first review date.

Approval Boundaries

Do not create or share accounts; change access, roles, agreements, consent, retention, or security settings; enter PHI; record a conversation; copy content into another system; contact a patient; make a diagnosis or treatment decision; submit billing; transmit a support packet; run a production pilot; or represent vendor capabilities without explicit approval from the accountable owner. A qualified professional remains responsible for clinical decisions.

Output

Return scope, current first-party evidence and date, data classification, workflow or findings, citations reviewed, assumptions rejected, clinical and governance owners, approval state, unresolved risk, and the exact next action. Redact patient and credential data.

Error Handling

ConditionResponse
Owner unsignedNo-go.
Critical control unknownNo-go until confirmed in writing.
Rollback untestedRun a tabletop or keep the workflow in pilot.

Examples

This compact example shows the minimum reviewable handoff; adapt fields to the approved workflow without adding sensitive data.

Input:

workflow=Visits notes; launch=2026-10-01; cohort=10; approvals=matrix

Expected handoff:

decision=no-go; blockers=consent-script+rollback-test; owners=assigned

Resources

Prerequisites

Production OpenEvidence API credentialsSecrets manager configured (Vault, AWS Secrets Manager, or GCP Secret Manager)HIPAA-compliant monitoring stackBusiness Associate Agreement (BAA) executed with OpenEvidence

How it compares

This checklist enforces HIPAA-grade security, citation verification, and SLA discipline for healthcare-adjacent systems, which is more rigorous than a general API integration.

Compared to similar skills

openevidence-prod-checklist side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
openevidence-prod-checklist (this skill)12moReviewAdvanced
windows-ui-automation1710moReviewAdvanced
linux-production-shell-scripts78moReviewIntermediate
cursor-prod-checklist42moReviewIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore →

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

You might also like

windows-ui-automation

martinholovsky

Expert in Windows UI Automation (UIA) and Win32 APIs for desktop automation. Specializes in accessible, secure automation of Windows applications including element discovery, input simulation, and process interaction. HIGH-RISK skill requiring strict security controls for system access.

17126

linux-production-shell-scripts

davila7

This skill should be used when the user asks to "create bash scripts", "automate Linux tasks", "monitor system resources", "backup files", "manage users", or "write production shell scripts". It provides ready-to-use shell script templates for system administration.

746

cursor-prod-checklist

jeremylongshore

Execute production readiness checklist for Cursor IDE setup. Triggers on "cursor production", "cursor ready", "cursor checklist", "optimize cursor setup". Use when working with cursor prod checklist functionality. Trigger with phrases like "cursor prod checklist", "cursor checklist", "cursor".

434

posthog-enterprise-rbac

jeremylongshore

Configure PostHog enterprise SSO, role-based access control, and organization management. Use when implementing SSO integration, configuring role-based permissions, or setting up organization-level controls for PostHog. Trigger with phrases like "posthog SSO", "posthog RBAC", "posthog enterprise", "posthog roles", "posthog permissions", "posthog SAML".

13

prowler-provider

prowler-cloud

Creates new Prowler cloud providers or adds services to existing providers. Trigger: When extending Prowler SDK provider architecture (adding a new provider or a new service to an existing provider).

13

custom-workers

ruvnet

Create and run custom background analysis workers with composable phases. Use when you need automated code analysis, security scanning, pattern learning, or API documentation generation.

12

Search skills

Search the agent skills registry