openevidence-prod-checklist
Enforces security, HIPAA compliance, and performance standards for OpenEvidence clinical AI.
Install
mkdir -p .claude/skills/openevidence-prod-checklist && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4841" && unzip -o skill.zip -d .claude/skills/openevidence-prod-checklist && rm skill.zipInstalls to .claude/skills/openevidence-prod-checklist
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Prod Checklist for OpenEvidence.Key capabilities
- →Store API keys in a secrets manager with rotation
- →Configure request timeouts and monitor response time SLAs
- →Implement pagination for evidence result sets
- →De-identify clinical query payloads before sending
- →Validate citation URLs before displaying to clinicians
- →Configure circuit breakers and retry logic for API calls
How it works
This skill provides a checklist and validation script to ensure an OpenEvidence integration meets production readiness standards, focusing on security, compliance, and resilience.
Inputs & outputs
When to use openevidence-prod-checklist
- →Conducting pre-deployment reviews
- →Auditing integration for HIPAA compliance
- →Setting up secrets management
About this skill
OpenEvidence Clinical Go-Live Checklist
Overview
Produce a binary, owner-signed readiness decision for one clearly bounded workflow. Keep inputs minimal, separate observed facts from assumptions, and leave consequential decisions with the named accountable owner.
Prerequisites
- A clearly bounded workflow, accountable clinical owner, and organizational policy
- Current first-party OpenEvidence documentation and applicable institution agreements
- Synthetic or properly authorized minimum-necessary data
Tool Discipline
Use Read, Glob, and Grep to inspect supplied policies, plans, and evidence. Use WebFetch only for current first-party OpenEvidence documentation. Use Write or Edit only when the user requests a named deliverable with an approved destination. Never expose credentials, PHI, recordings, or unrestricted environment output.
Current Contract
- Go-live approval belongs to the accountable institution, not this skill or the product output.
- Current first-party terms, privacy, security, feature guidance, and institution agreements all matter.
- A successful technical test does not waive clinical review or data obligations.
Authentication
Use only the official OpenEvidence web/mobile sign-in or an institution-approved access path. Do not invent API keys, OAuth clients, SDK credentials, service accounts, or private endpoints. Never ask a user to reveal a password, session token, cookie, or recovery code.
Instructions
- Freeze workflow scope, users, surfaces, data classes, dependencies, success measures, and exclusions.
- Verify account/access lifecycle, agreements, PHI boundary, consent, retention, approved exports, and security review.
- Complete synthetic acceptance tests and clinician-led evidence/citation review across normal and failure cases.
- Verify training, support contacts, incident response, downtime alternative, and rollback authority.
- Record unresolved items as blockers or explicitly accepted risks with named decision owners.
- Issue go, conditional-go, or no-go with evidence links, signatures, launch window, and first review date.
Approval Boundaries
Do not create or share accounts; change access, roles, agreements, consent, retention, or security settings; enter PHI; record a conversation; copy content into another system; contact a patient; make a diagnosis or treatment decision; submit billing; transmit a support packet; run a production pilot; or represent vendor capabilities without explicit approval from the accountable owner. A qualified professional remains responsible for clinical decisions.
Output
Return scope, current first-party evidence and date, data classification, workflow or findings, citations reviewed, assumptions rejected, clinical and governance owners, approval state, unresolved risk, and the exact next action. Redact patient and credential data.
Error Handling
| Condition | Response |
|---|---|
| Owner unsigned | No-go. |
| Critical control unknown | No-go until confirmed in writing. |
| Rollback untested | Run a tabletop or keep the workflow in pilot. |
Examples
This compact example shows the minimum reviewable handoff; adapt fields to the approved workflow without adding sensitive data.
Input:
workflow=Visits notes; launch=2026-10-01; cohort=10; approvals=matrix
Expected handoff:
decision=no-go; blockers=consent-script+rollback-test; owners=assigned
Resources
Prerequisites
How it compares
This checklist enforces HIPAA-grade security, citation verification, and SLA discipline for healthcare-adjacent systems, which is more rigorous than a general API integration.
Compared to similar skills
openevidence-prod-checklist side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| openevidence-prod-checklist (this skill) | 1 | 2mo | Review | Advanced |
| windows-ui-automation | 17 | 10mo | Review | Advanced |
| linux-production-shell-scripts | 7 | 8mo | Review | Intermediate |
| cursor-prod-checklist | 4 | 2mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
windows-ui-automation
martinholovsky
Expert in Windows UI Automation (UIA) and Win32 APIs for desktop automation. Specializes in accessible, secure automation of Windows applications including element discovery, input simulation, and process interaction. HIGH-RISK skill requiring strict security controls for system access.
linux-production-shell-scripts
davila7
This skill should be used when the user asks to "create bash scripts", "automate Linux tasks", "monitor system resources", "backup files", "manage users", or "write production shell scripts". It provides ready-to-use shell script templates for system administration.
cursor-prod-checklist
jeremylongshore
Execute production readiness checklist for Cursor IDE setup. Triggers on "cursor production", "cursor ready", "cursor checklist", "optimize cursor setup". Use when working with cursor prod checklist functionality. Trigger with phrases like "cursor prod checklist", "cursor checklist", "cursor".
posthog-enterprise-rbac
jeremylongshore
Configure PostHog enterprise SSO, role-based access control, and organization management. Use when implementing SSO integration, configuring role-based permissions, or setting up organization-level controls for PostHog. Trigger with phrases like "posthog SSO", "posthog RBAC", "posthog enterprise", "posthog roles", "posthog permissions", "posthog SAML".
prowler-provider
prowler-cloud
Creates new Prowler cloud providers or adds services to existing providers. Trigger: When extending Prowler SDK provider architecture (adding a new provider or a new service to an existing provider).
custom-workers
ruvnet
Create and run custom background analysis workers with composable phases. Use when you need automated code analysis, security scanning, pattern learning, or API documentation generation.