CtrlK
BlogDocsLog inGet started
Tessl Logo

ask-openmed

Choose the first OpenMed workflow skill for an intake, privacy, extraction, exchange, or verification request using deterministic local routing. Use when a goal is broad, spans several clinical-data stages, or leaves the data-sensitivity status unclear; the privacy gate is selected before downstream work when raw clinical or personal content may be present.

71

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Ask OpenMed

Use this skill as the first pass when a request does not name a focused OpenMed workflow. It selects an existing skill identifier; it does not process input, download a model, call a service, or make a clinical decision. No mandatory network call is part of this route.

Deterministic routing contract

Apply these rules in order:

  1. Normalize only the stated goal: lowercase it, trim surrounding whitespace, and collapse repeated whitespace. Do not inspect or copy the data payload.
  2. Apply the intake boundary. If the goal matches an Intake row, select the first matching intake skill even when the goal also names a later stage. If sensitivity is unclear, its next handoff is the privacy gate: deidentifying-clinical-text, before extraction, exchange, or verification sees the parsed content.
  3. For a goal with no intake cue, apply the privacy override. If it asks to analyze, extract, exchange, share, upload, or verify clinical or personal content and is not explicitly marked safe, start at the privacy gate. The only safe markers are synthetic input, synthetic note, synthetic record, synthetic dataset, input is synthetic, data is synthetic, already de-identified, and already deidentified. A marker does not count when no, not, never, unknown, or uncertain occurs in the four normalized words before it. Treat every ambiguous safety statement as sensitive.
  4. Otherwise inspect the remaining tables in the fixed handoff order shown below. Treat each comma-separated cue as a case-insensitive substring of the normalized goal, and select the first matching row. Every cue cell is a comma-separated list of alternatives; conjunctions have no special meaning. Do not add synonyms or infer cues from the payload. This stage order and row order break every tie.
  5. If no row matches, use building-with-openmed as the orientation fallback.

Route output should contain only the selected category, skill identifier, matched rule index, and next handoff. Never echo the request, input values, exception text, or detected spans into a log or report.

For a multi-stage request, route one stage at a time in this fixed handoff order: intake → privacy → extraction → exchange → verification. A later stage does not bypass the privacy gate merely because it was named first.

Intake

Choose the first skill for turning an external document or record format into local, processable input.

Goal cuesFirst skillContinue with
laboratory table, lab tableextracting-lab-tablesprivacy, then verification
scan, fax, image, PDF, CSV, table, document OCRingesting-clinical-documentsprivacy, then extraction
C-CDA, CCD, CDA XMLparsing-ccda-documentsprivacy, then extraction
HL7 v2, ADT, ORU, MDM, OBX, pipe-delimited feedparsing-hl7v2-messagesprivacy, then extraction
DICOM header, DICOM-SR metadataextracting-dicom-metadataprivacy, then extraction
pull FHIR records, page FHIR records, FHIR serverfetching-fhir-resourcesprivacy, then extraction

Privacy

Use the privacy table both for an explicit privacy goal and for the privacy override. The first row is the default gate for unspecified sensitive input.

Goal cuesFirst skillContinue with
remove clinical identifiers, mask clinical identifiers, redact clinical text, anonymize clinical text, de-identify clinical textdeidentifying-clinical-textextraction or exchange
find identifiers, detect identifiers, PII entitiesextracting-pii-entitiesde-identification or review
privacy policy, privacy profileconfiguring-privacy-policiesde-identification
PHI in logs, PHI in errors, PHI in telemetry, no-PHI loggingenforcing-nophi-loggingverification
de-identify non-English text, multilingual de-identificationdeidentifying-multilingual-textextraction
stable pseudonyms, approved linkage pseudonymspseudonymizing-for-gdprverification

Extraction

Choose the focused skill after intake and privacy handling when the request is about finding or structuring clinical meaning.

Goal cuesFirst skillContinue with
diseases, drugs, anatomy, genes, clinical NERextracting-clinical-entitiesexchange or verification
custom entity labels, zero-shot extractionrunning-zeroshot-nerexchange or verification
housing, food, work, transport, SDOHextracting-sdohverification
lab values, units, reference ranges, abnormal flagsparsing-lab-valuesterminology or exchange
radiology findings, radiology measurements, radiology impressionstructuring-radiology-reportsexchange or verification
note sections, clinical sections, section segmentationsegmenting-clinical-sectionsextraction

Exchange

Choose an exchange skill only after the source is safe to handle. These skills may use a user-supplied endpoint or terminology service; this router itself performs no network call.

Goal cuesFirst skillContinue with
FHIR R4 resources, export to FHIRexporting-to-fhirbundle or conformance verification
FHIR transaction Bundle, FHIR batch Bundleassembling-fhir-bundlesconformance verification
FHIR Bulk Data export, bulk FHIRexporting-bulk-fhirprivacy, then extraction
SMART-on-FHIR app, SMART-on-FHIR launchscaffolding-smart-on-fhirconformance verification
terminology validation, terminology expansion, terminology translation, terminology serverquerying-terminology-serviceexchange or verification

Verification

Use verification routes for a stated release, safety, leakage, audit, risk, or conformance check. If the source is not explicitly safe, the privacy override still wins first.

Goal cuesFirst skillDecision or handoff
residual identifiers, de-identification leakageauditing-deid-leakageblock release on a finding
de-identification audit trail, no-PHI audit trailauditing-deidentification-runsretain offsets, hashes, and provenance
leakage gate, release leakageevaluating-with-leakage-gatesfail closed on leakage
re-identification risk, k-anonymity, quasi-identifiersreviewing-reidentification-riskreview residual risk
Safe Harborauditing-safe-harbor-checklistreview the no-PHI report
FHIR US Core, USCDI conformancevalidating-us-corecorrect the resource before exchange
HIPAA privacy checklist, HIPAA security checklistchecking-hipaa-complianceaddress gaps before release

Ambiguous goals and escalation examples

Use the privacy override and the fixed handoff order for ambiguous requests:

These are routing examples only. Keep all demonstrations synthetic or placeholder-based, and keep route diagnostics free of source content.

Repository
maziyarpanahi/openmed
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.