Skip to content
FunCoding

Search

Search docs, Skills and MCP

abridge-prod-checklist

Run an evidence-backed Abridge production readiness decision across clinical, privacy, security, EHR, training, support, and rollback owners. Use when preparing a pilot or cohort expansion. Trigger with "review Abridge go-live".

安全2.8kskills/.curated/abridge-prod-checklist/SKILL.md

Install

Send this to Claude Code, Codex or Cursor. The agent checks the Skill for safety first and installs it only after you confirm.

读取 https://funcoding.ai/skills/jeremylongshore/tons-of-skills-marketplace/abridge-prod-checklist/install.md ,按里面的步骤帮我安装这个 Skill。

SKILL.md

Abridge Production Go-Live Checklist

Overview

Convert the implementation plan into a fail-closed go/no-go record. A green technical test is insufficient without consent, clinical review, EHR mapping, access, privacy, training, support, monitoring, and rollback evidence.

Prerequisites

  • The authorized Abridge environment, clinical owner, and health-system policy set
  • Current tenant-specific implementation evidence for every private interface in scope
  • Synthetic data or the organization's formally approved test-record procedure

Tool Discipline

Use Read, Glob, and Grep to inspect repository configuration, adapters, tests, policies, and existing evidence. Use WebFetch only for current official Abridge, HHS, or named EHR documentation. Use Write or Edit only after confirming scope, environment, owners, patient-data boundary, and approval state. These tools do not confer access to Abridge, an EHR, or a clinical record; return exact operator steps or an approval-gated handoff for live actions.

Current Contract

  • Abridge is used through clinical and EHR-integrated workflows that retain clinician review.
  • Abridge publicly describes enterprise security and governance, while tenant-specific control evidence may require Trust Center access or implementation records.
  • Care-setting features and downstream behavior must be verified for the licensed tenant and cohort.

Authentication

Use only the health system's provisioned Abridge application access, SSO, administrative role, or tenant-specific partner authentication documented for the approved environment. Do not infer public API credentials, reuse production secrets in tests, or expose tokens and session material. Verify identity owner, least privilege, environment binding, storage, rotation, and revocation before any authenticated action.

Instructions

  1. Freeze environment, cohort, care setting, note types, capabilities, owners, date, and change ticket.
  2. Use Read, Glob, and Grep to gather signed evidence for consent, access, EHR mapping, test results, privacy, security, training, and support.
  3. Verify the clinician review and wrong-patient controls, test-record procedure, audit evidence, downtime path, and rollback.
  4. Confirm monitoring includes safety, workflow completion, adoption, support, and integration health without PHI.
  5. Use WebFetch only to check current official product and security context; do not substitute public claims for tenant evidence.
  6. Use Write or Edit to publish the decision with explicit owners, expiries, exceptions, and stop triggers.

Approval Boundaries

Only the named change, clinical, privacy, security, and EHR authorities may accept their risks. Missing evidence is a no-go, not an assumed pass.

Output

Return gate-by-gate evidence, exceptions, owners, expiry dates, rollback trigger, monitoring window, and final go/no-go decision. Separate verified facts, tenant-specific evidence, assumptions, and actions still awaiting approval.

Error Handling

ConditionResponse
Required owner has not signedRecord no-go.
Evidence applies to another environmentReject it and test the target environment.
Rollback was not rehearsedDelay launch.

Example

The example is a redacted operational receipt, not patient data or proof of vendor certification.

environment=prod; cohort=40; gates=12/12; exceptions=0; rollback=rehearsed; owners=5/5; decision=go-bounded-pilot

Resources

Read the source map before changing a workflow. Recheck tenant-specific implementation evidence for every interface or capability that public documentation does not define.

Next Steps

Revalidate the evidence date and tenant-specific authority before repeating this workflow in another environment, cohort, care setting, or integration mode.

Similar Skills

security-and-hardening
addyosmani/agent-skills103k

security-and-hardening

Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package. Use when personal data or privacy compliance (GDPR, CCPA) is involved.

Security

archify
tt-a1i/archify80k

archify

Create polished, validated architecture, workflow, sequence, data-flow, and lifecycle/state diagrams as explorable standalone HTML with inline SVG, dark/light themes, optional trace motion, and PNG/JPEG/WebP/SVG/WebM export. Accept plain-language requirements or pasted Mermaid flowchart, sequenceDiagram, and stateDiagram input; inspect repository evidence when the diagram must reflect real code. Use when the user asks to visualize system architecture, infrastructure, cloud/security/network topology, technical workflows, API call sequences, request lifecycles, data pipelines, ETL/ELT, data lineage, state machines, or to convert/beautify Mermaid. Also use for everyday subjects with steps, parts, relationships, or states: a leave or travel plan, an application or approval process, a back-and-forth such as renting, where money or documents go, or where an application or order stands. Not for numeric charts or dashboards.

Security

security-research
code-yeongyu/oh-my-openagent70k

security-research

Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취약점 감사'.

Security

007
sickn33/agentic-awesome-skills47k

007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

Security

open-code-review
alibaba/open-code-review45k

open-code-review

Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.

Security

open-code-review
alibaba/open-code-review45k

open-code-review

Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.

Security