Hipaa Gap Analysis

PassAudited by ClawScan on May 1, 2026.

Overview

This instruction-only skill is coherently focused on reviewing HIPAA compliance documents, with only expected document-reading and citation behavior.

This appears safe to install as an instruction-only HIPAA document review aid. Before using it, make sure you attach only the documents you want reviewed and redact any patient data, secrets, or unrelated confidential material.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent may read and search documents supplied or made available for the HIPAA assessment.

Why it was flagged

The skill allows file-reading/search tools and web fetching. This is purpose-aligned for reviewing compliance documents and regulatory references, but users should notice that file contents may be accessed for the analysis.

Skill content
allowed-tools: "Read, Glob, Grep, WebFetch"
Recommendation

Provide only the compliance documents you intend to analyze, and avoid granting access to unrelated directories or files.

What this means

Sensitive text from provided documents may appear in the generated gap-analysis output.

Why it was flagged

The skill uses user-provided documents as context and intentionally repeats exact excerpts in its findings. This is expected for evidence-based compliance review, but those excerpts may contain sensitive internal policy or compliance details.

Skill content
Extract evidence — Quote the exact text from the document that relates to the control.
Recommendation

Use the skill in a trusted workspace and redact secrets, patient data, or unrelated confidential content before sharing documents.