Medical Billing Coder

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's requirements and instructions are internally consistent with a medical billing/coding assistant: it is instruction-only, requests no credentials by default, optionally uses a CMS API key for NCCI validation, and includes appropriate disclaimers about PHI and review by a qualified coder.

This skill appears coherent for advising on codes, but keep these practical cautions before installing or using it: 1) Never paste patient-identifiable PHI into queries — the SKILL.md warns to de-identify, but the runtime must enforce that; confirm your agent/runtime will not transmit PHI. 2) If you set CMS_API_KEY, verify what is actually transmitted (the skill claims only code pairs are sent) and that the API key has appropriate, limited scope; monitor network traffic or review logs if possible. 3) CPT text is proprietary — the skill says it references CPT numbers and common descriptions for advisory use only; do not rely on this for production claim submission without a proper licensed CPT dataset and review by a certified coder. 4) Because this is instruction-only with no code, behavior depends on the agent correctly implementing the steps in SKILL.md — test thoroughly with de-identified examples and cross-check outputs with an experienced coder before using it for billing. 5) The repository/homepage is provided; if you require higher assurance, review that GitHub repo and the author before using in a production environment.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.