bshepp commited on
Commit ·
8aed835
1
Parent(s): 9dea0ad
Add LICENSE (Apache 2.0), CONTRIBUTING.md, SECURITY.md; move competition files
Browse files- LICENSE: Apache 2.0 with HAI-DEF Terms of Use notice for Gemma model
- CONTRIBUTING.md: setup guide, code style, areas for contribution
- SECURITY.md: responsible disclosure policy, patient data handling, LLM risks
- Moved download_data.txt, overview.txt, rules.txt to competition/ subfolder
- README.md: updated License section, added new files to Documentation Index
- CONTRIBUTING.md +82 -0
- LICENSE +194 -0
- README.md +6 -2
- SECURITY.md +59 -0
- download_data.txt → competition/download_data.txt +0 -0
- overview.txt → competition/overview.txt +0 -0
- rules.txt → competition/rules.txt +0 -0
CONTRIBUTING.md
ADDED
|
@@ -0,0 +1,82 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
# Contributing to CDS Agent
|
| 2 |
+
|
| 3 |
+
Thank you for your interest in contributing to the Clinical Decision Support Agent!
|
| 4 |
+
|
| 5 |
+
## Getting Started
|
| 6 |
+
|
| 7 |
+
1. Fork the repository
|
| 8 |
+
2. Clone your fork locally
|
| 9 |
+
3. Follow the setup instructions in [README.md](README.md)
|
| 10 |
+
4. Create a feature branch from `master`
|
| 11 |
+
|
| 12 |
+
## Development Setup
|
| 13 |
+
|
| 14 |
+
```bash
|
| 15 |
+
# Backend
|
| 16 |
+
cd src/backend
|
| 17 |
+
python -m venv venv
|
| 18 |
+
venv\Scripts\activate # Windows
|
| 19 |
+
pip install -r requirements.txt
|
| 20 |
+
copy .env.template .env # Add your Google AI Studio key
|
| 21 |
+
|
| 22 |
+
# Frontend
|
| 23 |
+
cd src/frontend
|
| 24 |
+
npm install
|
| 25 |
+
```
|
| 26 |
+
|
| 27 |
+
## Running Tests
|
| 28 |
+
|
| 29 |
+
```bash
|
| 30 |
+
cd src/backend
|
| 31 |
+
|
| 32 |
+
# RAG quality (no server needed)
|
| 33 |
+
python test_rag_quality.py --rebuild --verbose
|
| 34 |
+
|
| 35 |
+
# E2E pipeline (requires running backend on port 8002)
|
| 36 |
+
python test_e2e.py
|
| 37 |
+
|
| 38 |
+
# Clinical test suite
|
| 39 |
+
python test_clinical_cases.py
|
| 40 |
+
|
| 41 |
+
# External validation
|
| 42 |
+
python -m validation.run_validation --medqa --max-cases 5
|
| 43 |
+
```
|
| 44 |
+
|
| 45 |
+
## How to Contribute
|
| 46 |
+
|
| 47 |
+
### Reporting Issues
|
| 48 |
+
|
| 49 |
+
- Use GitHub Issues for bug reports and feature requests
|
| 50 |
+
- Include reproduction steps, expected behavior, and actual behavior
|
| 51 |
+
- For clinical accuracy concerns, note the patient scenario and expected medical reasoning
|
| 52 |
+
|
| 53 |
+
### Submitting Changes
|
| 54 |
+
|
| 55 |
+
1. Create a branch: `git checkout -b feature/your-feature`
|
| 56 |
+
2. Make changes with clear, focused commits
|
| 57 |
+
3. Ensure existing tests still pass
|
| 58 |
+
4. Submit a pull request with a description of what changed and why
|
| 59 |
+
|
| 60 |
+
### Areas Where Contributions Are Welcome
|
| 61 |
+
|
| 62 |
+
- **Clinical guidelines** — Adding new guidelines to `app/data/clinical_guidelines.json` (must cite authoritative sources: ACC/AHA, ADA, IDSA, etc.)
|
| 63 |
+
- **Test cases** — Additional clinical scenarios in `test_clinical_cases.py`
|
| 64 |
+
- **Validation harnesses** — Improving or adding dataset harnesses in `validation/`
|
| 65 |
+
- **Frontend polish** — UI/UX improvements, accessibility, responsive design
|
| 66 |
+
- **Documentation** — Corrections, clarifications, translations
|
| 67 |
+
|
| 68 |
+
### Code Style
|
| 69 |
+
|
| 70 |
+
- **Python:** Standard library conventions, type hints where practical, Pydantic models for data structures
|
| 71 |
+
- **TypeScript/React:** Functional components, hooks, Tailwind CSS utility classes
|
| 72 |
+
- **Commits:** Descriptive messages with a prefix (`feat:`, `fix:`, `docs:`, `test:`, `refactor:`)
|
| 73 |
+
|
| 74 |
+
## Important Notes
|
| 75 |
+
|
| 76 |
+
- **This is a medical AI project.** Changes to clinical reasoning, guidelines, or conflict detection require extra scrutiny. If you're not a domain expert, flag your PR for clinical review.
|
| 77 |
+
- **No patient data.** Never commit real patient information. All test cases must be synthetic.
|
| 78 |
+
- **API keys.** Never commit API keys or secrets. Use `.env` (gitignored).
|
| 79 |
+
|
| 80 |
+
## License
|
| 81 |
+
|
| 82 |
+
By contributing, you agree that your contributions will be licensed under the [Apache License 2.0](LICENSE).
|
LICENSE
ADDED
|
@@ -0,0 +1,194 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
Apache License
|
| 2 |
+
Version 2.0, January 2004
|
| 3 |
+
http://www.apache.org/licenses/
|
| 4 |
+
|
| 5 |
+
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
| 6 |
+
|
| 7 |
+
1. Definitions.
|
| 8 |
+
|
| 9 |
+
"License" shall mean the terms and conditions for use, reproduction,
|
| 10 |
+
and distribution as defined by Sections 1 through 9 of this document.
|
| 11 |
+
|
| 12 |
+
"Licensor" shall mean the copyright owner or entity authorized by
|
| 13 |
+
the copyright owner that is granting the License.
|
| 14 |
+
|
| 15 |
+
"Legal Entity" shall mean the union of the acting entity and all
|
| 16 |
+
other entities that control, are controlled by, or are under common
|
| 17 |
+
control with that entity. For the purposes of this definition,
|
| 18 |
+
"control" means (i) the power, direct or indirect, to cause the
|
| 19 |
+
direction or management of such entity, whether by contract or
|
| 20 |
+
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
| 21 |
+
outstanding shares, or (iii) beneficial ownership of such entity.
|
| 22 |
+
|
| 23 |
+
"You" (or "Your") shall mean an individual or Legal Entity
|
| 24 |
+
exercising permissions granted by this License.
|
| 25 |
+
|
| 26 |
+
"Source" form shall mean the preferred form for making modifications,
|
| 27 |
+
including but not limited to software source code, documentation
|
| 28 |
+
source, and configuration files.
|
| 29 |
+
|
| 30 |
+
"Object" form shall mean any form resulting from mechanical
|
| 31 |
+
transformation or translation of a Source form, including but
|
| 32 |
+
not limited to compiled object code, generated documentation,
|
| 33 |
+
and conversions to other media types.
|
| 34 |
+
|
| 35 |
+
"Work" shall mean the work of authorship, whether in Source or
|
| 36 |
+
Object form, made available under the License, as indicated by a
|
| 37 |
+
copyright notice that is included in or attached to the work
|
| 38 |
+
(an example is provided in the Appendix below).
|
| 39 |
+
|
| 40 |
+
"Derivative Works" shall mean any work, whether in Source or Object
|
| 41 |
+
form, that is based on (or derived from) the Work and for which the
|
| 42 |
+
editorial revisions, annotations, elaborations, or other modifications
|
| 43 |
+
represent, as a whole, an original work of authorship. For the purposes
|
| 44 |
+
of this License, Derivative Works shall not include works that remain
|
| 45 |
+
separable from, or merely link (or bind by name) to the interfaces of,
|
| 46 |
+
the Work and Derivative Works thereof.
|
| 47 |
+
|
| 48 |
+
"Contribution" shall mean any work of authorship, including
|
| 49 |
+
the original version of the Work and any modifications or additions
|
| 50 |
+
to that Work or Derivative Works thereof, that is intentionally
|
| 51 |
+
submitted to the Licensor for inclusion in the Work by the copyright owner
|
| 52 |
+
or by an individual or Legal Entity authorized to submit on behalf of
|
| 53 |
+
the copyright owner. For the purposes of this definition, "submitted"
|
| 54 |
+
means any form of electronic, verbal, or written communication sent
|
| 55 |
+
to the Licensor or its representatives, including but not limited to
|
| 56 |
+
communication on electronic mailing lists, source code control systems,
|
| 57 |
+
and issue tracking systems that are managed by, or on behalf of, the
|
| 58 |
+
Licensor for the purpose of discussing and improving the Work, but
|
| 59 |
+
excluding communication that is conspicuously marked or otherwise
|
| 60 |
+
designated in writing by the copyright owner as "Not a Contribution."
|
| 61 |
+
|
| 62 |
+
"Contributor" shall mean Licensor and any individual or Legal Entity
|
| 63 |
+
on behalf of whom a Contribution has been received by the Licensor and
|
| 64 |
+
subsequently incorporated within the Work.
|
| 65 |
+
|
| 66 |
+
2. Grant of Copyright License. Subject to the terms and conditions of
|
| 67 |
+
this License, each Contributor hereby grants to You a perpetual,
|
| 68 |
+
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
| 69 |
+
copyright license to reproduce, prepare Derivative Works of,
|
| 70 |
+
publicly display, publicly perform, sublicense, and distribute the
|
| 71 |
+
Work and such Derivative Works in Source or Object form.
|
| 72 |
+
|
| 73 |
+
3. Grant of Patent License. Subject to the terms and conditions of
|
| 74 |
+
this License, each Contributor hereby grants to You a perpetual,
|
| 75 |
+
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
| 76 |
+
(except as stated in this section) patent license to make, have made,
|
| 77 |
+
use, offer to sell, sell, import, and otherwise transfer the Work,
|
| 78 |
+
where such license applies only to those patent claims licensable
|
| 79 |
+
by such Contributor that are necessarily infringed by their
|
| 80 |
+
Contribution(s) alone or by combination of their Contribution(s)
|
| 81 |
+
with the Work to which such Contribution(s) was submitted. If You
|
| 82 |
+
institute patent litigation against any entity (including a
|
| 83 |
+
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
| 84 |
+
or a Contribution incorporated within the Work constitutes direct
|
| 85 |
+
or contributory patent infringement, then any patent licenses
|
| 86 |
+
granted to You under this License for that Work shall terminate
|
| 87 |
+
as of the date such litigation is filed.
|
| 88 |
+
|
| 89 |
+
4. Redistribution. You may reproduce and distribute copies of the
|
| 90 |
+
Work or Derivative Works thereof in any medium, with or without
|
| 91 |
+
modifications, and in Source or Object form, provided that You
|
| 92 |
+
meet the following conditions:
|
| 93 |
+
|
| 94 |
+
(a) You must give any other recipients of the Work or
|
| 95 |
+
Derivative Works a copy of this License; and
|
| 96 |
+
|
| 97 |
+
(b) You must cause any modified files to carry prominent notices
|
| 98 |
+
stating that You changed the files; and
|
| 99 |
+
|
| 100 |
+
(c) You must retain, in the Source form of any Derivative Works
|
| 101 |
+
that You distribute, all copyright, patent, trademark, and
|
| 102 |
+
attribution notices from the Source form of the Work,
|
| 103 |
+
excluding those notices that do not pertain to any part of
|
| 104 |
+
the Derivative Works; and
|
| 105 |
+
|
| 106 |
+
(d) If the Work includes a "NOTICE" text file as part of its
|
| 107 |
+
distribution, then any Derivative Works that You distribute must
|
| 108 |
+
include a readable copy of the attribution notices contained
|
| 109 |
+
within such NOTICE file, excluding any notices that do not
|
| 110 |
+
pertain to any part of the Derivative Works, in at least one
|
| 111 |
+
of the following places: within a NOTICE text file distributed
|
| 112 |
+
as part of the Derivative Works; within the Source form or
|
| 113 |
+
documentation, if provided along with the Derivative Works; or,
|
| 114 |
+
within a display generated by the Derivative Works, if and
|
| 115 |
+
wherever such third-party notices normally appear. The contents
|
| 116 |
+
of the NOTICE file are for informational purposes only and
|
| 117 |
+
do not modify the License. You may add Your own attribution
|
| 118 |
+
notices within Derivative Works that You distribute, alongside
|
| 119 |
+
or as an addendum to the NOTICE text from the Work, provided
|
| 120 |
+
that such additional attribution notices cannot be construed
|
| 121 |
+
as modifying the License.
|
| 122 |
+
|
| 123 |
+
You may add Your own copyright statement to Your modifications and
|
| 124 |
+
may provide additional or different license terms and conditions
|
| 125 |
+
for use, reproduction, or distribution of Your modifications, or
|
| 126 |
+
for any such Derivative Works as a whole, provided Your use,
|
| 127 |
+
reproduction, and distribution of the Work otherwise complies with
|
| 128 |
+
the conditions stated in this License.
|
| 129 |
+
|
| 130 |
+
5. Submission of Contributions. Unless You explicitly state otherwise,
|
| 131 |
+
any Contribution intentionally submitted for inclusion in the Work
|
| 132 |
+
by You to the Licensor shall be under the terms and conditions of
|
| 133 |
+
this License, without any additional terms or conditions.
|
| 134 |
+
Notwithstanding the above, nothing herein shall supersede or modify
|
| 135 |
+
the terms of any separate license agreement you may have executed
|
| 136 |
+
with Licensor regarding such Contributions.
|
| 137 |
+
|
| 138 |
+
6. Trademarks. This License does not grant permission to use the trade
|
| 139 |
+
names, trademarks, service marks, or product names of the Licensor,
|
| 140 |
+
except as required for reasonable and customary use in describing the
|
| 141 |
+
origin of the Work and reproducing the content of the NOTICE file.
|
| 142 |
+
|
| 143 |
+
7. Disclaimer of Warranty. Unless required by applicable law or
|
| 144 |
+
agreed to in writing, Licensor provides the Work (and each
|
| 145 |
+
Contributor provides its Contributions) on an "AS IS" BASIS,
|
| 146 |
+
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
| 147 |
+
implied, including, without limitation, any warranties or conditions
|
| 148 |
+
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
| 149 |
+
PARTICULAR PURPOSE. You are solely responsible for determining the
|
| 150 |
+
appropriateness of using or redistributing the Work and assume any
|
| 151 |
+
risks associated with Your exercise of permissions under this License.
|
| 152 |
+
|
| 153 |
+
8. Limitation of Liability. In no event and under no legal theory,
|
| 154 |
+
whether in tort (including negligence), contract, or otherwise,
|
| 155 |
+
unless required by applicable law (such as deliberate and grossly
|
| 156 |
+
negligent acts) or agreed to in writing, shall any Contributor be
|
| 157 |
+
liable to You for damages, including any direct, indirect, special,
|
| 158 |
+
incidental, or consequential damages of any character arising as a
|
| 159 |
+
result of this License or out of the use or inability to use the
|
| 160 |
+
Work (including but not limited to damages for loss of goodwill,
|
| 161 |
+
work stoppage, computer failure or malfunction, or any and all
|
| 162 |
+
other commercial damages or losses), even if such Contributor
|
| 163 |
+
has been advised of the possibility of such damages.
|
| 164 |
+
|
| 165 |
+
9. Accepting Warranty or Additional Liability. While redistributing
|
| 166 |
+
the Work or Derivative Works thereof, You may choose to offer,
|
| 167 |
+
and charge a fee for, acceptance of support, warranty, indemnity,
|
| 168 |
+
or other liability obligations and/or rights consistent with this
|
| 169 |
+
License. However, in accepting such obligations, You may act only
|
| 170 |
+
on Your own behalf and on Your sole responsibility, not on behalf
|
| 171 |
+
of any other Contributor, and only if You agree to indemnify,
|
| 172 |
+
defend, and hold each Contributor harmless for any liability
|
| 173 |
+
incurred by, or claims asserted against, such Contributor by reason
|
| 174 |
+
of your accepting any such warranty or additional liability.
|
| 175 |
+
|
| 176 |
+
END OF TERMS AND CONDITIONS
|
| 177 |
+
|
| 178 |
+
Copyright 2025 bshepp
|
| 179 |
+
|
| 180 |
+
Licensed under the Apache License, Version 2.0 (the "License");
|
| 181 |
+
you may not use this file except in compliance with the License.
|
| 182 |
+
You may obtain a copy of the License at
|
| 183 |
+
|
| 184 |
+
http://www.apache.org/licenses/LICENSE-2.0
|
| 185 |
+
|
| 186 |
+
Unless required by applicable law or agreed to in writing, software
|
| 187 |
+
distributed under the License is distributed on an "AS IS" BASIS,
|
| 188 |
+
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
| 189 |
+
See the License for the specific language governing permissions and
|
| 190 |
+
limitations under the License.
|
| 191 |
+
|
| 192 |
+
ADDITIONAL NOTICE: This project uses the Gemma model, which is subject
|
| 193 |
+
to the Google HAI-DEF Terms of Use. See:
|
| 194 |
+
https://developers.google.com/health-ai-developer-foundations/terms
|
README.md
CHANGED
|
@@ -322,13 +322,17 @@ curl -X POST http://localhost:8000/api/cases/submit \
|
|
| 322 |
| [docs/test_results.md](docs/test_results.md) | Detailed test results, RAG benchmarks, pipeline timing |
|
| 323 |
| [DEVELOPMENT_LOG.md](DEVELOPMENT_LOG.md) | Chronological build history, problems solved, decisions made |
|
| 324 |
| [docs/writeup_draft.md](docs/writeup_draft.md) | Project writeup / summary |
|
|
|
|
|
|
|
|
|
|
| 325 |
| [SUBMISSION_GUIDE.md](SUBMISSION_GUIDE.md) | Competition submission strategy |
|
| 326 |
-
| [RULES_SUMMARY.md](RULES_SUMMARY.md) | Competition rules checklist |
|
| 327 |
|
| 328 |
---
|
| 329 |
|
| 330 |
## License
|
| 331 |
|
| 332 |
-
|
|
|
|
|
|
|
| 333 |
|
| 334 |
> **Disclaimer:** This is a research / demonstration system. It is NOT a substitute for professional medical judgment. All clinical decisions must be made by qualified healthcare professionals.
|
|
|
|
| 322 |
| [docs/test_results.md](docs/test_results.md) | Detailed test results, RAG benchmarks, pipeline timing |
|
| 323 |
| [DEVELOPMENT_LOG.md](DEVELOPMENT_LOG.md) | Chronological build history, problems solved, decisions made |
|
| 324 |
| [docs/writeup_draft.md](docs/writeup_draft.md) | Project writeup / summary |
|
| 325 |
+
| [CONTRIBUTING.md](CONTRIBUTING.md) | How to contribute to the project |
|
| 326 |
+
| [SECURITY.md](SECURITY.md) | Security policy and responsible disclosure |
|
| 327 |
+
| [TODO.md](TODO.md) | Next-session action items and project state |
|
| 328 |
| [SUBMISSION_GUIDE.md](SUBMISSION_GUIDE.md) | Competition submission strategy |
|
|
|
|
| 329 |
|
| 330 |
---
|
| 331 |
|
| 332 |
## License
|
| 333 |
|
| 334 |
+
Licensed under the [Apache License 2.0](LICENSE).
|
| 335 |
+
|
| 336 |
+
This project uses the Gemma model, which is subject to the [HAI-DEF Terms of Use](https://developers.google.com/health-ai-developer-foundations/terms).
|
| 337 |
|
| 338 |
> **Disclaimer:** This is a research / demonstration system. It is NOT a substitute for professional medical judgment. All clinical decisions must be made by qualified healthcare professionals.
|
SECURITY.md
ADDED
|
@@ -0,0 +1,59 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
# Security Policy
|
| 2 |
+
|
| 3 |
+
## Important Disclaimer
|
| 4 |
+
|
| 5 |
+
**This is a research / demonstration system. It is NOT approved for clinical use and must NOT be used to make real medical decisions.** All clinical decisions must be made by qualified healthcare professionals.
|
| 6 |
+
|
| 7 |
+
## Reporting a Vulnerability
|
| 8 |
+
|
| 9 |
+
If you discover a security vulnerability in this project, please report it responsibly:
|
| 10 |
+
|
| 11 |
+
1. **Do NOT open a public GitHub issue** for security vulnerabilities
|
| 12 |
+
2. Email the maintainer directly (see GitHub profile for contact info)
|
| 13 |
+
3. Include a description of the vulnerability, steps to reproduce, and potential impact
|
| 14 |
+
|
| 15 |
+
We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation within 7 days for critical issues.
|
| 16 |
+
|
| 17 |
+
## Scope
|
| 18 |
+
|
| 19 |
+
### In scope
|
| 20 |
+
|
| 21 |
+
- Authentication/authorization bypasses (if auth is added in the future)
|
| 22 |
+
- Injection vulnerabilities (prompt injection, SQL injection, command injection)
|
| 23 |
+
- Sensitive data exposure (API keys, patient data leakage)
|
| 24 |
+
- Dependency vulnerabilities in `requirements.txt` or `package.json`
|
| 25 |
+
- CORS misconfigurations that could enable data exfiltration
|
| 26 |
+
|
| 27 |
+
### Out of scope
|
| 28 |
+
|
| 29 |
+
- Clinical accuracy of AI-generated recommendations (this is a known limitation, not a vulnerability)
|
| 30 |
+
- Denial of service via expensive LLM calls (known limitation of the architecture)
|
| 31 |
+
- Issues in third-party services (Google AI Studio, OpenFDA, RxNorm)
|
| 32 |
+
|
| 33 |
+
## Security Considerations for This Project
|
| 34 |
+
|
| 35 |
+
### Patient Data
|
| 36 |
+
|
| 37 |
+
- This system processes clinical text that could contain protected health information (PHI)
|
| 38 |
+
- **No real patient data should ever be used** with this demonstration system
|
| 39 |
+
- In a production deployment, HIPAA compliance would require: encrypted storage, audit logging, access controls, and BAAs with all third-party services
|
| 40 |
+
- The Gemma model can be self-hosted on-premises to avoid sending data to external APIs
|
| 41 |
+
|
| 42 |
+
### API Keys
|
| 43 |
+
|
| 44 |
+
- The Google AI Studio API key is stored in `.env` (gitignored)
|
| 45 |
+
- Never commit `.env` or any file containing API keys
|
| 46 |
+
- The `.env.template` file shows required variables without actual values
|
| 47 |
+
|
| 48 |
+
### LLM-Specific Risks
|
| 49 |
+
|
| 50 |
+
- **Prompt injection:** The system processes untrusted user input (patient text) that is sent to the LLM. Adversarial inputs could potentially manipulate LLM behavior.
|
| 51 |
+
- **Hallucination:** The LLM may generate plausible but incorrect medical information. The conflict detection step and RAG grounding mitigate but do not eliminate this risk.
|
| 52 |
+
- **Over-reliance:** The system is designed as decision *support*, not decision *making*. UI disclaimers and caveats are included to reinforce this.
|
| 53 |
+
|
| 54 |
+
## Supported Versions
|
| 55 |
+
|
| 56 |
+
| Version | Supported |
|
| 57 |
+
|---------|-----------|
|
| 58 |
+
| Current `master` branch | Yes |
|
| 59 |
+
| Older commits | No |
|
download_data.txt → competition/download_data.txt
RENAMED
|
File without changes
|
overview.txt → competition/overview.txt
RENAMED
|
File without changes
|
rules.txt → competition/rules.txt
RENAMED
|
File without changes
|