P-16

clinical-agent-runtime(臨床 Agent 執行框架,權限分級)

Taiwan Medical AI Agent Framework 的執行層:LLM agent 只能呼叫 P-15 已簽章工具,強制四級權限——read-only → suggest-only → draft-only → order-ready-but-physician-confirmed——外加工具白名單、prompt injection / data exfiltration 防護、全程 audit、human confirmation。未來門診/住院摘要/檢查追蹤/慢病管理/研究/品質指標/IRB 文件/衛教等 agent 全部跑在此框架上。

DRAFT evidence snapshot

摘要與 purpose

Taiwan Medical AI Agent Framework 的執行層:LLM agent 只能呼叫 P-15 已簽章工具,強制四級權限——read-only → suggest-only → draft-only → order-ready-but-physician-confirmed——外加工具白名單、prompt injection / data exfiltration 防護、全程 audit、human confirmation。未來門診/住院摘要/檢查追蹤/慢病管理/研究/品質指標/IRB 文件/衛教等 agent 全部跑在此框架上。

目前狀態

查看 maturity 與 evidence 定義

Evidence

Repo implementation/automated-test evidence

已找到 permission、confirmation、exfiltration、sandbox 與至少 50 條 synthetic red-team attacks。

Synthetic evidence

Repo inventory 找到合成 fixtures、mock、golden set、對抗測試或工程 drill,因此最高保守標示為 Synthetic validation/Synthetic verification;本 WP 未重新執行該專案 test suite,也不公開未複驗的 pass count 或 coverage。

Clinical/operational evidence

未找到 clinical agent deployment evidence。

External/IRB/regulatory evidence

未找到外部或 regulatory review evidence。

Known limitations/evidence gaps

Planner 為 mock;macOS memory limit 無法強制;filesystem/network 主要為 Python 層攔截。

本頁不得被解讀為 clinical deployment、external validation、IRB approval、regulatory review、government endorsement、正式服務或可投入臨床使用。

Governance/human-review boundary

Source provenance

Project READMEprojects/P-16-clinical-agent-runtime/README.md
Project source commit89d3cb4
Evidence inventorydocs/website-evidence-inventory.md snapshot 5fdebfe
Website generation base64f0ba78b11942156f40c18cef3b24489b708f68
Last reviewed2026-07-17
Content statusDRAFT