摘要與 purpose
Taiwan Medical AI Agent Framework 的執行層:LLM agent 只能呼叫 P-15 已簽章工具,強制四級權限——read-only → suggest-only → draft-only → order-ready-but-physician-confirmed——外加工具白名單、prompt injection / data exfiltration 防護、全程 audit、human confirmation。未來門診/住院摘要/檢查追蹤/慢病管理/研究/品質指標/IRB 文件/衛教等 agent 全部跑在此框架上。
目前狀態
Evidence
Repo implementation/automated-test evidence
已找到 permission、confirmation、exfiltration、sandbox 與至少 50 條 synthetic red-team attacks。
Synthetic evidence
Repo inventory 找到合成 fixtures、mock、golden set、對抗測試或工程 drill,因此最高保守標示為 Synthetic validation/Synthetic verification;本 WP 未重新執行該專案 test suite,也不公開未複驗的 pass count 或 coverage。
Clinical/operational evidence
未找到 clinical agent deployment evidence。
External/IRB/regulatory evidence
未找到外部或 regulatory review evidence。
Known limitations/evidence gaps
Planner 為 mock;macOS memory limit 無法強制;filesystem/network 主要為 Python 層攔截。
本頁不得被解讀為 clinical deployment、external validation、IRB approval、regulatory review、government endorsement、正式服務或可投入臨床使用。
Governance/human-review boundary
- Engineering owner 對 implementation 與 test claims 負責;clinical/regulatory owner 必須另行核准醫療與法規內容。
- Repo verification 或 synthetic drill 不是 certification decision。
- 研究網路可以執行 certification,但同案 development/consulting/sponsored research/validation 人員必須和 certification review/decision/appeal 分離;Studio 不得審查自己的工作。
- 任何臨床、IRB、TFDA、政府與院內責任仍由其法定或專業 owner 承擔。
Source provenance
| Project README | projects/P-16-clinical-agent-runtime/README.md |
|---|---|
| Project source commit | 89d3cb4 |
| Evidence inventory | docs/website-evidence-inventory.md snapshot 5fdebfe |
| Website generation base | 64f0ba78b11942156f40c18cef3b24489b708f68 |
| Last reviewed | 2026-07-17 |
| Content status | DRAFT |