
Safety-Critical Medical Device Firmware Code Review
Review medical device firmware for safety, compliance, and critical defects
What You Can Do
This skill performs rigorous code review of safety-critical medical device firmware, identifying compliance gaps, security vulnerabilities, and design defects that could impact patient safety. You submit firmware code snippets or full modules, and Claude analyzes them against FDA guidance, IEC 62304 standards, and embedded systems best practices. The skill flags issues before they reach certification or production, categorizes risk levels, and provides specific remediation guidance.
Features
buffer overflows, use-after-free, race conditions
cryptographic misuse, unvalidated inputs, hardcoded secrets
Example Output
Code Review Summary
File: patient_monitor_v2.1.c
Risk Level: CRITICAL (2 issues found)
Issue #1: Buffer Overflow in Sensor Handler (CRITICAL)
Location: Line 127, memcpy(buffer, sensor_data, length);
Problem: No bounds checking on incoming sensor data
Risk: Stack overflow → arbitrary code execution → device compromise
FDA Guideline: 21 CFR Part 11.10(e) — software validation
Remediation: Add bounds check: if (length > BUFFER_MAX) return ERROR_OVERFLOW;
Issue #2: Unprotected Shared State (MAJOR)
Location: Lines 45-63, waveform_data race condition
Problem: Interrupt handler and main loop access waveform_data without synchronization
Risk: Torn writes → corrupted vital sign displays → clinical misdiagnosis
IEC 62304 Clause: 7.3.4 (FMEA mitigation)
Remediation: Wrap access with mutex_lock/unlock
Compliance Scorecard
- ✅ Input validation: 3/5 functions compliant
- ⚠️ Memory safety: 1 critical defect found
- ❌ Real-time determinism: No WCET analysis
- ✅ Approved cryptography: AES-256 (compliant)
- ⚠️ Error handling: Missing recovery paths in 2 places
What's Included
- SKILL.md: Complete firmware review methodology with decision trees and checklists
- FDA 21 CFR Part 11 Compliance Checklist: Automated validation against software requirements
- IEC 62304:2015 Traceability Worksheet: Map code to design and verification documents
- Common Medical Device Code Defects Library: Pattern reference for buffer overflows, race conditions, crypto misuse
- Risk Assessment Template: Quantify patient safety impact for each finding
- Remediation Response Tracker: Document fixes and evidence of resolution
Who It's For
- Firmware engineers preparing code for FDA 510(k) or PMA submissions
- Medical device QA/compliance specialists reviewing design changes and vendor code
- Embedded systems architects designing patient-facing or life-critical modules
- Regulatory affairs teams preparing for pre-submission meetings with FDA
- Clinical engineering teams validating third-party or legacy device firmware
Best For
- Pre-certification code review (identify defects before FDA inspection)
- Security vulnerability assessment in connected medical devices
- Compliance gap analysis — verify firmware meets IEC 62304 and FDA requirements
- Post-incident forensics — root cause analysis after adverse events
- Vendor firmware vetting — evaluate firmware from acquired or partnered companies






