Official agent skill

Secret Serialization

by getsentry in getsentry/skills

Finds secrets, tokens, passwords, and API keys that can leak through generated serialization: Python dataclass repr and asdict, attrs, pydantic modeldump, NamedTuple, JavaScript JSON.stringify and…

OfficialApache-2.0Auto-check: notesDevOps & Cloud

Install Secret Serialization

skills CLI
$ npx skills add getsentry/skills --skill secret-serialization -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install getsentry/skills secret-serialization --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secret-serialization .claude/skills/secret-serialization && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secret-serialization
GitHub stars
1k
Token cost
~2.6k tokens
SKILL.md length
1,310 words
Files
5 (incl. references)
Skills in repo
27
Repo updated
First seen
Licence
Apache-2.0

At a glance

Finds secrets, tokens, passwords, and API keys that can leak through generated serialization: Python dataclass repr and asdict, attrs, pydantic modeldump, NamedTuple, JavaScript JSON.stringify and…

  • Works in 2 steps: Holder: a credential is stored as a… → Sink: logging, tracing, error reporting,…
  • Asked to check for secret serialization
  • SKILL.md covers Boundary, References, Credential Fields and Explicit Exclusion, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Secret Serialization is an agent skill from getsentry/skills, published by the product's own GitHub organization. Finds secrets, tokens, passwords, and API keys that can leak through generated serialization: Python dataclass repr and asdict, attrs, pydantic modeldump, NamedTuple, JavaScript JSON.stringify and util.inspect, structured logs, tracing spans, and error reports. Use when asked to "check for secret serialization", "credential in repr", "repr=False audit", "secret in spans", "token in logs", or when a change adds a credential field to a dataclass, model, or config object, or adds code that stringifies whole objects…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `SOURCES.md`, `SPEC.md` and `references/javascript-typescript.md`).

It sits in DevOps & Cloud, covering Observability. It works with JavaScript, Python, Sentry and Pydantic. The repository describes itself as: Agent Skills used by the Sentry team for development. The licence is Apache-2.0.

When your agent uses it

  • Asked to check for secret serialization
  • Credential in repr
  • Repr=False audit
  • Secret in spans

Example prompts

  • “check for secret serialization”
  • “credential in repr”
  • “repr=False audit”
  • “/secret-serialization”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Grep, Glob

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Holder: a credential is stored as a field on a type with generated repr, str, asdict, model_dump, toJSON, or property enumeration.
  2. Sink: logging, tracing, error reporting, caching, or a response serializes whole objects or every kwarg (str(value), span.set_data(key…

What it can do on your machine

Read from SKILL.md and the folder at commit d18b7aa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secret Serialization loads about 2.6k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 143 tokens; SKILL.md has 1,310 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~143
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:22
    Hardcoded secret literals and committed `.env` files are out of scope.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from getsentry/skills at commit d18b7aa, republished under its Apache-2.0 licence (© getsentry). 1,310 words, ~2,606 tokens.

Download SKILL.mdSave it as .claude/skills/secret-serialization/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
secret-serialization
description
Finds secrets, tokens, passwords, and API keys that can leak through generated serialization: Python dataclass repr and asdict, attrs, pydantic model_dump, NamedTuple, JavaScript JSON.stringify and util.inspect, structured logs, tracing spans, and error reports. Use when asked to "check for secret serialization", "credential in repr", "repr=False audit", "secret in spans", "token in logs", or when a change adds a credential field to a dataclass, model, or config object, or adds code that stringifies whole objects or every kwarg into telemetry.
allowed-tools
Read, Grep, Glob

Secret Serialization Review

Find credentials that can leak because a type serializes itself and something upstream serializes whole objects.

A leak usually needs two changes that each look safe alone:

  1. Holder: a credential is stored as a field on a type with generated repr, str, asdict, model_dump, toJSON, or property enumeration.
  2. Sink: logging, tracing, error reporting, caching, or a response serializes whole objects or every kwarg (str(value), span.set_data(key, obj), logger.info("%s", obj), JSON.stringify(args)).

The two sides are often written months apart by different authors. Report either side on its own. Always search the existing tree for the other side, because it is frequently already on the default branch and absent from the diff.

Boundary

  • This skill covers indirect leaks through generated serialization and wholesale sinks.
  • Direct leaks, such as interpolating a token into a log message, belong to security-review. Report them here only when they come from a changed wholesale sink.
  • Hardcoded secret literals and committed .env files are out of scope.

References

ReferenceRead When
references/python.mdReviewing Python dataclasses, attrs, pydantic, NamedTuple, msgspec, logging, Sentry SDK, or OpenTelemetry code
references/javascript-typescript.mdReviewing JavaScript or TypeScript classes, config objects, JSON.stringify, util.inspect, pino or winston, or Sentry and OpenTelemetry spans

Credential Fields

Treat a field as credential-bearing when its name, type, or source says so:

  • Names containing secret, token, password, passwd, pwd, api_key, apikey, access_key, private_key, signing_key, client_secret, bearer, credential, authorization, auth_header, cookie, session_key, dsn, connection_string, webhook_secret, hmac, or refresh_token.
  • Types such as SecretStr, SecretBytes, or wrappers around them.
  • Values assigned from environment variables, a secrets manager, or a constructor argument named like the above.

Explicit Exclusion

Separate two kinds of path:

  • Generated paths are produced by the type itself: __repr__ and __str__, asdict, model_dump, toJSON, and own-enumerable-property walks (JSON.stringify, util.inspect, spread). They are the holder's responsibility.
  • Raw attribute access reads the stored value directly: vars(obj), obj.__dict__, pickle, json.dumps(obj, default=vars). Every stored attribute is exposed this way, whatever flags the field has. Treat these only as sinks: report them when a sink in the repository applies one to a credential-bearing instance.

A field is fully excluded when every generated path its type has is blocked, whether by one mechanism or several together. A field is partially excluded when at least one generated path still includes it. No field-level mechanism defeats raw attribute access. Only not storing the value does, so fix raw attribute findings at the sink.

MechanismBlocksStill includes the field
dataclasses.field(repr=False), attrs.field(repr=False)__repr__, __str__asdict, astuple, raw access
Pydantic Field(repr=False)__repr__, __str__model_dump, model_dump_json, response serialization, raw access
Pydantic Field(exclude=True)model_dump, model_dump_json, response serialization__repr__, __str__, raw access
Pydantic Field(repr=False, exclude=True)Every generated pathRaw access
JavaScript #private fieldEvery generated pathNothing outside the class body
Object.defineProperty(..., { enumerable: false })Every generated pathExplicit property reads, Object.getOwnPropertyNames
Hand-written __repr__, __str__, toJSON, or [util.inspect.custom] that omits the fieldOnly the path it overrides (a __repr__ also serves str() when there is no __str__)Every other generated path, raw access
Redacting wrapper: SecretStr, SecretBytes, a project Redacted[T]Every generated pathpickle and recursive __dict__ walks such as default=vars, which reach the value stored inside the wrapper
Not stored on the object: read inside the method, or held in a closureEverythingNothing

Do not treat underscore naming, TypeScript private, __slots__, type annotations, comments, dataclass(init=False), or a custom __init__ that still assigns the field as blocking any path.

Investigation Process

  1. Read the changed hunk. Find new or modified credential fields on auto-serializing types, and new or modified code that serializes objects or kwargs into logs, spans, error context, caches, queues, or responses.
  2. For each credential field, read the full class, decorators, base classes, and model config. List every generated path and check which ones the field's mechanisms block, using the table above.
  3. Grep for where instances are constructed and passed. Instances handed to decorators, **kwargs, tool call arguments, task payloads, or middleware reach generic sinks.
  4. Grep the whole repository for sinks that can see those instances, not only the diff. Useful patterns: str(value), repr(, asdict(, model_dump(, set_data(, set_attribute(, set_context(, set_extra(, JSON.stringify(, util.inspect(, loggers called with objects, and raw attribute access (vars(, __dict__, pickle.dumps(, default=vars).
  5. For each changed sink, check for a key allowlist, redaction keyed on credential names, or a filter that replaces objects with their type name. Then grep for callers that pass credential-bearing objects into it.
  6. Look at tests only to see whether one asserts the credential is absent from the serialized form. A missing test is fix guidance, not a finding.
  7. Confirm the code ships. Skip fixtures, examples, generated code, and test-only helpers.
Show full SKILL.md (548 more words)Show less

What To Report

CategoryReport When
Unexcluded credential fieldA credential field is added or moved onto a type with generated serialization, and no mechanism blocks any of its generated paths.
Partial exclusionAt least one generated path still includes the field, and a sink in the repository uses that path on instances of the type.
Raw attribute sinkA sink applies vars, __dict__, pickle, or default=vars to an instance that stores a credential, even if the field is fully excluded or wrapped.
Credential moved onto a holderA refactor moves a credential from a lazy read or closure onto an object field.
Wholesale serialization sinkNew or changed telemetry, logging, error-context, cache, or response code serializes every kwarg, every attribute, or whole objects without an allowlist or redaction.
Sink loses its filterA change removes or weakens redaction, an allowlist, or object-to-type-name replacement in an existing sink.
Object passed to telemetryA client, config, or settings object is passed to a span, log, or error-context call that stringifies it.

Severity

LevelUse For
highThe credential reaches a sink anywhere in the repository: log line, span attribute, error event, cache entry, persisted row, queue payload, or API response. The other side may predate the diff. Also a new wholesale sink whose existing callers pass credential-bearing objects.
mediumAn unexcluded credential field whose instances leave the constructing module, after a repository search found no sink. Also a wholesale sink with no allowlist and no traced credential-bearing caller.
lowAn unexcluded credential field whose instances never leave the constructing scope.
  • Do not downgrade because the sink or the holder is outside the diff. That is the normal shape of this bug.
  • Choose the lower severity when reachability depends on unproven preconditions.

What Not To Report

  • Fully excluded fields, unless a raw attribute sink receives the instance.
  • Partial exclusions when no sink in the repository uses the unblocked path.
  • Credentials read inside a method and never stored on the instance.
  • Placeholder or fake values in tests, fixtures, or examples.
  • Types with no generated serialization and no __dict__ or enumeration sink.
  • Sinks that already allowlist scalar keys, redact by credential name, or replace objects with a type name.
  • Pre-existing fields and sinks the diff does not touch, unless the diff connects them.
  • Style, naming, or missing-test-only observations.

Fix Guidance

Include one concrete fix per finding:

  • Holder: block every generated path, wrap the value in a redacting type, or stop storing it on the object.
  • Raw attribute sink: serialize an explicit allowlisted dict instead of the instance, or stop storing the credential on it. A field flag or wrapper does not fix it.
  • Sink: allowlist scalar keys, redact keys matching credential names, and record type(value).__name__ instead of str(value) for non-scalar values.
  • Regression test: serialize an instance with the same serializer the sink uses (for example sentry_sdk.serializer.serialize, json.dumps(asdict(obj)), JSON.stringify(obj), util.inspect(obj)) and assert the credential string is absent.

Finding Format

  • Title: name the field or sink and the leak path, for example "_shared_secret included in RpcClient dataclass repr".
  • Description: one or two sentences naming the generated path that exposes the credential, where instances travel, and the fix.
  • Evidence: 2 to 5 bullets naming the class, decorator, generated paths checked, the exclusion looked for, and every sink or caller traced, including those outside the diff.

© getsentry, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/secret-serialization of getsentry/skills.

  • SKILL.md
  • SOURCES.md
  • SPEC.md
  • references/javascript-typescript.md
  • references/python.md

Open the folder on GitHubat commit d18b7aa

Compare with similar skills

Secret Serialization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secret Serialization compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secret Serialization this skillgetsentry/skills1k—~2.6kAutomated safety check: NotesApache-2.0
Logfire Instrumentationpydantic/skills140—~6.1kAutomated safety check: PassMIT
Logfire Instrumentationbasicmachines-co/basic-memory4.1k—~2.3kAutomated safety check: PassAGPL-3.0
Bump Sentry Dependencygetsentry/sentry45k—~815Automated safety check: PassCustom licence
Inngest MiddlewareAsymmetric-al/core382—~2.9kAutomated safety check: PassAGPL-3.0
Olore Sentry Latestolorehq/olore103—~523Automated safety check: PassMIT

Similar skills

  • Official

    Add Pydantic Logfire observability to application code — traces, logs, metrics, and AI/agent spans.

    140 GitHub stars~6.1k tokensUpdated 6 days ago
    AI & LLM EngineeringAuto-check passed
  • Logfire Instrumentation

    basicmachines-co/basic-memory

    Adds Pydantic Logfire tracing, logging and metrics to Python, JavaScript or TypeScript and Rust projects, with the correct setup order and library extras.

    4.1k GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Bump Sentry Dependency

    getsentry/sentry

    Official

    Bumps an existing Python dependency in getsentry/sentry through the repository's self-serve GitHub Actions workflow.

    45k GitHub stars~815 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Inngest Middleware

    Asymmetric-al/core

    A skill your agent uses when adding cross-cutting concerns to durable functions — structured logging or tracing across all functions, error tracking with Sentry, payload encryption for sensitive…

    382 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Olore Sentry Latest

    olorehq/olore

    Local Sentry documentation reference (latest). An agent skill from olorehq/olore.

    103 GitHub stars~523 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime.

    253 GitHub stars~1.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from getsentry/skills

All 27 skills in this repo
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    Auto-check: warnings
  • Gh Review Requests

    getsentry/skills

    Official

    Fetch unread GitHub notifications for open PRs where review is requested from a specified team or opened by a team member.

    1k GitHub starsUsed in 3 repos~621 tokens
    Auto-check: notes
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    Auto-check: notes
  • Skill Writer

    getsentry/skills

    Official

    Create, synthesize, and iteratively improve agent skills following the Agent Skills specification.

    1k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Auto-check: notes
  • Gha Security Review

    getsentry/skills

    Official

    GitHub Actions security review for workflow exploitation vulnerabilities.

    1k GitHub starsUsed in 3 repos~2.2k tokens
    Auto-check: notes

Categories

Questions about Secret Serialization

What does Secret Serialization do?

Finds secrets, tokens, passwords, and API keys that can leak through generated serialization: Python dataclass repr and asdict, attrs, pydantic modeldump, NamedTuple, JavaScript JSON.stringify and…. Secret Serialization is an agent skill from getsentry/skills, published by the product's own GitHub organization.inspect, structured logs, tracing spans, and error reports.

When should I use Secret Serialization?

Secret Serialization fits situations like: asked to check for secret serialization; credential in repr; repr=False audit; secret in spans.

How do I install Secret Serialization in Claude Code?

Run `npx skills add getsentry/skills --skill secret-serialization -a claude-code`. Or copy the skill folder (skills/secret-serialization in getsentry/skills) into .claude/skills/secret-serialization in your project. Claude Code loads it when a task matches its description.

How do I install Secret Serialization in Codex?

Run `npx skills add getsentry/skills --skill secret-serialization -a codex`. Or copy the skill folder (skills/secret-serialization in getsentry/skills) into .agents/skills/secret-serialization in your project. Codex loads it when a task matches its description.

Can I use Secret Serialization in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getsentry/skills --skill secret-serialization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secret-serialization, .gemini/skills/secret-serialization, .github/skills/secret-serialization and .opencode/skills/secret-serialization in your project.

What does Secret Serialization need to run?

SKILL.md names no scripts, command-line tools or credentials: Secret Serialization is instructions for the agent only. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob.

Does Secret Serialization access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Secret Serialization safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Secret Serialization use?

Secret Serialization is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secret Serialization use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.8k tokens, read only when the agent opens those files.

What are the alternatives to Secret Serialization?

Skills that share tags, products or a category with Secret Serialization: Logfire Instrumentation (pydantic/skills, 140 stars), Logfire Instrumentation (basicmachines-co/basic-memory, 4.1k stars), Bump Sentry Dependency (getsentry/sentry, 45k stars) and Inngest Middleware (Asymmetric-al/core, 382 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secret Serialization?

getsentry (a GitHub organization, an official publisher) maintains it in getsentry/skills, which has 1,037 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 2, 2026.

Source: getsentry/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.