Geo Fundamentals
wasp-lang/wasp
Generative Engine Optimization for AI search engines (ChatGPT, Claude, Perplexity).
Audit or fix sensitive-data exposure in JS SDK diagnostics, exceptions, logging, and telemetry.
$ npx skills add openai/openai-agents-js --skill sensitive-logging-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openai/openai-agents-js sensitive-logging-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openai/openai-agents-js.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/sensitive-logging-audit .claude/skills/sensitive-logging-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sensitive-logging-audit" agent skill from https://github.com/openai/openai-agents-js/tree/main/.agents/skills/sensitive-logging-audit into .claude/skills/sensitive-logging-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sensitive-logging-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openai/openai-agents-js/tree/main/.agents/skills/sensitive-logging-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openai/openai-agents-js --skill sensitive-logging-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openai/openai-agents-js sensitive-logging-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openai/openai-agents-js.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/sensitive-logging-audit .agents/skills/sensitive-logging-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sensitive-logging-audit" agent skill from https://github.com/openai/openai-agents-js/tree/main/.agents/skills/sensitive-logging-audit into .agents/skills/sensitive-logging-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sensitive-logging-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openai/openai-agents-js --skill sensitive-logging-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openai/openai-agents-js sensitive-logging-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openai/openai-agents-js.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/sensitive-logging-audit .cursor/skills/sensitive-logging-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sensitive-logging-audit" agent skill from https://github.com/openai/openai-agents-js/tree/main/.agents/skills/sensitive-logging-audit into .cursor/skills/sensitive-logging-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sensitive-logging-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openai/openai-agents-js.git --path .agents/skills/sensitive-logging-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openai/openai-agents-js --skill sensitive-logging-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openai/openai-agents-js sensitive-logging-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openai/openai-agents-js.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/sensitive-logging-audit .gemini/skills/sensitive-logging-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sensitive-logging-audit" agent skill from https://github.com/openai/openai-agents-js/tree/main/.agents/skills/sensitive-logging-audit into .gemini/skills/sensitive-logging-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sensitive-logging-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openai/openai-agents-js sensitive-logging-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openai/openai-agents-js --skill sensitive-logging-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openai/openai-agents-js.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/sensitive-logging-audit .github/skills/sensitive-logging-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sensitive-logging-audit" agent skill from https://github.com/openai/openai-agents-js/tree/main/.agents/skills/sensitive-logging-audit into .github/skills/sensitive-logging-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sensitive-logging-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openai/openai-agents-js --skill sensitive-logging-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openai/openai-agents-js sensitive-logging-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openai/openai-agents-js.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/sensitive-logging-audit .opencode/skills/sensitive-logging-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sensitive-logging-audit" agent skill from https://github.com/openai/openai-agents-js/tree/main/.agents/skills/sensitive-logging-audit into .opencode/skills/sensitive-logging-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sensitive-logging-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sensitive-logging-auditAudit or fix sensitive-data exposure in JS SDK diagnostics, exceptions, logging, and telemetry.
Sensitive Logging Audit is an agent skill from openai/openai-agents-js, published by the product's own GitHub organization. Audit or fix sensitive-data exposure in JS SDK diagnostics, exceptions, logging, and telemetry.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `agents/openai.yaml` and `references/redaction-validation.md`).
It works with OpenAI. The repository describes itself as: A lightweight, powerful framework for multi-agent workflows and voice agents. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d8fa6c3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodegitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sensitive Logging Audit loads about 2.2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 30 tokens; SKILL.md has 1,112 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from openai/openai-agents-js at commit d8fa6c3, republished under its MIT licence (© openai). 1,112 words, ~2,165 tokens.
.claude/skills/sensitive-logging-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Inventory every runtime log sink, classify each dynamic value against the documented logger-flag contract, and fix every demonstrated model/tool input/output leak in scope. If no leak is demonstrated, report that result and leave runtime code unchanged.
Do not claim automated taint analysis. The inventory proves sink coverage and provides lexical review hints; it does not classify a value as sensitive. Source-to-sink classification still requires code tracing.
The two logger flags have a narrow contract:
dontLogModelData suppresses LLM inputs and outputs.dontLogToolData suppresses tool inputs and outputs.They are not general "hide every caller-configurable string" flags. Agent names, tool names, model names, session IDs, call IDs, trace/span IDs, response IDs, counts, byte lengths, durations, enum values, booleans, status codes, and similar operational metadata are not sensitive under this contract merely because an application can choose their values. Treat one of these as sensitive only when concrete source tracing proves that the field carries or is derived from actual model/tool input or output, or when a separate documented policy explicitly covers it.
git status --short --branch and the current commit.packages/agents-core/src/config.ts and helpers in packages/agents-core/src/logger.ts before judging call sites.Run the deterministic inventory from the repository root:
node .agents/skills/sensitive-logging-audit/scripts/inventory-logging.mjs --format json > /tmp/sensitive-logging-before.json
node .agents/skills/sensitive-logging-audit/scripts/inventory-logging.mjs --summary-onlyRun its tests before relying on the report:
node --test .agents/skills/sensitive-logging-audit/scripts/inventory-logging.test.mjsReview the complete JSON ledger. Do not stop after the first confirmed leak. Prioritize:
console.* calls, because they bypass Logger policy.JSON.stringify, schema formatting, or toErrorMessage.Inventory signals are lexical prioritization hints only. A tool, model, or payload hint is not a finding and does not override source tracing.
Assign one disposition to every dynamic entry:
model: may contain model requests, responses, Realtime model events, or derived values.tool: may contain tool arguments, outputs, tool events, MCP payloads, or derived values.model+tool: may contain either class.operational: contains SDK diagnostics or metadata outside the documented model/tool input-output contract.uncertain: source tracing is incomplete; investigate before deciding.Record file, line, fingerprint, disposition, evidence, and action in the task notes. A variable name or log message is not sufficient evidence. Trace producers, formatters, callbacks, and thrown-value ownership.
Use this decision gate before calling any candidate a leak:
If any step is missing, keep the candidate uncertain or classify it as operational; do not modify runtime code.
Do not prove a leak by putting a sentinel into an operational name or identifier. That only proves that the field is logged, not that it falls under the model/tool-data contract. Caller configurability, by itself, is not sensitivity evidence.
Before changing runtime code, use $implementation-strategy and follow the repository's compatibility decision. Then implement the narrowest shared-boundary fix.
logModelActionError or logToolActionError for error-level paths.model+tool, redact when either relevant policy disables data logging.error.constructor, stack, message, cause, proxy properties, or supplemental payloads.toString, proxy, or constructor cases for ordinary SDK-owned metadata objects.When a candidate is not a leak, keep the code unchanged and record the concrete source-to-sink reason.
Read the redaction validation matrix and cover every changed sensitive path. At minimum test:
Error, string, object, supplemental payload, constructor override, revoked Proxy, and throwing getPrototypeOf cases where arbitrary thrown values are accepted;Prefer focused unit tests at the real caller boundary. Helper-only tests do not prove all call sites use the helper.
Do not add tests that expect agent names, tool names, model names, or IDs to disappear solely because a model/tool-data flag is enabled. Such a test silently broadens the public contract instead of validating it.
Run the inventory again:
node .agents/skills/sensitive-logging-audit/scripts/inventory-logging.mjs --format json > /tmp/sensitive-logging-after.jsonCompare the before/after findings by fingerprint and inspect every new or changed dynamic call. Revisit the full candidate list, not only edited files. The completion report must state:
Do not report completion while a demonstrated leak remains in scope.
packages/ changed, use $changeset-validation and ensure every affected package has an appropriate changeset.$code-change-verification and rerun the full stack after the final fix.$pr-draft-summary after all edits and verification.Lead with whether any real model/tool payload leaks were found. Separate confirmed leaks from conservative review candidates and operational metadata. Include the inventory counts, affected paths, adversarial cases, verification results, and remaining uncertainty. Do not present candidate counts as vulnerability counts, and do not equate a clean inventory shape with proof that all dynamic values are non-sensitive.
© openai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references) in .agents/skills/sensitive-logging-audit of openai/openai-agents-js.
Open the folder on GitHubat commit d8fa6c3
Sensitive Logging Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sensitive Logging Audit this skillopenai/openai-agents-js | 3.9k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Geo Fundamentalswasp-lang/wasp | 19k | 8 repos | ~861 | Automated safety check: Pass | MIT | |
| AI SDKvercel-labs/ai-facts | 168 | 21 repos | ~1.2k | Automated safety check: Pass | None | |
| AI Image Generation and Editingzhayujie/CowAgent | 47k | — | ~1.3k | Automated safety check: Pass | MIT | |
| PR Design DocOpenHands/OpenHands | 90k | — | ~2.4k | Automated safety check: Pass | MIT | |
| SEO GeoReScienceLab/opc-skills | 1.8k | 4 repos | ~2.1k | Automated safety check: Pass | Apache-2.0 |
wasp-lang/wasp
Generative Engine Optimization for AI search engines (ChatGPT, Claude, Perplexity).
vercel-labs/ai-facts
Answer questions about the AI SDK and help build AI-powered features.
zhayujie/CowAgent
Generates or edits images from text prompts through a Python script that picks an image backend based on which API keys are configured.
OpenHands/OpenHands
For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…
ReScienceLab/opc-skills
SEO & GEO (Generative Engine Optimization) for websites. An agent skill from ReScienceLab/opc-skills.
andrewyng/context-hub
Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.
openai/openai-agents-js
Validate changesets in openai-agents-js using LLM judgment against git diffs (including uncommitted local changes).
openai/openai-agents-js
Keep pnpm current: preflight the published package and pnpm/action-setup self-installer, update pnpm locally, align packageManager in package.json, and refresh CI pins.
openai/openai-agents-js
Assess a JS SDK release candidate or release plan against the previous release and recommend ship or block.
openai/openai-agents-js
Plan and, after explicit approval, execute runtime-behavior probes for local or live integrations.
openai/openai-agents-js
Run the required final install, build, type, lint, test, and format checks after eligible SDK changes pass review.
openai/openai-agents-js
Analyze logs and source from a completed repository example run.
Works with
Audit or fix sensitive-data exposure in JS SDK diagnostics, exceptions, logging, and telemetry. Sensitive Logging Audit is an agent skill from openai/openai-agents-js, published by the product's own GitHub organization. Audit or fix sensitive-data exposure in JS SDK diagnostics, exceptions, logging, and telemetry.
Run `npx skills add openai/openai-agents-js --skill sensitive-logging-audit -a claude-code`. Or copy the skill folder (.agents/skills/sensitive-logging-audit in openai/openai-agents-js) into .claude/skills/sensitive-logging-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openai/openai-agents-js --skill sensitive-logging-audit -a codex`. Or copy the skill folder (.agents/skills/sensitive-logging-audit in openai/openai-agents-js) into .agents/skills/sensitive-logging-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openai/openai-agents-js --skill sensitive-logging-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sensitive-logging-audit, .gemini/skills/sensitive-logging-audit, .github/skills/sensitive-logging-audit and .opencode/skills/sensitive-logging-audit in your project.
Going by SKILL.md and its folder, Sensitive Logging Audit needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and git). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Sensitive Logging Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Sensitive Logging Audit: Geo Fundamentals (wasp-lang/wasp, 19k stars), AI SDK (vercel-labs/ai-facts, 168 stars), AI Image Generation and Editing (zhayujie/CowAgent, 47k stars) and PR Design Doc (OpenHands/OpenHands, 90k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openai (a GitHub organization, an official publisher) maintains it in openai/openai-agents-js, which has 3,892 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 6, 2026.
Source: openai/openai-agents-js on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.