Official agent skill

Sensitive Logging Audit

by openai in openai/openai-agents-python

Audit or fix sensitive-data exposure in Python SDK diagnostics, exceptions, logging, and telemetry.

OfficialMITAuto-check passedDevelopment

Install Sensitive Logging Audit

skills CLI
$ npx skills add openai/openai-agents-python --skill sensitive-logging-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openai/openai-agents-python sensitive-logging-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openai/openai-agents-python.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/sensitive-logging-audit .claude/skills/sensitive-logging-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sensitive-logging-audit
GitHub stars
30k
Token cost
~1k tokens
SKILL.md length
432 words
Files
5 (incl. scripts, references)
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Audit or fix sensitive-data exposure in Python SDK diagnostics, exceptions, logging, and telemetry.

  • Works in 6 steps: Establish the review surface → Supplement the collector with source… → Classify manually → …
  • Development work in your project
  • SKILL.md covers Objective and Workflow
  • Runs Python scripts from its folder; calls rg and uv

What it does

Sensitive Logging Audit is an agent skill from openai/openai-agents-python, published by the product's own GitHub organization. Audit or fix sensitive-data exposure in Python SDK diagnostics, exceptions, logging, and telemetry.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/redaction-validation.md` and `scripts/inventory_logging.py`).

It sits in Development. It works with Python and OpenAI. The repository describes itself as: A lightweight, powerful framework for multi-agent workflows. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/sensitive-logging-audit”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Establish the review surface
  2. Supplement the collector with source search
  3. Classify manually
  4. Fix runtime boundaries
  5. Prove caller behavior
  6. Re-run and close out

What it can do on your machine

Read from SKILL.md and the folder at commit 26345c1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • rg
    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sensitive Logging Audit loads about 1k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 31 tokens; SKILL.md has 432 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from openai/openai-agents-python at commit 26345c1, republished under its MIT licence (© openai). 432 words, ~1,012 tokens.

Download SKILL.mdSave it as .claude/skills/sensitive-logging-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
sensitive-logging-audit
description
Audit or fix sensitive-data exposure in Python SDK diagnostics, exceptions, logging, and telemetry.

Sensitive Logging Audit

Objective

Find candidate output sinks, trace their values manually, fix demonstrated leaks at shared runtime boundaries, and prove redaction with adversarial tests.

The collector is only a syntax-based search aid. It does not resolve Python aliases or control flow, certify policy guards, or prove that an absent candidate is safe.

Workflow

1. Establish the review surface
  • Work in the current checkout and preserve unrelated changes.
  • Read src/agents/_debug.py, src/agents/logger.py, and the affected callers.
  • Treat exception messages, arguments, tracebacks, causes, contexts, notes, names, URLs, and arbitrary values as potentially sensitive.
  • Read the Python redaction validation matrix.

Run the collector tests, then collect candidates:

bash
uv run python .agents/skills/sensitive-logging-audit/scripts/test_inventory.py
uv run python .agents/skills/sensitive-logging-audit/scripts/inventory_logging.py \
  --format json --output /tmp/sensitive-logging-candidates.json

The report intentionally contains no policy, safe, or guard classification.

The collector does not follow assignments such as emit = logger.error. Search the source directly and inspect aliases, callbacks, wrappers, and reflective dispatch:

bash
rg -n '\.(debug|info|warning|warn|error|exception|critical|fatal|log)\b' src/agents
rg -n '\b(print|pprint|pp|warn|warn_explicit|write|writelines|print_exc|print_exception)\b' src/agents
rg -n 'DONT_LOG_(MODEL|TOOL)_DATA|log_(model|tool|model_and_tool)_action' src/agents

Do not turn collector coverage or a textual guard into a security conclusion. Trace producers and callers.

3. Classify manually

Assign each reviewed path one disposition:

  • model: model requests, responses, Realtime events, or derived values.
  • tool: tool arguments, outputs, MCP data, tool events, or derived values.
  • model+tool: either class may reach the sink.
  • operational: demonstrated to contain only non-sensitive SDK metadata.
  • intentional-output: explicitly user-facing output rather than diagnostics.
  • uncertain: source tracing is incomplete.

Record evidence in the audit report. The script does not validate or inherit dispositions.

Show full SKILL.md (202 more words)Show less
4. Fix runtime boundaries

Before changing runtime behavior, use $implementation-strategy.

  • Check the relevant _debug.DONT_LOG_MODEL_DATA and _debug.DONT_LOG_TOOL_DATA flags before formatting or inspecting sensitive values.
  • Redact mixed model/tool values when either flag disables data logging.
  • In redacted mode, emit a fixed message and omit sensitive args, extra, and exc_info.
  • Build diagnostic-only context lazily so redacted mode never reads it.
  • Preserve useful diagnostics when sensitive-data logging is explicitly enabled.
  • Keep logging failure from changing fallback, cleanup, event, rejection, or cancellation behavior.
  • For MCP URLs, remove credentials, query parameters, and fragments in diagnostic mode; never use sanitized names as a substitute for fixed redacted messages.
5. Prove caller behavior

Add tests at every changed caller boundary. Inspect the complete LogRecord, not only rendered text. Test both redacted policies, diagnostic mode, hostile objects, exception chains, and the caller's observable fallback or cleanup behavior as applicable.

6. Re-run and close out

Re-run the collector, the manual searches, focused tests, and applicable repository gates. Use $code-change-verification for runtime or test changes and $pr-draft-summary when required.

Report candidate counts as search coverage only. Lead with confirmed leaks fixed, retained intentional output, reviewed uncertainty, and verification results. Never report a clean collector result as proof that no sensitive logging path exists.

© openai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in .agents/skills/sensitive-logging-audit of openai/openai-agents-python.

  • SKILL.md
  • agents/openai.yaml
  • references/redaction-validation.md
  • scripts/inventory_logging.py
  • scripts/test_inventory.py

Open the folder on GitHubat commit 26345c1

Compare with similar skills

Sensitive Logging Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sensitive Logging Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sensitive Logging Audit this skillopenai/openai-agents-python30k—~1kAutomated safety check: PassMIT
Audit Repo1838904818/audit-repo157—~2.8kAutomated safety check: PassMIT
Diataxis Docs Writercalf-ai/calfkit-sdk1491 repos~3kAutomated safety check: PassApache-2.0
Pypi ReleasealchemiststudiosDOTai/tunacode125—~2.2kAutomated safety check: PassMIT
Lintroryeckel/wyoming_openai218—~707Automated safety check: PassApache-2.0
Groq SDK Patternsjeremylongshore/tons-of-skills-marketplace2.8k1 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Audit Repo

    1838904818/audit-repo

    Audit a software repository and turn reproducible signals into a prioritized, evidence-backed health report or compare audit snapshots over time.

    157 GitHub stars~2.8k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Diataxis Docs Writer

    calf-ai/calfkit-sdk

    Write or improve software documentation using the Diátaxis framework — four documentation types (tutorials, how-to guides, reference, explanation), each serving a different user need.

    149 GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check passed
  • Pypi Release

    alchemiststudiosDOTai/tunacode

    This skill should be used when releasing tunacode-cli to PyPI.

    125 GitHub stars~2.2k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Lint

    roryeckel/wyoming_openai

    Run all linters (ruff, pyright) and fix issues in a loop until the codebase is clean.

    218 GitHub stars~707 tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Groq SDK Patterns

    jeremylongshore/tons-of-skills-marketplace

    Apply production-ready Groq SDK patterns for TypeScript and Python.

    2.8k GitHub starsUsed in 1 repo~1.5k tokens
    DevelopmentAuto-check passed
  • Genie API Service Docs

    qualcomm/qai-appbuilder

    GenieAPIService technical documentation retrieval. An agent skill from qualcomm/qai-appbuilder.

    246 GitHub stars~840 tokensUpdated today
    DevelopmentAuto-check passed

More from openai/openai-agents-python

All 14 skills in this repo
  • Implementation Final Review

    openai/openai-agents-python

    Official

    Review completed implementation changes before final verification.

    30k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Final Release Review

    openai/openai-agents-python

    Official

    Assess a Python SDK release candidate or release plan against the previous release and recommend ship or block.

    30k GitHub stars~5.4k tokensUpdated today
    Auto-check passed
  • Release Candidate Prep

    openai/openai-agents-python

    Official

    Prepare a local Python SDK release candidate in a dedicated worktree.

    30k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Code Change Verification

    openai/openai-agents-python

    Official

    Run the required final formatting, lint, type, and test checks after eligible SDK changes pass review.

    30k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Examples Run Analysis

    openai/openai-agents-python

    Official

    Analyze logs and source from a completed manual examples run.

    30k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Implementation Kickoff

    openai/openai-agents-python

    Official

    Carry implementation through an isolated worktree and local handoff.

    30k GitHub stars~2.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Sensitive Logging Audit

What does Sensitive Logging Audit do?

Audit or fix sensitive-data exposure in Python SDK diagnostics, exceptions, logging, and telemetry. Sensitive Logging Audit is an agent skill from openai/openai-agents-python, published by the product's own GitHub organization. Audit or fix sensitive-data exposure in Python SDK diagnostics, exceptions, logging, and telemetry.

When should I use Sensitive Logging Audit?

Sensitive Logging Audit fits situations like: development work in your project.

How do I install Sensitive Logging Audit in Claude Code?

Run `npx skills add openai/openai-agents-python --skill sensitive-logging-audit -a claude-code`. Or copy the skill folder (.agents/skills/sensitive-logging-audit in openai/openai-agents-python) into .claude/skills/sensitive-logging-audit in your project. Claude Code loads it when a task matches its description.

How do I install Sensitive Logging Audit in Codex?

Run `npx skills add openai/openai-agents-python --skill sensitive-logging-audit -a codex`. Or copy the skill folder (.agents/skills/sensitive-logging-audit in openai/openai-agents-python) into .agents/skills/sensitive-logging-audit in your project. Codex loads it when a task matches its description.

Can I use Sensitive Logging Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openai/openai-agents-python --skill sensitive-logging-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sensitive-logging-audit, .gemini/skills/sensitive-logging-audit, .github/skills/sensitive-logging-audit and .opencode/skills/sensitive-logging-audit in your project.

What does Sensitive Logging Audit need to run?

Going by SKILL.md and its folder, Sensitive Logging Audit needs Python for the scripts in its folder and the command-line tools its instructions call (rg and uv). Our summary lists: Python 3.

Does Sensitive Logging Audit access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sensitive Logging Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sensitive Logging Audit use?

Sensitive Logging Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sensitive Logging Audit use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Sensitive Logging Audit?

Skills that share tags, products or a category with Sensitive Logging Audit: Audit Repo (1838904818/audit-repo, 157 stars), Diataxis Docs Writer (calf-ai/calfkit-sdk, 149 stars), Pypi Release (alchemiststudiosDOTai/tunacode, 125 stars) and Lint (roryeckel/wyoming_openai, 218 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sensitive Logging Audit?

openai (a GitHub organization, an official publisher) maintains it in openai/openai-agents-python, which has 29,896 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 8, 2026.

Source: openai/openai-agents-python on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.