Run the required final formatting, lint, type, and test checks after eligible SDK changes pass review.
日本語の概要は準備中です。原文の説明を表示しています。
Audit or fix sensitive-data exposure in Python SDK diagnostics, exceptions, logging, and telemetry.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Find candidate output sinks, trace their values manually, fix demonstrated leaks at shared runtime boundaries, and prove redaction with adversarial tests.
The collector is only a syntax-based search aid. It does not resolve Python aliases or control flow, certify policy guards, or prove that an absent candidate is safe.
src/agents/_debug.py, src/agents/logger.py, and the affected callers.Run the collector tests, then collect candidates:
uv run python .agents/skills/sensitive-logging-audit/scripts/test_inventory.py
uv run python .agents/skills/sensitive-logging-audit/scripts/inventory_logging.py \
--format json --output /tmp/sensitive-logging-candidates.json
The report intentionally contains no policy, safe, or guard classification.
The collector does not follow assignments such as emit = logger.error. Search the source directly and inspect aliases, callbacks, wrappers, and reflective dispatch:
rg -n '\.(debug|info|warning|warn|error|exception|critical|fatal|log)\b' src/agents
rg -n '\b(print|pprint|pp|warn|warn_explicit|write|writelines|print_exc|print_exception)\b' src/agents
rg -n 'DONT_LOG_(MODEL|TOOL)_DATA|log_(model|tool|model_and_tool)_action' src/agents
Do not turn collector coverage or a textual guard into a security conclusion. Trace producers and callers.
Assign each reviewed path one disposition:
model: model requests, responses, Realtime events, or derived values.tool: tool arguments, outputs, MCP data, tool events, or derived values.model+tool: either class may reach the sink.operational: demonstrated to contain only non-sensitive SDK metadata.intentional-output: explicitly user-facing output rather than diagnostics.uncertain: source tracing is incomplete.Record evidence in the audit report. The script does not validate or inherit dispositions.
Before changing runtime behavior, use $implementation-strategy.
_debug.DONT_LOG_MODEL_DATA and _debug.DONT_LOG_TOOL_DATA flags before formatting or inspecting sensitive values.args, extra, and exc_info.Add tests at every changed caller boundary. Inspect the complete LogRecord, not only rendered text. Test both redacted policies, diagnostic mode, hostile objects, exception chains, and the caller's observable fallback or cleanup behavior as applicable.
Re-run the collector, the manual searches, focused tests, and applicable repository gates. Use $code-change-verification for runtime or test changes and $pr-draft-summary when required.
Report candidate counts as search coverage only. Lead with confirmed leaks fixed, retained intentional output, reviewed uncertainty, and verification results. Never report a clean collector result as proof that no sensitive logging path exists.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Run the required final formatting, lint, type, and test checks after eligible SDK changes pass review.
日本語の概要は準備中です。原文の説明を表示しています。
Fix the tiny credit-note formatting bug and rerun the exact targeted test command.
日本語の概要は準備中です。原文の説明を表示しています。
Analyze CSV files in /mnt/data and return concise numeric summaries.
日本語の概要は準備中です。原文の説明を表示しています。
Audit or update English SDK documentation against the requested implementation scope.
日本語の概要は準備中です。原文の説明を表示しています。
Analyze logs and source from a completed manual examples run. Never execute or control examples.
日本語の概要は準備中です。原文の説明を表示しています。
Assess a Python SDK release candidate or release plan against the previous release and recommend ship or block.
日本語の概要は準備中です。原文の説明を表示しています。