一键导入
secrets-and-logging-hygiene
Workflow for preventing secret leaks and sensitive logging (PII/credentials) and adding redaction defaults.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Workflow for preventing secret leaks and sensitive logging (PII/credentials) and adding redaction defaults.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.
Triage a dependency CVE using local repo evidence and remediation guidance.
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
Review workflow for AI/LLM output usage to prevent over-trust, injection, and unsafe automation.
| name | secrets-and-logging-hygiene |
| description | Workflow for preventing secret leaks and sensitive logging (PII/credentials) and adding redaction defaults. |
Use this skill when asked to scan for secrets, harden logging, or reduce sensitive data exposure.
Related prompts:
check-for-secrets.prompt.mdassess-logging.prompt.mdAuthorization and cookies by default; verify logs no longer contain bearer tokens.