skills/secrets-and-logging-hygiene/SKILL.md
Workflow for preventing secret leaks and sensitive logging (PII/credentials) and adding redaction defaults.
npx skillsauth add robotti-io/copilot-security-instructions secrets-and-logging-hygieneInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when asked to scan for secrets, harden logging, or reduce sensitive data exposure.
Related prompts:
check-for-secrets.prompt.mdassess-logging.prompt.mdAuthorization and cookies by default; verify logs no longer contain bearer tokens.tools
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
testing
Analyze repository-grounded identity, access control, and authorization design with evidence-first reporting and script-validated Mermaid diagrams.
tools
Threat model a system, feature, service, or PR using Shostack's 4Q workflow, evidence-first analysis, risk scoring, and CLI-friendly Mermaid helper scripts.
content-media
Triage a dependency CVE using local repo evidence and remediation guidance.