Skip to content

Sec #4: Harden tool call logging#512

Merged
kgprs merged 2 commits into
mainfrom
codex/harden-tool-call-logging
Jun 18, 2026
Merged

Sec #4: Harden tool call logging#512
kgprs merged 2 commits into
mainfrom
codex/harden-tool-call-logging

Conversation

@kgprs

@kgprs kgprs commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Run secret blocking before built-in tool call logging when both gateway options are enabled.
  • Stop logging raw tool argument values; log argument shape metadata instead.
  • Add regression tests proving blocked secret-shaped arguments do not appear in logs.

Validation

  • go test ./pkg/secretsscan ./pkg/interceptors ./pkg/gateway

@kgprs kgprs changed the title [codex] Harden tool call logging Sec #4: Harden tool call logging Jun 18, 2026
@kgprs kgprs marked this pull request as ready for review June 18, 2026 02:23
@kgprs kgprs requested a review from a team as a code owner June 18, 2026 02:24
@kgprs kgprs merged commit c135a70 into main Jun 18, 2026
8 checks passed
@kgprs kgprs deleted the codex/harden-tool-call-logging branch June 18, 2026 16:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants