6. Excessive Debug Logging with Secrets
6. Excessive Debug Logging with Secrets
LLM completions, credentials, and internal payloads logged for debugging in production mode.
Tech Detail:
- .log files include full prompt+completion strings
- API tokens exposed in stack traces or headers
Exploit Potential:
- Log scraping yields credentials, payload structures
- Prompt leakage aids in adversarial replays
Mitigation:
- Apply redaction filters (***) on sensitive keys
- Split debug and runtime logs into separate sinks