Auditing Error Handling And Information Exposure

Audit error handling and diagnostic surfaces for sensitive information a real client receives, where an exception path, a debug feature, or a diagnostic endpoint returns stack traces, database errors, internal paths, framework or version banners, configuration, secrets, or messages that differ enough to enumerate users. Use when reviewing how a service responds to malformed, unauthorized, or failing requests in its deployed configuration, and whether debug modes, source maps, or version-control metadata are exposed. Scoped to what production actually returns, not developer-only verbosity. The error or diagnostic path is the source, the response, header, or user-visible log is the sink, and disclosing detail that aids a further attack is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-error-handling-and-information-exposure commit 50620ffd55

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-error-handling-and-information-exposure