What problem does it solve?
Legacy security and compliance frameworks fail to address critical telemetry-pipeline vulnerabilities common in mid-2026 environments, including CR/LF log injection that forges audit records, unredacted secrets and PII leaking across log sinks, unauthenticated metrics endpoints exposing internal topology, and exporter/webhook configurations that enable SSRF and data exfiltration. This skill closes these gaps to ensure observability data remains intact, confidential, and secure.
Core Features & Use Cases
- Log Injection Neutralization: Sanitizes CR/LF and control characters in all interpolated log values to prevent log forging and audit record corruption across every sink.
- Sensitive Data Redaction: Automatically strips secrets and PII from logs before they are shipped to downstream systems like SIEMs or cloud log services to prevent data leaks.
- Exporter & Endpoint Hardening: Audits and secures metrics endpoints, OTLP/CloudWatch exporters, and webhook sinks against unauthenticated access, unallowlisted destinations, credential exposure, and SSRF attacks.
- Use Case: A cloud-native team using Prometheus, CloudWatch, and webhook-based alerting can use this skill to validate that no log injection can hide attacker activity, no credentials are exposed in centralized logs, and no exporter can be abused to reach internal cloud metadata services.
Quick Start
Use the log-injection-telemetry skill to audit your full observability pipeline for log injection risks, unredacted sensitive data in logs, and exposed or misconfigured metrics and exporter endpoints.