sensitive-info-exposure

Detect unmasked sensitive information in API responses, logs, and exports.

83|8|Updated May 6, 2026
One-click install
npx skills add https://github.com/Q16G/aster --skill sensitive-info-exposure
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sensitive-info-exposure
Source: https://github.com/Q16G/aster/tree/main/skills/pentest/sensitive-info-exposure
Command: npx skills add https://github.com/Q16G/aster --skill sensitive-info-exposure

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Skill helps identify and prevent leakage of unmasked sensitive information in interfaces, logs, and exports, safeguarding privacy and compliance.

Core Features & Use Cases

  • Detects exposure of PII, credentials, and other sensitive fields in API responses, logs, and exports.
  • Provides baseline checks and guided remediation steps to enforce data masking and access controls.
  • Use Case: run checks against user detail endpoints or export data to confirm no sensitive fields are exposed.

Quick Start

Run a test against a sample response to verify that sensitive fields are masked and not exposed in logs or exports.

Frequently Asked Questions about sensitive-info-exposure

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is sensitive data exposure and how do I prevent it in data exports?

Sensitive data exposure occurs when unmasked PII, credentials, or financial records appear in API responses, logs, or exports. You can prevent this by running deterministic checks to enforce data masking, validate access controls, and ensure closure verification for regulatory compliance.

How do I check API responses for PII and credential exposure?

Yes, you can run PII masking checks against user detail endpoints. The process verifies that sensitive fields are masked in API responses, logs, and exports, providing guided remediation steps to enforce access controls and traceability for compliance workflows.

What is the best way to ensure data masking in compliance workflows?

You validate access-control checks for sensitive user data by applying deterministic checks to API responses and exports. This enforces data masking, verifies evidence closure, and provides remediation guidance to maintain privacy and compliance across user records and system configurations.

Can I use this for financial records and system configurations?

Yes, this approach works for financial records and system configurations by applying privacy and compliance workflows across all user data. It detects unmasked sensitive fields in logs and exports, enforcing masking and access-control checks to maintain data security and traceability.

Why does sensitive data still appear in logs after baseline checks?

Sensitive information may still appear in logs if baseline checks lack closure verification. You need deterministic checks that validate evidence and traceability, ensuring masking rules are actively enforced across all API responses, logs, and data exports without gaps.