stacktale writes a second log file (errors-ai.log) meant to be read by an automated
consumer — an AI assistant or agent. Because tools read it, its contents deserve deliberate
thought. This is the security posture and the vulnerability-reporting process.
Please do not open a public issue for a security problem. Email gabrielbaldez2009@gmail.com with details and steps to reproduce; you'll get an acknowledgement within a few days. Once a fix is available it is released and credited to you (if you'd like).
No network, no exfiltration. stacktale only appends to a local file. It opens no
sockets, makes no callbacks, and sends nothing anywhere. The optional stacktale-mcp server
is read-only and speaks JSON-RPC over stdio — there is no network listener.
Redaction is on by default — know its edges:
- Masks: values of secret-named keys (including compound keys like
db.password,x-api-key), secret-shaped values (Bearer …, JWTs, long hex runs, PEM private-key blocks, and vendor-prefixed API keys — AWS, GitHub, OpenAI, Stripe, Slack, Google), and message arguments at positions your patterns mark. The vendor prefixes matter because everything else on this line needs a keyword or a scheme word beside the value; a key named by nothing is caught by its own shape. - Can't know: a secret in an unusual shape under a benign name. Redaction is a strong default, not a guarantee.
- Harden it: add your own
redactPatterns; setcaptureExceptionFields=falseto stop reading exception getters intofields:(recommended if your domain exceptions carry sensitive state); weighredactionCorrelation(a keyed hash of masked values — see docs/FORMAT.md) against your threat model. - Verify before you trust it: in dev, read
errors-ai.logand confirm nothing sensitive leaks before wiring it near prod. Theaudit_redactiontool instacktale-mcpdoes the mechanical half — it scans the file for credential shapes and reports where, never the value. Run it before attaching a report file to a ticket, a PR or a CI artifact.
What ends up in the file (by design): the distilled exception chain, the log message and args, MDC, exception field values (unless disabled), the recent story of the same request/thread, and one environment line (app version, git sha, Java, profile, OS). Your normal logs are untouched.
Single writer. errors-ai.log assumes one writing process. Two JVMs sharing a file can
race on rotation — run one writer per file, or give each instance its own path.
Supply chain. stacktale-core has one runtime dependency (slf4j-api). The agent shades
ByteBuddy (relocated under an internal package). Releases are GPG-signed and published to
Maven Central.
Security fixes land on the latest released minor line. Please run a current version.