Skip to content
Back to skills

Logging Design Gate

ASecurity

Use `task-agent` for bounded logging changes or `review-agent` to independently assess placement, schema, severity, redaction, correlation, and signal tradeoffs. Skip work with no logging impact and self-review requests.

  • 7 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 8, 2026
securitygosecurity

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 22, 2026

npx -y skills add machenjie/rd-skills --skill logging-design-gate --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Logging Design Gate?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Logging Design Gate
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/machenjie-logging-design-gate/badge)](https://www.skillsdirectory.com/skills/machenjie-logging-design-gate)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: logging-design-gate
description: "Use `task-agent` for bounded logging changes or `review-agent` to independently assess placement, schema, severity, redaction, correlation, and signal tradeoffs. Skip work with no logging impact and self-review requests."
---

# logging-design-gate

## Role

Support `task-agent` and `review-agent` for bounded logging decisions.

- **Task mode (`task-agent`):** Apply the accepted logging purpose, placement, and schema.
- **Review mode (`review-agent`):** Judge logging against purpose, safety, and signal criteria.

## When To Use

- logging schema or redaction change
- diagnostic gap

## Do Not Use

- no logging impact
- self review request

## Required Inputs

- acceptance
- logging decision
- **Task mode (`task-agent`):** event boundary, logger policy, sensitive-field classification, and signal checks.
- **Review mode (`review-agent`):** changed event paths with safe-logging evidence.

## Professional Decision Rules

- Keep the selected logging design gate decision within its declared owner, inputs, stops, and output contract.
- Emit a log only for a named diagnostic, audit, security, or operational question, at the single boundary owning the final outcome rather than at duplicate retry or wrapper paths.
- Derive level, stable schema, purpose-required fields, redaction, and correlation from current logger and data-classification policy; exclude raw secrets, payloads, and unnecessary identity.
- Bound rate, value space, cardinality, retention, access, sink, cost, and failure visibility with measured or platform evidence and a named owner.

## High-Value Gotchas

- More events can reduce diagnostic value through volume, cardinality, or duplicate noise.
- Redaction after formatting can expose sensitive values before the sink applies policy.
- A schema change can silently break alerts, audit consumers, or correlation.

## Execution Checklist

- **Task mode:** Map the diagnostic question to its event owner, placement, schema, and sink.
- **Task mode:** Apply approved field classification, redaction, level, and correlation decisions.
- **Review mode:** Compare emitted and suppressed paths with purpose and safe-logging evidence.
- Record unmeasured volume, consumer drift, and inaccessible sink behavior as residual risk.
- Minimal validation: run emission and suppression tests at the selected sink boundary.

## Stop / Escalation Conditions

- Stop without a named question, event owner, placement, consumer meaning, current data/sink policy, and negative proof.
- Stop unbounded volume/cardinality or sensitive evidence without measured bounds, authority, redaction, scope, and recovery.

## Output Contract

- **Task mode (`task-agent`):** logging changes; placement and redaction evidence; signal risk.
- **Review mode (`review-agent`):** logging verdict; unsafe event findings; unproven signal behavior.

## Targeted References

| Path | Type | Load when | Do not load when | Required by | Required output |
|---|---|---|---|---|---|
| [checklist](references/checklist.md) | decision-checklist | A bounded mode needs compact checks for its triggered purpose, placement, fields, redaction, level, signal split, or validation risk | The root contract is enough or targeted proof fields are required | task-agent, review-agent | checklist-result, validation-plan |
| [index](references/index.md) | index | competing logging design gate references require dependency, conflict, or output-fragment selection | the logging design gate root or a task-named reference already resolves selection | task-agent, review-agent | reference-selection |
| [logging output and gates](references/logging-output-and-gates.md) | targeted | implementation or review needs mode-specific closure and targeted gates for selected purpose, placement, schema safety, correlation, volume, sink, or failure-visibility risk | The root result is sufficient and no selected risk needs the extended proof contract | task-agent, review-agent | gate-decision, residual-risk |
| [logging selection criteria](references/logging-selection-criteria.md) | targeted | A concrete purpose, level, field, redaction, correlation, placement, or signal choice needs more detail than the root contract | The root contract determines the no-log or bounded logging decision | task-agent, review-agent | selected-approach, residual-risk |

Files in this skill

  • SKILL.md4.8 KB
  • references/checklist.md1.2 KB
  • references/index.md1.9 KB
  • references/logging-output-and-gates.md4.8 KB
  • references/logging-selection-criteria.md4.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…