Skip to content
Back to skills

Stack Trace Exposure

ASecurity

Use when reviewing error handling middleware, API route handlers, or server responses for security-sensitive information disclosure.

  • 74,358 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
developmentgoapidatabasefrontendsecurity

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 5, 2026

npx -y skills add thedaviddias/Front-End-Checklist --skill stack-trace-exposure --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Stack Trace Exposure?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Stack Trace Exposure
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/thedaviddias-stack-trace-exposure/badge)](https://www.skillsdirectory.com/skills/thedaviddias-stack-trace-exposure)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: stack-trace-exposure
description: "Use when reviewing error handling middleware, API route handlers, or server responses for security-sensitive information disclosure."
metadata:
  category: security
  priority: high
  difficulty: intermediate
  estimatedTime: "20"
  source: frontendchecklist.io
  url: https://frontendchecklist.io/rules/security/stack-trace-exposure
---

# Prevent stack trace exposure in production error responses

Stack traces reveal file paths, function names, library versions, and sometimes database schema or configuration details. An attacker uses this information to identify the exact version of a framework or ORM, look up known CVEs for that version, and craft a targeted exploit. OWASP lists "Security Logging and Monitoring Failures" (A09) as a top-10 risk partly because organisations often expose this information without realising it.

## Quick Reference

- Never return raw error objects or stack traces in API responses
- Log full error details server-side; send only a generic message to the client
- Use a central error handler to ensure consistent sanitisation across all routes
- Assign correlation IDs so support teams can match client-visible errors to server logs

## Check

Check whether production API error responses include stack traces, file paths, or internal implementation details.

## Fix

Implement a central error handler that logs full details server-side and returns only a sanitised, generic error message to the client.

## Explain

Explain what information stack traces reveal and how attackers use that information to identify and exploit vulnerabilities.

## Code Review

Review error handlers, catch blocks, and API response code. Flag any location where error.stack, error.message (raw), or internal paths are serialised directly into a response body.

---

For full implementation details, code examples, and framework-specific guidance,
see `references/rule.md`.

Rule page: https://frontendchecklist.io/rules/security/stack-trace-exposure

Files in this skill

  • SKILL.md2 KB
  • references/rule.md8.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…