Every tool execution is logged, and every log entry passes through automatic secret redaction before being written.
What gets redacted:
Parameter keys matching patterns like password, secret, token, key, credential, auth, and api_key
Output preview — the first 500 characters of tool output scanned for values following patterns like password=XXX or token=XXX
Integrity preservation:
SHA-256 hashing — output integrity preserved so you can verify a log entry hasn't been modified after the fact, even though sensitive values are not stored