python-structured-logging

Warn

Audited by Socket on Sep 22, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
examples/structlog/bad.py

The code appears to process invoice-related logging rather than perform malicious activity. It contains security risks because it logs an entire payment payload and a hardcoded bearer token. The token should be removed or securely supplied only where required, and sensitive payment fields should be redacted before logging. No malware indicators or external data-exfiltration behavior are present in this fragment.

Confidence: 98%Severity: 72%
AnomalyLOW
examples/stdlib/bad.py

The code does not show evidence of malware, backdoors, exfiltration, or code execution. It contains significant logging hygiene issues: a bearer-token-like value and an entire payment payload are sent to logging infrastructure, while identifiers are printed to stdout. The token should be removed or sourced securely, and sensitive payload fields should be redacted before logging. Confidence is high because these behaviors are explicit in the provided code.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 22, 2026, 01:02 PM
Package URL
pkg:socket/skills-sh/mrkazzila%2Fpython-structured-logging-skill%2Fpython-structured-logging%2F@09743f0ca55a599758fd06f854b0fb37f28a04f47a07b348a800cd715094deb2
Security Audit — socket — python-structured-logging