{"record":{"id":"004d99f3d6cf4710","repo":"spring-projects/spring-ai","slug":"you-have-enabled-the-inclusion-of-the-tool-call-ar","errorCode":null,"errorMessage":"You have enabled the inclusion of the tool call arguments and result in the observations, with the risk of exposing sensitive or private information. Please, be careful!","messagePattern":"You have enabled the inclusion of the tool call arguments and result in the observations, with the risk of exposing sensitive or private information\\. Please, be careful!","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"auto-configurations/models/tool/spring-ai-autoconfigure-model-tool/src/main/java/org/springframework/ai/model/tool/autoconfigure/ToolCallingAutoConfiguration.java","lineNumber":194,"sourceCode":"\t\t\t\tbuilder.maxTotalToolCalls(maxTotalToolCalls);\n\t\t\t}\n\t\t}\n\n\t\tbuilder.onLimitExceeded(limits.getOnLimitExceeded());\n\n\t\tvar toolCallingManager = builder.build();\n\n\t\tobservationConvention.ifAvailable(toolCallingManager::setObservationConvention);\n\n\t\treturn toolCallingManager;\n\t}\n\n\t@Bean\n\t@ConditionalOnMissingBean\n\t@ConditionalOnProperty(prefix = ToolCallingProperties.CONFIG_PREFIX + \".observations\", name = \"include-content\",\n\t\t\thavingValue = \"true\")\n\tToolCallingContentObservationFilter toolCallingContentObservationFilter() {\n\t\tlogger.warn(\n\t\t\t\t\"You have enabled the inclusion of the tool call arguments and result in the observations, with the risk of exposing sensitive or private information. Please, be careful!\");\n\t\treturn new ToolCallingContentObservationFilter();\n\t}\n\n\tprivate static @Nullable Class<? extends RuntimeException> getClassOrNull(String className) {\n\t\ttry {\n\t\t\tClass<?> clazz = ClassUtils.forName(className, null);\n\t\t\tif (RuntimeException.class.isAssignableFrom(clazz)) {\n\t\t\t\treturn (Class<? extends RuntimeException>) clazz;\n\t\t\t}\n\t\t\telse {\n\t\t\t\tif (logger.isDebugEnabled()) {\n\t\t\t\t\tlogger.debug(\"Class \" + className + \" is not a subclass of RuntimeException\");\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\t\tcatch (ClassNotFoundException e) {\n\t\t\tif (logger.isDebugEnabled()) {","sourceCodeStart":176,"sourceCodeEnd":212,"githubUrl":"https://github.com/spring-projects/spring-ai/blob/98a7beda4f29d80a71c5837eb4053b03a93a46f7/auto-configurations/models/tool/spring-ai-autoconfigure-model-tool/src/main/java/org/springframework/ai/model/tool/autoconfigure/ToolCallingAutoConfiguration.java#L176-L212","documentation":"Warning emitted when the ToolCallingContentObservationFilter bean is created because spring.ai.tools.observations.include-content=true. This records tool call arguments and results in observations, which can expose sensitive data processed by tools (database rows, file contents, tokens). The library warns at startup that this risks leaking private information into observability systems.","triggerScenarios":"Setting spring.ai.tools.observations.include-content=true in configuration, causing the conditional toolCallingContentObservationFilter @Bean method to log the warning and register the filter.","commonSituations":"Debugging tool-calling agents and leaving content capture enabled in production; tools returning credentials or PII that end up in trace spans; compliance reviews flagging tool payloads stored in observability backends.","solutions":["Set spring.ai.tools.observations.include-content=false (or remove it) in production.","Scope the flag to dev/test profiles via application-dev.yml.","If content capture is required, restrict and audit the observability backend and add redaction where possible.","Suppress the logger for ToolCallingAutoConfiguration in logging config once the risk is consciously accepted."],"exampleFix":"// before (application.yml)\nspring:\n  ai:\n    tools:\n      observations:\n        include-content: true\n// after\nspring:\n  ai:\n    tools:\n      observations:\n        include-content: false  # or keep 'true' only under the dev profile","handlingStrategy":"validation","validationCode":"boolean risky = env.getProperty(\"spring.ai.tools.observations.include-content\", Boolean.class, false);\nif (risky && isProductionProfile(env)) {\n    throw new IllegalStateException(\"tool call content must not be recorded in observations in production\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Treat tool call payloads as sensitive data in your threat model.","Enable include-content only temporarily during debugging sessions.","Review tool implementations for secrets returned in results.","Add redaction in tools themselves so captured content is safe by construction."],"tags":["observability","privacy","tool-calling","logging"],"backgroundTag":"invalid-config-value","analyzedSha":"98a7beda4f29d80a71c5837eb4053b03a93a46f7","analyzedAt":"2026-09-11T14:15:49.441Z","contentChangedAt":"2026-09-11T14:15:49.441Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}