spring-projects/spring-ai · warning
You have enabled the inclusion of the tool call arguments…
Error message
You have enabled the inclusion of the tool call arguments and result in the observations, with the risk of exposing sensitive or private information. Please, be careful!
What it means
Warning emitted when the ToolCallingContentObservationFilter bean is created because spring.ai.tools.observations.include-content=true. This records tool call arguments and results in observations, which can expose sensitive data processed by tools (database rows, file contents, tokens). The library warns at startup that this risks leaking private information into observability systems.
Solutions
- Set spring.ai.tools.observations.include-content=false (or remove it) in production.
- Scope the flag to dev/test profiles via application-dev.yml.
- If content capture is required, restrict and audit the observability backend and add redaction where possible.
- Suppress the logger for ToolCallingAutoConfiguration in logging config once the risk is consciously accepted.
Example fix
// before (application.yml)
spring:
ai:
tools:
observations:
include-content: true
// after
spring:
ai:
tools:
observations:
include-content: false # or keep 'true' only under the dev profile Defensive patterns
Strategy: validation
Validate before calling
boolean risky = env.getProperty("spring.ai.tools.observations.include-content", Boolean.class, false);
if (risky && isProductionProfile(env)) {
throw new IllegalStateException("tool call content must not be recorded in observations in production");
} Prevention
- Treat tool call payloads as sensitive data in your threat model.
- Enable include-content only temporarily during debugging sessions.
- Review tool implementations for secrets returned in results.
- Add redaction in tools themselves so captured content is safe by construction.
When it happens
Trigger: Setting spring.ai.tools.observations.include-content=true in configuration, causing the conditional toolCallingContentObservationFilter @Bean method to log the warning and register the filter.
Common situations: Debugging tool-calling agents and leaving content capture enabled in production; tools returning credentials or PII that end up in trace spans; compliance reviews flagging tool payloads stored in observability backends.
Understand the failure class
Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.
Related errors
- You have enabled logging out the image prompt content with…
- You have enabled logging out of the query response content…
- You have enabled logging out the ChatClient completion…
- You have enabled logging out the ChatClient prompt content…
- You have enabled logging out the prompt content with the…
AI-assisted analysis of spring-projects/spring-ai@98a7beda4f (2026-09-11).
Data as JSON: /api/errors/004d99f3d6cf4710.
Report an issue: GitHub.
Appendix: source
Thrown at auto-configurations/models/tool/spring-ai-autoconfigure-model-tool/src/main/java/org/springframework/ai/model/tool/autoconfigure/ToolCallingAutoConfiguration.java:194
builder.maxTotalToolCalls(maxTotalToolCalls);
}
}
builder.onLimitExceeded(limits.getOnLimitExceeded());
var toolCallingManager = builder.build();
observationConvention.ifAvailable(toolCallingManager::setObservationConvention);
return toolCallingManager;
}
@Bean
@ConditionalOnMissingBean
@ConditionalOnProperty(prefix = ToolCallingProperties.CONFIG_PREFIX + ".observations", name = "include-content",
havingValue = "true")
ToolCallingContentObservationFilter toolCallingContentObservationFilter() {
logger.warn(
"You have enabled the inclusion of the tool call arguments and result in the observations, with the risk of exposing sensitive or private information. Please, be careful!");
return new ToolCallingContentObservationFilter();
}
private static @Nullable Class<? extends RuntimeException> getClassOrNull(String className) {
try {
Class<?> clazz = ClassUtils.forName(className, null);
if (RuntimeException.class.isAssignableFrom(clazz)) {
return (Class<? extends RuntimeException>) clazz;
}
else {
if (logger.isDebugEnabled()) {
logger.debug("Class " + className + " is not a subclass of RuntimeException");
}
}
}
catch (ClassNotFoundException e) {
if (logger.isDebugEnabled()) {View on GitHub (pinned to 98a7beda4f)