Any reason why the contents of a password parameter aren't automatically filtered out from console logs?
No one has implemented such a feature (or proposed a mechanism by which it could be implemented).
HOSTING-679 claims to implement something like this.
proposed a mechanism by which it could be implemented
This is actually possible now via TaskListenerDecorator, I think.