langfuse

Warn

Audited by Socket on Jul 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but it routes Langfuse credentials and observability data through a third-party MCP package from a personal repo instead of Langfuse's documented same-org hosted MCP endpoint. This is a coherent debugging workflow, but the install trust and credential/data-flow design are disproportionate enough to warrant caution.

Confidence: 90%Severity: 81%
Audit Metadata
Analyzed At
Jul 17, 2026, 05:37 AM
Package URL
pkg:socket/skills-sh/avivsinai%2Fskills-marketplace%2Flangfuse%2F@50166b50766d006b227e6289ab1feffa7a9e806881ac47236269440bb393f5a2
Security Audit — socket — langfuse