langfuse
Warn
Audited by Socket on Jul 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is plausible, but it routes Langfuse credentials and observability data through a third-party MCP package from a personal repo instead of Langfuse's documented same-org hosted MCP endpoint. This is a coherent debugging workflow, but the install trust and credential/data-flow design are disproportionate enough to warrant caution.
Confidence: 90%Severity: 81%
Audit Metadata