langfuse
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill documentation and reference files (e.g.,
SKILL.md,references/prompt-migration.md) explicitly instruct the user to handle sensitive API keys via environment variables or.envfiles, providing a specific warning against sharing keys directly in the chat interface. - [EXTERNAL_DOWNLOADS]: The skill fetches documentation, JSON schema files, and integration guides from the official
langfuse.comandgithub.comdomains. These are functional requirements for providing current information and tool support. - [COMMAND_EXECUTION]: The skill utilizes standard command-line tools including
npx,bunx, and theghCLI. It also employs shell utilities likegrepandxargsto manage local configuration settings. - [DATA_EXFILTRATION]: Functional API operations are performed against the Langfuse platform using user-provided credentials. A diagnostic step is included to verify authentication before continuing with data manipulation.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes application source code and prompt templates to facilitate migration to Langfuse.
- Ingestion points: Reads local codebase files and existing prompts (
references/prompt-migration.md). - Boundary markers: None identified in the provided instructions.
- Capability inventory: Uses
Bash(curl, npx, gh) andWebFetchtools. - Sanitization: Not explicitly defined; relies on standard agent parsing of code content.
Audit Metadata