langfuse
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the official Langfuse cloud domain (cloud.langfuse.com) for tracing data. This is a well-known service for LLM observability.
- [CREDENTIALS_UNSAFE]: The code examples include configuration for
public_keyandsecret_keyusing clear placeholders ('pk-...' and 'sk-...'). No actual credentials or secrets are exposed. - [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for ingesting user input into LLM chains (e.g., in LangChain templates). While this represents a common attack surface for LLM applications, the skill follows standard implementation patterns for the libraries discussed.
- Ingestion points: Input variables in LangChain
ChatPromptTemplateand OpenAI generation calls. - Boundary markers: Uses standard library abstractions like
ChatPromptTemplatewhich provide basic separation. - Capability inventory: Tracing LLM calls, monitoring cost, and logging generations.
- Sanitization: Relies on the underlying LLM provider and library defaults.
Audit Metadata