langfuse-enterprise-rbac
Fail
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: CRITICAL
Full Analysis
- [SAFE]: The skill provides documentation and implementation examples for setting up Langfuse Role-Based Access Control. No malicious code or behaviors were identified.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or sensitive secrets were found. Code snippets correctly use environment variable placeholders like
${ENCRYPTION_KEY}and truncated strings for API keys. - [EXTERNAL_DOWNLOADS]: No remote code execution or suspicious external downloads are present. The skill mentions the legitimate '@langfuse/client' library in its examples.
- [PROMPT_INJECTION]: The instructions do not contain any patterns intended to bypass AI safety guidelines, extract system prompts, or override agent behavior.
- [SAFE]: The URLs flagged by automated scanners (e.g., 'langfuse.your-domain.com') are used as generic placeholders for user-specific deployment domains in the documentation and do not represent a security risk.
Recommendations
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata