langfuse-enterprise-rbac

Fail

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: CRITICAL
Full Analysis
  • [SAFE]: The skill provides documentation and implementation examples for setting up Langfuse Role-Based Access Control. No malicious code or behaviors were identified.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials or sensitive secrets were found. Code snippets correctly use environment variable placeholders like ${ENCRYPTION_KEY} and truncated strings for API keys.
  • [EXTERNAL_DOWNLOADS]: No remote code execution or suspicious external downloads are present. The skill mentions the legitimate '@langfuse/client' library in its examples.
  • [PROMPT_INJECTION]: The instructions do not contain any patterns intended to bypass AI safety guidelines, extract system prompts, or override agent behavior.
  • [SAFE]: The URLs flagged by automated scanners (e.g., 'langfuse.your-domain.com') are used as generic placeholders for user-specific deployment domains in the documentation and do not represent a security risk.
Recommendations
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 21, 2026, 11:30 AM
Security Audit — agent-trust-hub — langfuse-enterprise-rbac