langsmith-observability
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted data from LLM interactions, creating a surface for indirect prompt injection. • Ingestion points: Interaction data is captured via the @traceable decorator and wrap_openai utility in SKILL.md. • Capability inventory: The tool transmits data to external servers and can be configured to read local files using the dangerously_allow_filesystem parameter mentioned in advanced-usage.md. • Boundary markers: Provided code examples do not demonstrate the use of specific boundary markers for untrusted content. • Sanitization: The skill provides a sanitize_inputs example for redacting sensitive fields before tracing.
- [EXTERNAL_DOWNLOADS]: The skill fetches external resources from well-known services. It pulls prompt templates from the LangChain Hub using client.pull_prompt() and recommends installing the langsmith package from official package registries.
- [DATA_EXFILTRATION]: The skill transmits detailed execution traces, including user inputs and model outputs, to the LangSmith observability platform (smith.langchain.com). This is the core functionality of the observability tool.
- [COMMAND_EXECUTION]: The troubleshooting documentation suggests disabling SSL certificate verification by setting LANGSMITH_VERIFY_SSL to false, which is a security anti-pattern that increases vulnerability to network-based attacks.
Audit Metadata