langsmith-observability

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted data from LLM interactions, creating a surface for indirect prompt injection. • Ingestion points: Interaction data is captured via the @traceable decorator and wrap_openai utility in SKILL.md. • Capability inventory: The tool transmits data to external servers and can be configured to read local files using the dangerously_allow_filesystem parameter mentioned in advanced-usage.md. • Boundary markers: Provided code examples do not demonstrate the use of specific boundary markers for untrusted content. • Sanitization: The skill provides a sanitize_inputs example for redacting sensitive fields before tracing.
  • [EXTERNAL_DOWNLOADS]: The skill fetches external resources from well-known services. It pulls prompt templates from the LangChain Hub using client.pull_prompt() and recommends installing the langsmith package from official package registries.
  • [DATA_EXFILTRATION]: The skill transmits detailed execution traces, including user inputs and model outputs, to the LangSmith observability platform (smith.langchain.com). This is the core functionality of the observability tool.
  • [COMMAND_EXECUTION]: The troubleshooting documentation suggests disabling SSL certificate verification by setting LANGSMITH_VERIFY_SSL to false, which is a security anti-pattern that increases vulnerability to network-based attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — langsmith-observability