audit-langfuse-llm

Fail

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructions direct the agent to search for and extract sensitive credentials, including LANGFUSE_SECRET_KEY, from environment configuration files such as .env, .env.local, and .env.production (Phase 0a).
  • [EXTERNAL_DOWNLOADS]: The skill dynamically downloads and executes external packages using npx, specifically langfuse-cli and @playwright/cli (Phases 2 and 3).
  • [REMOTE_CODE_EXECUTION]: The skill utilizes npx to download and execute remote code at runtime for auditing and browser automation tasks.
  • [COMMAND_EXECUTION]: The skill executes various shell commands for tracing, as well as database operations using supabase:execute_sql to verify AI outputs.
  • [DYNAMIC_EXECUTION]: The skill modifies the local codebase using StrReplace to update prompt text during the 'Prompt Improvement Cycle' (Phase 5b).
  • [INDIRECT_PROMPT_INJECTION]: The skill scrapes external websites using firecrawl and uses the retrieved content to influence the drafting and modification of source code prompts.
  • Ingestion points: External content ingested via firecrawl_scrape in Phase 1a and Phase 5b.
  • Boundary markers: None; the skill uses the scraped content directly to draft improved prompt versions.
  • Capability inventory: StrReplace (file system writes), npx langfuse-cli (external service interaction), and supabase:execute_sql (database access).
  • Sanitization: No sanitization or validation of the scraped content is performed before it is used to modify the codebase.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 13, 2026, 05:12 AM
Security Audit — agent-trust-hub — audit-langfuse-llm