dspy-langfuse

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates the ingestion of untrusted data (e.g., support ticket text in examples.md and search queries in SKILL.md) into DSPy modules. This represents a potential surface for indirect prompt injection where malicious instructions in the data could influence agent behavior. The examples lack explicit boundary markers or sanitization logic, which is common for integration documentation but should be addressed in production deployments.
  • [EXTERNAL_DOWNLOADS]: The documentation guides users to install well-known and standard libraries from the Python Package Index (PyPI), including langfuse, dspy, and openinference-instrumentation-dspy. These are legitimate tools for the stated purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 06:13 AM
Security Audit — agent-trust-hub — dspy-langfuse