ratel-langfuse-analyze

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to read trace data, sessions, and metrics from a Langfuse observability platform via an MCP server and generate a markdown report.
  • [COMMAND_EXECUTION]: The skill uses Bash to check MCP configuration, but the commands are restricted to inspecting system state (mcp config) or querying the MCP server itself. No arbitrary or dangerous command execution was found.
  • [EXTERNAL_DOWNLOADS]: The skill references Langfuse endpoints and GitHub paths, but these are well-known services or part of the vendor's own ecosystem (ratel-ai). No untrusted remote scripts or binaries are downloaded or executed.
  • [DATA_EXFILTRATION]: While the skill accesses sensitive trace and cost data, it does so within the local environment. It instructs the agent to write findings to a local file (.ratel/) and explicitly warns against querying external cloud URLs directly via WebFetch. No evidence of unauthorized data transmission was detected.
  • [PROMPT_INJECTION]: The skill's instructions focus on structured data analysis and follow-up tasks. It includes logic to handle 'honest skips' when data is clean, preventing the AI from hallucinating findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 05:05 PM
Security Audit — agent-trust-hub — ratel-langfuse-analyze