claude-langfuse

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely coherent with its stated Langfuse observability purpose and uses official Langfuse credential patterns, but it reads credentials from `~/.secrets` and forwards them to unseen local scripts while analyzing potentially sensitive historical prompts/tool outputs. No clear malware or deceptive exfiltration path is shown, yet the credential-loading pattern and unverified script behavior make this a moderate-risk skill rather than benign.

Confidence: 84%Severity: 55%
Audit Metadata
Analyzed At
May 5, 2026, 09:06 AM
Package URL
pkg:socket/skills-sh/stevengonsalvez%2Fagents-in-a-box%2Fclaude-langfuse%2F@0f949de082acbc21399cb01bd2adb3091261b749