error-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze traces from external LLM applications, which could potentially contain adversarial instructions or malicious content.
  • Ingestion Point: Phase 1 fetches traces into error-analysis/traces.jsonl from the Langfuse API or local JSONL files.
  • Boundary Markers: The methodology strictly enforces a human-in-the-loop "Open Coding" phase where every failure note must be reviewed and confirmed by a human user via AskUserQuestion before being clustered into a taxonomy.
  • Capability Inventory: The agent uses Bash for network requests and can invoke subagents for evaluation execution.
  • Sanitization: The process relies on manual human verification to gate the interpretation of all content before it becomes part of the persistent taxonomy or eval recommendations.
  • [COMMAND_EXECUTION]: The skill provides Bash snippets for interacting with the Langfuse API using curl and jq for trace normalization.
  • The implementation includes sophisticated defensive logic (in SKILL.md and references/langfuse-traces.md) that restricts the use of insecure HTTP to local endpoints only.
  • It proactively checks for and refuses URLs containing userinfo components to prevent common credential-stealing patterns.
  • The credential usage is restricted to standard environment variable references (e.g., -u "$LANGFUSE_PUBLIC_KEY:$LANGFUSE_SECRET_KEY"), preventing secret values from being logged or echoed during execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:07 PM
Security Audit — agent-trust-hub — error-analysis