error-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze traces from external LLM applications, which could potentially contain adversarial instructions or malicious content.
- Ingestion Point: Phase 1 fetches traces into
error-analysis/traces.jsonlfrom the Langfuse API or local JSONL files. - Boundary Markers: The methodology strictly enforces a human-in-the-loop "Open Coding" phase where every failure note must be reviewed and confirmed by a human user via
AskUserQuestionbefore being clustered into a taxonomy. - Capability Inventory: The agent uses
Bashfor network requests and can invoke subagents for evaluation execution. - Sanitization: The process relies on manual human verification to gate the interpretation of all content before it becomes part of the persistent taxonomy or eval recommendations.
- [COMMAND_EXECUTION]: The skill provides Bash snippets for interacting with the Langfuse API using
curlandjqfor trace normalization. - The implementation includes sophisticated defensive logic (in
SKILL.mdandreferences/langfuse-traces.md) that restricts the use of insecure HTTP to local endpoints only. - It proactively checks for and refuses URLs containing userinfo components to prevent common credential-stealing patterns.
- The credential usage is restricted to standard environment variable references (e.g.,
-u "$LANGFUSE_PUBLIC_KEY:$LANGFUSE_SECRET_KEY"), preventing secret values from being logged or echoed during execution.
Audit Metadata