langfuse

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Langfuse skill footprint is coherent with its stated purpose: it provides MCP-based observability tooling for Langfuse traces, exceptions, sessions, and content management, with explicit read-only safeguards. The credential and host configuration uses standard, officially recognized sources. Data flows are restricted to Langfuse APIs and MCP tooling, with no evident exfiltration or supply-chain risks in the described setup. Overall, the risk profile is low to moderate (BENIGN) given proper handling of credentials and avoidance of logging secrets.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 10:11 PM
Package URL
pkg:socket/skills-sh/avivsinai%2Flangfuse-mcp%2Flangfuse%2F@60b46653316b3dee008f0d5ddfe5110b31ee8bc3