langfuse-integration

Fail

Audited by Snyk on Apr 9, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). No obfuscated backdoors or remote-exec constructs were found, but the content explicitly and repeatedly instructs automated instrumentation that will send sensitive pharmaceutical data (user IDs/emails, session IDs, URS contents, compliance metadata) and uses environment-held API keys to a specific external Langfuse Cloud project — a high-risk data-exfiltration / supply-chain exposure if the remote project or keys are untrusted.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 9, 2026, 09:56 PM
Issues
1