langfuse-integration

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior is mostly coherent with an observability migration skill: it installs official SDKs, edits code, and sends traces to Langfuse’s official cloud. However, it hard-codes a specific Langfuse project, instructs the agent to handle live secret keys and regulated metadata, recommends further skill installations, and references a likely outdated/misaligned LlamaIndex integration path. This looks more like a high-impact cloud integration playbook than malware, but the scope and data-routing implications make it medium risk rather than benign.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:57 PM
Package URL
pkg:socket/skills-sh/danik911%2Fthesis_project%2Flangfuse-integration%2F@40a8e57f6eb0a411488a383f25815873e2609c61