langfuse

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Langfuse Observability skill presents a coherent, purpose-driven instrumentation framework for LLM tracing with two integration points. The data flows, credential usage, and outbound telemetry align with an observability use case and do not exhibit suspicious or malicious behavior. However, there are moderate concerns around data minimization/privacy of input content, multi-point data paths potentially complicating governance, and standard secret-management risks inherent to API-based telemetry. Overall, the footprint is proportionate to its stated purpose and is unlikely to be malicious; treat as SUSPICIOUS if privacy controls or data retention are not explicitly addressed in deployment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 04:55 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Flangfuse%2F@0f954962b25d0916f5dc30c786e8f45d5d31f02a