OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail3 providerslatest audit Feb 16, 2026
Independent checks from skills.sh's audit partners.
This skill provides access to the Langfuse API and documentation. It is rated HIGH risk primarily due to the potential for Indirect Prompt Injection. The agent fetches external documentation and search results from the web; if an attacker were to compromise these sources or inject malicious instructions into indexed content (like GitHub issues), they could trick the agent into executing unintended commands or modifying data via the powerful Langfuse CLI.
Detected behaviors
No alerts
No issues