OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail4 providerslatest audit Mar 18, 2026
Independent checks from skills.sh's audit partners.
The skill provides comprehensive instructions for Langfuse instrumentation but presents a high security risk due to Indirect Prompt Injection. It directs the AI agent to ingest and analyze untrusted source code from the user's project and has the capability to suggest or implement modifications to that code.
Detected behaviors
No alerts
No issues
1/1 file flagged