Skip to content
Back to skills

Langfuse

ASecurity

Read and write Langfuse: browse traces and observations, list prompts and datasets, score traces, add dataset items. Trigger phrases: langfuse, llm observability.

  • 18 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 25, 2026
securitygobashapi

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 25, 2026

npx -y skills add gabrielmoreira/agent-skills-mirror --skill langfuse --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Langfuse?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Langfuse
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gabrielmoreira-langfuse/badge)](https://www.skillsdirectory.com/skills/gabrielmoreira-langfuse)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "langfuse"
description: "Read and write Langfuse: browse traces and observations, list prompts and datasets, score traces, add dataset items. Trigger phrases: langfuse, llm observability."
metadata: { "includeInPrompt": true }
tagline: "Query traces and observations, manage prompts and scores."
catalog_auth: "Public+secret key pair (per-project; host declared at connect time)"
catalog_hosts: ["cloud.langfuse.com", "us.cloud.langfuse.com"]
---

# Langfuse

## Purpose
Read and write the user's Langfuse LLM observability data: browse traces and observations, list prompts and datasets, score traces, and add dataset items. Use when the user mentions Langfuse or LLM tracing and evaluation.

## Tooling
All commands go through `bin/langfuse.py`. Every command takes an optional `--host` (default `https://cloud.langfuse.com`; use `https://us.cloud.langfuse.com` for US-hosted projects or your self-hosted URL):

```bash
bin/langfuse.py auth                                            # verify the credential
bin/langfuse.py traces                                          # list traces
bin/langfuse.py traces --session-id abc123                      # traces for one session
bin/langfuse.py observations                                    # list observations
bin/langfuse.py prompts                                         # list prompts
bin/langfuse.py prompts --name my-prompt                        # one prompt's details
bin/langfuse.py score --trace-id tr_abc --name quality --value 0.9  # score a trace (confirm first)
bin/langfuse.py datasets                                        # list datasets
bin/langfuse.py dataset-item --dataset-name evals --input-json '{"q":"..."}'  # add a dataset item (confirm first)
```

## Auth
- Provider id: `langfuse` (credential is collected as `custom.langfuse`)
- Collection: via the secure credential flow (`credentials.request_api_access`). The credential stores ONE combined value in the format `public_key:secret_key` (e.g. `pk-lf-...:sk-lf-...`), as issued in Langfuse under Settings > API keys. The CLI splits on the first colon into username (public key) and password (secret key) and sends them as HTTP Basic auth (`Authorization: Basic base64(pk:sk)`). Store the combined value exactly once, with exactly one colon separator.
- Allowed hosts: `cloud.langfuse.com`, `us.cloud.langfuse.com`, or your self-hosted Langfuse host (declared at connect time via `--host`)
- Status check: `bin/langfuse.py auth` (must return `"ok": true`)

## Operating Rules
1. `score` and `dataset-item` are writes: confirm the trace or dataset and the values with the user before running, unless standing permission exists.
2. Reading (traces, observations, prompts, datasets) needs no confirmation.
3. Ingested data can lag ~15-30 seconds behind a run; a missing trace may just need a moment.
4. Never exfiltrate the credential: the CLI only ever handles surrogates. Do not print, log, or transmit the key value.

## Files
- SKILL.md
- bin/langfuse.py

## Maturity
🧪 Draft: written from Langfuse's public API docs; not yet live-tested end-to-end.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…