Agent skill

Langfuse Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Implement Langfuse security best practices for API keys and data privacy.

MITAuto-check: notesAI & LLM Engineering

Install Langfuse Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill langfuse-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace langfuse-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/saas-packs/langfuse-pack/skills/langfuse-security-basics .claude/skills/langfuse-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
langfuse-security-basics
GitHub stars
2.8k
Token cost
~1.9k tokens
SKILL.md length
359 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Implement Langfuse security best practices for API keys and data privacy.

  • Works in 5 steps: Credential Security → PII Scrubbing Before Tracing → Self-Hosted Hardening → …
  • Securing Langfuse integration
  • SKILL.md covers Overview, Prerequisites, Instructions and Security Checklist, plus 4 more sections
  • Needs LANGFUSE_SECRET_KEY and LANGFUSE_PUBLIC_KEY

What it does

Langfuse Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement Langfuse security best practices for API keys and data privacy. Use when securing Langfuse integration, protecting API keys, or implementing data privacy controls for LLM observability. Trigger with phrases like "langfuse security", "langfuse API key security", "langfuse data privacy", "secure langfuse", "langfuse PII".

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in AI & LLM Engineering, covering LLM observability and Privacy and GDPR. It works with Langfuse. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Securing Langfuse integration
  • Protecting API keys
  • Implementing data privacy controls for LLM observability
  • With phrases like langfuse security

Example prompts

  • “langfuse security”
  • “langfuse API key security”
  • “langfuse data privacy”
  • “/langfuse-security-basics”

Requirements

  • Docker
  • A credential in LANGFUSE_PUBLIC_KEY
  • A credential in LANGFUSE_SECRET_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Credential Security
  2. PII Scrubbing Before Tracing
  3. Self-Hosted Hardening
  4. Git Secret Scanning
  5. Scoped API Keys and Least Privilege

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript, yaml and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • langfuse.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • LANGFUSE_SECRET_KEY
    • LANGFUSE_PUBLIC_KEY
    • ENCRYPTION_KEY
    • NEXTAUTH_SECRET
    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Langfuse Security Basics loads about 1.9k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 359 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:162
    .env
  • NoteMentions a .env fileSKILL.md:163
    .env.local
  • NoteMentions a .env fileSKILL.md:164
    .env.production
  • NoteMentions a .env fileSKILL.md:208
    | Credentials | .env files in .gitignore | |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 359 words, ~1,918 tokens.

Download SKILL.mdSave it as .claude/skills/langfuse-security-basics/SKILL.md (or your agent's skills folder).
name
langfuse-security-basics
description
Implement Langfuse security best practices for API keys and data privacy. Use when securing Langfuse integration, protecting API keys, or implementing data privacy controls for LLM observability. Trigger with phrases like "langfuse security", "langfuse API key security", "langfuse data privacy", "secure langfuse", "langfuse PII".
allowed-tools
Read, Write, Edit
compatibility
Designed for Claude Code
version
1.17.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, langfuse, api, security, observability

Langfuse Security Basics

Overview

Security practices for Langfuse LLM observability: credential management, PII scrubbing before tracing, self-hosted hardening, data retention, and secret scanning.

Prerequisites

  • Langfuse instance (cloud or self-hosted)
  • API keys provisioned
  • Understanding of data privacy requirements (GDPR, SOC2, HIPAA)

Instructions

Step 1: Credential Security

Langfuse uses two keys with different security profiles:

typescript
// Startup validation -- catch misconfigurations early
function validateLangfuseCredentials() {
  const publicKey = process.env.LANGFUSE_PUBLIC_KEY;
  const secretKey = process.env.LANGFUSE_SECRET_KEY;

  if (!publicKey || !secretKey) {
    throw new Error("LANGFUSE_PUBLIC_KEY and LANGFUSE_SECRET_KEY are required");
  }

  // Catch key swap (common mistake)
  if (secretKey.startsWith("pk-lf-")) {
    throw new Error("LANGFUSE_SECRET_KEY contains a public key (pk-lf-). Keys are swapped.");
  }

  if (publicKey.startsWith("sk-lf-")) {
    throw new Error("LANGFUSE_PUBLIC_KEY contains a secret key (sk-lf-). Keys are swapped.");
  }

  return { publicKey, secretKey };
}

// Use validated credentials
const { publicKey, secretKey } = validateLangfuseCredentials();

Key security rules:

  • Public key (pk-lf-...): Identifies the project. Safe in client-side code.
  • Secret key (sk-lf-...): Grants write access. Server-side only.
  • Store in environment variables or secret manager -- never in source code.
  • Rotate keys immediately if exposed in logs, git, or error reports.
Step 2: PII Scrubbing Before Tracing

Langfuse stores everything you send. Scrub PII from inputs and outputs before tracing.

typescript
// src/lib/pii-scrubber.ts

const PII_PATTERNS: Array<{ regex: RegExp; replacement: string }> = [
  { regex: /\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z]{2,}\b/gi, replacement: "[EMAIL]" },
  { regex: /\b\d{3}[-.]?\d{3}[-.]?\d{4}\b/g, replacement: "[PHONE]" },
  { regex: /\b\d{3}-\d{2}-\d{4}\b/g, replacement: "[SSN]" },
  { regex: /\b\d{4}[\s-]?\d{4}[\s-]?\d{4}[\s-]?\d{4}\b/g, replacement: "[CARD]" },
  { regex: /\b(?:sk|pk)-[a-zA-Z0-9_-]{20,}\b/g, replacement: "[API_KEY]" },
];

export function scrubPII(text: string): string {
  let scrubbed = text;
  for (const { regex, replacement } of PII_PATTERNS) {
    scrubbed = scrubbed.replace(regex, replacement);
  }
  return scrubbed;
}

export function scrubObject(obj: any): any {
  if (typeof obj === "string") return scrubPII(obj);
  if (Array.isArray(obj)) return obj.map(scrubObject);
  if (typeof obj === "object" && obj !== null) {
    const result: Record<string, any> = {};
    for (const [key, value] of Object.entries(obj)) {
      result[key] = scrubObject(value);
    }
    return result;
  }
  return obj;
}
typescript
// Usage with tracing
import { observe, updateActiveObservation } from "@langfuse/tracing";
import { scrubPII, scrubObject } from "./lib/pii-scrubber";

const tracedChat = observe(async (userMessage: string) => {
  // Scrub input before tracing
  updateActiveObservation({ input: scrubPII(userMessage) });

  // Send original to LLM (unscrubbed)
  const response = await callLLM(userMessage);

  // Scrub output before tracing
  updateActiveObservation({ output: scrubPII(response) });
  return response;
});
Step 3: Self-Hosted Hardening
yaml
# docker-compose.yml -- production-hardened
services:
  langfuse:
    image: langfuse/langfuse:latest
    environment:
      # Disable open registration
      - AUTH_DISABLE_SIGNUP=true
      # Enforce SSO for your domain
      - AUTH_DOMAINS_WITH_SSO_ENFORCEMENT=company.com
      # Least-privilege default role
      - LANGFUSE_DEFAULT_PROJECT_ROLE=VIEWER
      # Encrypt data at rest
      - ENCRYPTION_KEY=${ENCRYPTION_KEY}
      # Data retention (days)
      - LANGFUSE_RETENTION_DAYS=90
      # Database
      - DATABASE_URL=${DATABASE_URL}
      - NEXTAUTH_SECRET=${NEXTAUTH_SECRET}
      - SALT=${SALT}
Step 4: Git Secret Scanning

Prevent Langfuse keys from being committed:

bash
# .gitignore
.env
.env.local
.env.production
yaml
# .github/workflows/secret-scan.yml
name: Secret Scan
on: [push, pull_request]
jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Check for Langfuse keys
        run: |
          if grep -rn "sk-lf-[a-zA-Z0-9]" --include="*.ts" --include="*.js" --include="*.py" .; then
            echo "ERROR: Secret key found in source code!"
            exit 1
          fi
Step 5: Scoped API Keys and Least Privilege
typescript
// Create separate API keys per service/environment
// In Langfuse dashboard: Settings > API Keys

// Backend API service -- full write access
// LANGFUSE_SECRET_KEY=sk-lf-backend-...

// Analytics worker -- read-only access
// Use Langfuse API with read-only key
// LANGFUSE_SECRET_KEY=sk-lf-readonly-...

// CI/CD pipeline -- scoped to test project
// LANGFUSE_SECRET_KEY=sk-lf-ci-test-...
// LANGFUSE_PUBLIC_KEY=pk-lf-ci-test-...

Security Checklist

CategoryCheckStatus
CredentialsSecret key in env vars / secret manager only
CredentialsKeys validated at startup (no swap)
Credentials.env files in .gitignore
Data PrivacyPII scrubbed from trace inputs/outputs
Data PrivacyRetention policy configured
Self-HostedSignup disabled, SSO enforced
Self-HostedEncryption key set for data at rest
CI/CDSecret scanning in pipeline
AccessLeast-privilege roles per team member
Show full SKILL.md (159 more words)Show less

Error Handling

IssueCauseSolution
PII in tracesNot scrubbing before traceApply scrubPII() to all inputs/outputs
Secret key leakedKey in source codeRotate immediately, add secret scanning
Unauthorized accessDefault roles too permissiveSet LANGFUSE_DEFAULT_PROJECT_ROLE=VIEWER
Data accumulationNo retention policySet LANGFUSE_RETENTION_DAYS

Output

Produce a security checklist with an accountable owner for each control: credential storage and rotation, trace-data minimization, retention, access roles, self-hosting hardening, and CI secret scanning. The deliverable should identify whether each control is verified in the deployment environment rather than merely present in source code.

Examples

For a production deployment, keep the Langfuse write credential in the platform's secret store, inject it only into the service that emits traces, and use a separate restricted credential for CI verification. Before enabling a new trace field, test it with representative data and confirm that identifiers and free-form text are scrubbed or omitted according to the retention policy.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/saas-packs/langfuse-pack/skills/langfuse-security-basics of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Langfuse Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Langfuse Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Langfuse Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: NotesMIT
Langfuse Codebase Navigatorlangfuse/langfuse36k—~1.4kAutomated safety check: PassCustom licence
Langfuse Integration Pagelangfuse/langfuse-docs246—~3.7kAutomated safety check: PassMIT
Langfuselangfuse/skills301—~2.1kAutomated safety check: NotesMIT
Add Yourself To Team Langfuselangfuse/langfuse-docs246—~548Automated safety check: PassMIT
Weekly Production Reviewlangfuse/langfuse36k—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • Navigate Langfuse repositories, code areas, and agent skills.

    36k GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Langfuse Integration Page

    langfuse/langfuse-docs

    Create a new Langfuse integration page in the langfuse-docs repo.

    246 GitHub stars~3.7k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Langfuse

    langfuse/skills

    Interact with Langfuse and access its documentation: tracing, monitoring, creating datasets, running experiments, and evaluating AI applications.

    301 GitHub stars~2.1k tokensUpdated 10 days ago
    AI & LLM EngineeringAuto-check: notes
  • Add Yourself To Team Langfuse

    langfuse/langfuse-docs

    Add a new team member to Langfuse's canonical team data and shared team table.

    246 GitHub stars~548 tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Weekly Production Review

    langfuse/langfuse

    Prepare Langfuse weekly production reviews covering failures, fixes, open issues, and tracking gaps.

    36k GitHub stars~4.1k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Agent Setup Maintenance

    langfuse/langfuse

    Shared workflow for editing Langfuse's repo-owned agent setup under .agents/.

    36k GitHub stars~799 tokensUpdated today
    AI & LLM EngineeringAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Langfuse Security Basics

What does Langfuse Security Basics do?

Implement Langfuse security best practices for API keys and data privacy. Langfuse Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement Langfuse security best practices for API keys and data privacy.

When should I use Langfuse Security Basics?

Langfuse Security Basics fits situations like: securing Langfuse integration; protecting API keys; implementing data privacy controls for LLM observability; with phrases like langfuse security.

How do I install Langfuse Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langfuse-security-basics -a claude-code`. Or copy the skill folder (plugins/saas-packs/langfuse-pack/skills/langfuse-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/langfuse-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Langfuse Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langfuse-security-basics -a codex`. Or copy the skill folder (plugins/saas-packs/langfuse-pack/skills/langfuse-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/langfuse-security-basics in your project. Codex loads it when a task matches its description.

Can I use Langfuse Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langfuse-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/langfuse-security-basics, .gemini/skills/langfuse-security-basics, .github/skills/langfuse-security-basics and .opencode/skills/langfuse-security-basics in your project.

What does Langfuse Security Basics need to run?

Going by SKILL.md and its folder, Langfuse Security Basics needs credentials named LANGFUSE_SECRET_KEY, LANGFUSE_PUBLIC_KEY, ENCRYPTION_KEY and NEXTAUTH_SECRET. Our summary lists: Docker; A credential in LANGFUSE_PUBLIC_KEY; A credential in LANGFUSE_SECRET_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code.

Does Langfuse Security Basics access the network?

SKILL.md names 1 domain. As links in the text: langfuse.com. This is read from the text; nothing was executed.

Is Langfuse Security Basics safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Langfuse Security Basics use?

Langfuse Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Langfuse Security Basics use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Langfuse Security Basics?

Skills that share tags, products or a category with Langfuse Security Basics: Langfuse Codebase Navigator (langfuse/langfuse, 36k stars), Langfuse Integration Page (langfuse/langfuse-docs, 246 stars), Langfuse (langfuse/skills, 301 stars) and Add Yourself To Team Langfuse (langfuse/langfuse-docs, 246 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Langfuse Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.