Agent skill

Security Review

by langfuse in langfuse/langfuse

Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

Custom licenceAuto-check passedSecurity

Install Security Review

skills CLI
$ npx skills add langfuse/langfuse --skill security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langfuse/langfuse security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langfuse/langfuse.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-review .claude/skills/security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review
GitHub stars
35k
Token cost
~1.4k tokens
SKILL.md length
612 words
Files
5 (incl. references)
Skills in repo
33
Repo updated
First seen
Licence
Custom licence

At a glance

Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

  • Works in 2 steps: Open references/checklist.md and run the… → For each bullet that fires, open the…
  • Change accepts URLs
  • SKILL.md covers When to Apply, How to Read This Skill, Output Expectations (Review… and Output Expectations (Design /…, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Review is an agent skill from langfuse/langfuse. Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy. Use when a design or change accepts URLs or host fields, handles secrets or cross-tenant data, makes outbound requests, adds an integration, follows redirects, widens permissions, or can send customer-controlled UI data through analytics, monitoring, or session replay.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/checklist.md`, `references/client-telemetry-privacy.md` and `references/outbound-url-validation.md`).

It sits in Security, covering Security review, LLM observability and Web application vulnerabilities. It works with Langfuse. The repository describes itself as: 🪢 Open source agent evals & observability: Trace, evaluate, and improve LLM applications with one open platform.

When your agent uses it

  • Change accepts URLs
  • Handles secrets
  • Cross-tenant data
  • Makes outbound requests

Example prompts

  • “/security-review”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Open references/checklist.md and run the mental
  2. For each bullet that fires, open the matching topic reference.

What it can do on your machine

Read from SKILL.md and the folder at commit 8b58764. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review loads about 1.4k tokens when it runs, and up to ~7k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 612 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 612 words (~1,422 tokens).

“Use this skill when reviewing or planning code that touches a security-sensitive surface in Langfuse. It collects the recurring findings the team has seen in external security reports so that future agents catch them at design and review time rather…”

— opening of SKILL.md by langfuse, Custom licence
name
security-review

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (references) in .agents/skills/security-review of langfuse/langfuse.

  • SKILL.md
  • references/checklist.md
  • references/client-telemetry-privacy.md
  • references/outbound-url-validation.md
  • references/secret-read-paths.md

Open the folder on GitHubat commit 8b58764

Compare with similar skills

Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review this skilllangfuse/langfuse35k—~1.4kAutomated safety check: PassCustom licence
Security Reviewtrycompai/comp2k—~853Automated safety check: PassAGPL-3.0
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Go ReviewSpecterOps/skills702—~2.1kAutomated safety check: PassApache-2.0
Security ConvexIgorWarzocha/Opencode-Workflows122—~3.1kAutomated safety check: PassNone
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT

Similar skills

  • Security Review

    trycompai/comp

    Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it…

    2k GitHub stars~853 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Go Review

    SpecterOps/skills

    Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.

    702 GitHub stars~2.1k tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Security Convex

    IgorWarzocha/Opencode-Workflows

    Review Convex security audit patterns for authentication and authorization.

    122 GitHub stars~3.1k tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check: notes
  • Openfdd Mt Security

    bbartling/open-fdd

    Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition.

    172 GitHub stars~2.2k tokensUpdated today
    Backend & APIsAuto-check passed

More from langfuse/langfuse

All 33 skills in this repo
  • Linear Context Handover

    langfuse/langfuse

    Use Linear as the org's memory: reconstruct a feature's history before touching it, and leave the reasoning behind finished work in the ticket description so the next agent inherits it.

    35k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Add Model Price

    langfuse/langfuse

    A skill your agent uses when editing worker/src/constants/default-model-prices.json, packages/shared/src/server/llm/types.ts, pricing tiers, tokenizer IDs, or matchPattern regexes for OpenAI…

    35k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Backend Dev Guidelines

    langfuse/langfuse

    Build or review Langfuse backend code. An agent skill from langfuse/langfuse.

    35k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Navigate Langfuse repositories, code areas, and agent skills.

    35k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Refactor React Effects

    langfuse/langfuse

    Refactor avoidable React useEffect usage in Langfuse frontend code.

    35k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Add To Dependabot CSV

    langfuse/langfuse

    Append GitHub Dependabot or Snyk/code-scanning alerts to an existing vulnerability CSV after verifying their API metadata.

    35k GitHub stars~1.5k tokensUpdated today
    Auto-check passed

Works with

Questions about Security Review

What does Security Review do?

Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy. Security Review is an agent skill from langfuse/langfuse. Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

When should I use Security Review?

Security Review fits situations like: change accepts URLs; handles secrets; cross-tenant data; makes outbound requests.

How do I install Security Review in Claude Code?

Run `npx skills add langfuse/langfuse --skill security-review -a claude-code`. Or copy the skill folder (.agents/skills/security-review in langfuse/langfuse) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.

How do I install Security Review in Codex?

Run `npx skills add langfuse/langfuse --skill security-review -a codex`. Or copy the skill folder (.agents/skills/security-review in langfuse/langfuse) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.

Can I use Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langfuse/langfuse --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.

What does Security Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Review is instructions for the agent only.

Does Security Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Review use?

Security Review has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Security Review use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.6k tokens, read only when the agent opens those files.

What are the alternatives to Security Review?

Skills that share tags, products or a category with Security Review: Security Review (trycompai/comp, 2k stars), Django Access Review (getsentry/skills, 1k stars), Go Review (SpecterOps/skills, 702 stars) and Security Convex (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review?

langfuse (a GitHub organization) maintains it in langfuse/langfuse, which has 35,460 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 7, 2026.

Source: langfuse/langfuse on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.