Atlas / MCP servers / avivsinai / Langfuse

LangfuseCAUTION

mcp/avivsinai/langfuse-1

A Model Context Protocol (MCP) server for Langfuse, enabling AI agents to query Langfuse trace data for enhanced debugging and observability

Verdict
CAUTION
Grade
B
Trust score
82 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
113
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://badge.fury.io/py/langfuse-mcp) [](https://github.com/avivsinai/langfuse-mcp/stargazers) [](https://pypistats.org/packages/langfuse-mcp) [](https://pepy.tech/projects/langfuse-mcp) [](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT)

Usage: 12,518 PyPI downloads last month (pypistats, 2026-08-19). v0.10.1.

Local MCP server and skill for Langfuse. Debug traces, sessions, and exceptions from Claude Code, Codex, Cursor, or any MCP client.

Why this instead of native Langfuse MCP?

Use this for local debug: first-class traces, sessions, and exceptions; route-decision tools; compact / file-dump output; plus the included langfuse skill.

Use official Langfuse MCP for hosted, zero-install access to the broader API (score writes, comments, models, media).

As of June 2026:

Read from source at commit 1fb851f74378OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add langfuse-mcp --env LANGFUSE_PUBLIC_KEY=${LANGFUSE_PUBLIC_KEY} --env LANGFUSE_SECRET_KEY=${LANGFUSE_SECRET_KEY} -- uvx langfuse-mcp==0.12.1
03

Trust audit

CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (6 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (13)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/langfuse
.agents/skills/langfuse
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/langfuse
.claude/skills/langfuse
Why it matters. link not followed
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
langfuse_mcp/_compat.py:53
mod = importlib.import_module(path)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/smoke-installed-wheel.sh:53
LANGFUSE_HOST="http://127.0.0.1:9" \
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_basic.py:275
secret = "super-secret-value-abc123"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaksignore
.gitleaksignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
Makefile:8
@test "$$(readlink .claude/skills/langfuse)" = "../../skills/langfuse" || (echo "❌ .claude/skills/langfuse target is not ../../skills/langfuse" && exit 1)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
Makefile:9
@test "$$(readlink .agents/skills/langfuse)" = "../../skills/langfuse" || (echo "❌ .agents/skills/langfuse target is not ../../skills/langfuse" && exit 1)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
langfuse_mcp/__main__.py:2102
decoded = base64.b64decode(credentials.strip().encode()).decode("utf-8")
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
CONTRIBUTING.md:15
curl -sSf https://astral.sh/uv/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 1fb851f74378full audit observations/trust-audit/mcp-server/avivsinai__langfuse-1.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-071fb851f74378CAUTIONB82first audit
05

Questions

What is the Langfuse MCP server?

A Model Context Protocol (MCP) server for Langfuse, enabling AI agents to query Langfuse trace data for enhanced debugging and observability

Is Langfuse safe to connect to an agent?

With care. The audit graded it B (82/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Langfuse need?

It reads LANGFUSE_PUBLIC_KEY and LANGFUSE_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Langfuse run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as langfuse-mcp.

How current is this page?

The grade is for one exact copy of the source (1fb851f74378), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement