Atlas / MCP servers / langfuse / Langfuse Prompts

Langfuse PromptsSAFE

mcp/langfuse/langfuse-prompts

Model Context Protocol (MCP) Server for Langfuse Prompt Management. This server allows you to access and manage your Langfuse prompts through the Model Context Protocol.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
MIT
Stars
173
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Model Context Protocol (MCP) Server for Langfuse Prompt Management. This server allows you to access and manage your Langfuse prompts through the Model Context Protocol.

Demo

Quick demo of Langfuse Prompts MCP in Claude Desktop (unmute for voice-over explanations):

https://github.com/user-attachments/assets/61da79af-07c2-4f69-b28c-ca7c6e606405

Features

MCP Prompt

This server implements the MCP Prompts specification for prompt discovery and retrieval.

  • prompts/list: List all available prompts
  • Optional cursor-based pagination
  • Returns prompt names and their required arguments, limitation: all arguments are assumed to be optional and do not include descriptions as variables do not have specification in Langfuse
  • Includes next cursor for pagination if there's more than 1 page of prompts
  • prompts/get: Get a specific prompt
  • Transforms Langfuse prompts (text and chat) into MCP prompt objects
  • Compiles prompt with provided variables

Tools

To increase compatibility with other MCP clients that do not support the prompt capability, the server also exports tools that replicate the functionality of the MCP Prompts.

  • get-prompts: List available prompts
  • Optional cursor parameter for pagination
  • Returns a list of prompts with their arguments
  • get-prompt: Retrieve and compile a specific prompt
  • Required name parameter: Name of the prompt to retrieve
  • Optional arguments parameter: JSON object with prompt variables

Development

npm install

# build current file
npm run build

# test in mcp inspector
npx @modelcontextprotocol/inspector node ./build/index.js

Usage

Step 1: Build

npm install
npm run build

Step 2: Add the server to your MCP servers:

Claude Desktop

Configure Cl

Read from source at commit 55cd94cf6ceeOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-server-langfuse -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server-langfuse": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
get-promptreadGet a prompt that is stored in Langfuse
get-promptsreadGet prompts that are stored in Langfuse
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, langfuse, zod, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 55cd94cf6ceefull audit observations/trust-audit/mcp-server/langfuse__langfuse-prompts.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0655cd94cf6ceeSAFEB89first audit
06

Questions

What is the Langfuse Prompts MCP server?

Model Context Protocol (MCP) Server for Langfuse Prompt Management. This server allows you to access and manage your Langfuse prompts through the Model Context Protocol.

What tools does Langfuse Prompts expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Langfuse Prompts safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Langfuse Prompts need?

No credential environment variables were found in its source, so it appears to need none.

How does Langfuse Prompts run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-server-langfuse at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (55cd94cf6cee), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement