Langfuse Core Workflow ASAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: langfuse-core-workflow-a description: 'Execute Langfuse primary workflow: Tracing LLM calls and spans. Use when implementing LLM tracing, building traced AI features, or adding observability to existing LLM applications. Trigger with phrases like "langfuse tracing", "trace LLM calls", "add langfuse to openai", "langfuse spans", "track llm requests". ' allowed-tools: Read, Write, Edit, Bash(npm:*), Grep version: 1.17.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - langfuse - observability - llm - workflow compatibility: Designed for Claude Code --- # Langfuse Core Workflow A: Tracing LLM Calls ## Overview End-to-end tracing of LLM calls, chains, and agents. Covers the OpenAI drop-in wrapper, manual tracing with `startActiveObservation`, RAG pipeline instrumentation, streaming response tracking, and LangChain integration. ## Prerequisites - Completed `langfuse-install-auth` setup - OpenAI SDK installed (`npm install openai`) - For v4+: `@langfuse/openai`, `@langfuse/tracing`, `@langfuse/otel`, `@opentelemetry/sdk-node` ## Instructions ### Step 1: OpenAI Drop-In Wrapper (Zero-Code Tracing) ```typescript import OpenAI from "openai"; import { observeOpenAI } from "@langfuse/openai"; // Wrap the OpenAI client -- all calls are now traced automatically const openai = observeOpenAI(new OpenAI()); // Every call captures: model, input, output, tokens, latency, cost const response = await openai.chat.completions.create({ model: "gpt-4o", messages: [ { role: "system", content: "You are a helpful assistant." }, { role: "user", content: "What is Langfuse?" }, ], }); // Add metadata to traces const res = await observeOpenAI(new OpenAI(), { generationName: "product-description", generationMetadata: { feature: "onboarding" }, sessionId: "session-abc", userId: "user-123", tags: ["production", "onboarding"], }).chat.completions.create({ model: "gpt-4o-mini", messages: [{ role: "user", content: "Describe this product" }], }); ``` ### Step 2: Manual Tracing -- RAG Pipeline (v4+ SDK) ```typescript import { startActiveObservation, updateActiveObservation } from "@langfuse/tracing"; async function ragPipeline(query: string) { return await startActiveObservation("rag-pipeline", async () => { updateActiveObservation({ input: { query }, metadata: { pipeline: "rag-v2" } }); // Span: Query embedding const embedding = await startActiveObservation("embed-query", async () => { updateActiveObservation({ input: { text: query } }); const vector = await embedText(query); updateActiveObservation({ output: { dimensions: vector.length }, metadata: { model: "text-embedding-3-small" }, }); return vector; }); // Span: Vector search const documents = await startActiveObservation("vector-search", async () => { updateActiveObservation({ input: { dimensions: embedding.length } }); const docs = await searchVectorDB(embedding); updateActiveObservation({ output: { documentCount: docs.length, topScore: docs[0]?.score }, }); return docs; }); // Generation: LLM call with context const answer = await startActiveObservation( { name: "generate-answer", asType: "generation" }, async () => { updateActiveObservation({ model: "gpt-4o", input: { query, context: documents.map((d) => d.content) }, }); const result = await generateAnswer(query, documents); updateActiveObservation({ output: result.content, usage: { promptTokens: result.usage.prompt_tokens, completionTokens: result.usage.completion_tokens, }, }); return result.content; } ); updateActiveObservation({ output: { answer } }); return answer; }); } ``` ### Step 3: Manual Tracing -- RAG Pipeline (v3 Legacy) ```typescript import { Langfuse } from "langfuse"; const langfuse = new Langfuse(); async function ragPipeline(query: string) { const trace = langfuse.trace({ name: "rag-pipeline", input: { query }, metadata: { pipeline: "rag-v1" }, }); const embedSpan = trace.span({ name: "embed-query", input: { text: query } }); const embedding = await embedText(query); embedSpan.end({ output: { dimensions: embedding.length } }); const searchSpan = trace.span({ name: "vector-search" }); const documents = await searchVectorDB(embedding); searchSpan.end({ output: { count: documents.length, topScore: documents[0]?.score } }); const generation = trace.generation({ name: "generate-answer", model: "gpt-4o", modelParameters: { temperature: 0.7, maxTokens: 500 }, input: { query, context: documents.map((d) => d.content) }, }); const answer = await generateAnswer(query, documents); generation.end({ output: answer.content, usage: { promptTokens: answer.usage.prompt_tokens, completionTokens: answer.usage.completion_tokens, totalTokens: answer.usage.total_tokens, }, }); trace.update({ output: { answer: answer.content } }); await langfuse.flushAsync(); return answer.content; } ``` ### Step 4: Streaming Response Tracking ```typescript import OpenAI from "openai"; import { observeOpenAI } from "@langfuse/openai"; // The wrapper handles streaming automatically const openai = observeOpenAI(new OpenAI()); const stream = await openai.chat.completions.create({ model: "gpt-4o", messages: [{ role: "user", content: "Tell me a story" }], stream: true, stream_options: { include_usage: true }, // Required for token tracking }); let fullContent = ""; for await (const chunk of stream) { const content = chunk.choices[0]?.delta?.content || ""; fullContent += content; process.stdout.write(content); } // Token usage and latency are captured automatically by the wrapper ``` ### Step 5: Anthropic Claude Tracing (Manual) ```typescript import Ant
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__langfuse-core-workflow-a.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Langfuse Core Workflow A skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Langfuse Core Workflow A safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Langfuse Core Workflow A access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Langfuse Core Workflow A work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.