langfuse-mcp-server
PyPI
v0.1.0
Published by an unidentified publisher — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
Langfuse MCP server with built-in analytics, multi-project routing, and Google OAuth. Token percentiles, accuracy metrics, failure detection, cost breakdowns, session analytics, latency analysis, context breach scanning — plus a hosted-remote deployment story.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 5 = 95. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −3 | capability blast radius (moderate) — client exposure if the model is manipulated |
| −2 | publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Untrusted-input tools ([fetch_traces, fetch_trace, fetch_observations, fetch_observation, fetch_sessions, fetch_scores]) co-exist with external-action tools ([create_comment]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.
Evidence: untrusted [fetch_traces, fetch_trace, fetch_observations, fetch_observation, fetch_sessions, fetch_scores] → sinks [create_comment]
Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.
Location: flow fetch_traces → create_comment
Each tool and what it can reach — statically extracted from the published source.
create_commentnetwork egressfetch_observationingests untrusted inputfetch_observationsingests untrusted inputfetch_scoresingests untrusted inputfetch_sessionsingests untrusted inputfetch_traceingests untrusted inputfetch_tracesingests untrusted inputaggregate_by_groupno sensitive capabilityanalyze_latencyno sensitive capabilityanalyze_sessionsno sensitive capabilitycompute_accuracyno sensitive capabilitycompute_token_percentilesno sensitive capabilitycreate_annotation_queueno sensitive capabilitycreate_annotation_queue_assignmentno sensitive capabilitycreate_annotation_queue_itemno sensitive capabilitycreate_chat_promptno sensitive capabilitycreate_datasetno sensitive capabilitycreate_dataset_itemno sensitive capabilitycreate_text_promptno sensitive capabilitydelete_annotation_queue_assignmentno sensitive capabilitydelete_annotation_queue_itemno sensitive capabilitydelete_dataset_itemno sensitive capabilitydetect_context_breachesno sensitive capabilitydetect_failuresno sensitive capabilitydiff_tracesno sensitive capabilityestimate_costsno sensitive capabilityfind_exceptionsno sensitive capabilityfind_slow_tracesno sensitive capabilityget_annotation_queueno sensitive capabilityget_annotation_queue_itemno sensitive capabilityget_commentno sensitive capabilityget_daily_metricsno sensitive capabilityget_data_schemano sensitive capabilityget_datasetno sensitive capabilityget_dataset_itemno sensitive capabilityget_error_countno sensitive capabilityget_exception_detailsno sensitive capabilityget_modelno sensitive capabilityget_promptno sensitive capabilityget_prompt_unresolvedno sensitive capabilityget_score_v2no sensitive capabilityget_session_detailsno sensitive capabilityget_user_sessionsno sensitive capabilitylist_annotation_queue_itemsno sensitive capabilitylist_annotation_queuesno sensitive capabilitylist_commentsno sensitive capabilitylist_dataset_itemsno sensitive capabilitylist_datasetsno sensitive capabilitylist_modelsno sensitive capabilitylist_projectsno sensitive capabilitylist_promptsno sensitive capabilitylist_scores_v2no sensitive capabilitylist_user_queriesno sensitive capabilitylist_usersno sensitive capabilityscore_tracesno sensitive capabilitysearch_trace_contentno sensitive capabilityupdate_annotation_queue_itemno sensitive capabilityupdate_prompt_labelsno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.1.0 latest |
A 95/100 | 1 | 1.13.0 | 2026-08-25 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan langfuse-mcp-server --online --registry pypi
Independent packages implementing the same tool, scanned with the same engine. Compare all 5 side by side →
Langfuse MCP server for accessing and analyzing telemetry data via natural language
MCP server that exposes the Langfuse REST API as tools — query traces, observations, sessions, scores, prompts, datasets, and metrics from any MCP client.
MCP server for Langfuse analytics and cost monitoring with readonly/readwrite modes via CLI flags for secure npx deployment
JurisLM Langfuse MCP Server — Prompt Management + Traces/Observations 查詢
Authenticated MCP transport with HTTP Signatures for AAuth agents
Local-first MCP server for parallel AI coding agents to claim file ownership before edits, preventing stomping on each other in the same worktree.
Agent-agnostic intercommunication system — sessions, messaging, channels, shared state, and real-time events
MCP server for AI agent task communication and delegation with diagnostic lifecycle visibility
Programmatic add/link/unlink for MCP servers across 23 AI coding agents (Claude Code, Claude Desktop, Cursor, VS Code, Codex, Gemini CLI, Zed, Cline, OpenCode, Goose, Kiro, Windsurf, and more). Functional API with dry-run support.
MCP server layer exposing agent-mesh orchestrator as an MCP agent