Security audit
OpenClaw Exporter to Langfuse
Security checks for vulnerabilities and agentic risk
Overview
This is a disclosed observability plugin that sends OpenClaw traces to a configured Langfuse endpoint, but users should treat it as sensitive because traces can include prompts, responses, tool data, and local identity metadata.
Install only for environments where sending prompts, responses, tool arguments, tool results, token usage, and trace metadata to your Langfuse or OTLP endpoint is acceptable. Use HTTPS, restrict enabledHooks where possible, avoid production secrets in traced content, review Langfuse retention/access controls, and set a pseudonymous userId instead of relying on the OS username default.
Static analysis
No suspicious patterns detected.
