Back to plugin

Security audit

OpenClaw Exporter to Langfuse

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed observability plugin that sends OpenClaw traces to a configured Langfuse endpoint, but users should treat it as sensitive because traces can include prompts, responses, tool data, and local identity metadata.

Install only for environments where sending prompts, responses, tool arguments, tool results, token usage, and trace metadata to your Langfuse or OTLP endpoint is acceptable. Use HTTPS, restrict enabledHooks where possible, avoid production secrets in traced content, review Langfuse retention/access controls, and set a pseudonymous userId instead of relying on the OS username default.

Static analysis

No suspicious patterns detected.