Back to skill

Security audit

N8n Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for n8n automation, but it can deploy and activate live workflows and recommends running an unpinned third-party MCP package with an n8n API key.

Install only if you are comfortable giving this MCP server access to your n8n instance. Prefer a pinned, reviewed package version, use a dedicated least-privilege and revocable n8n API key, keep stateless use credential-free, review generated workflow JSON before creation, and require explicit approval before activation on any live or production instance.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:76
Finding

Unpinned Third-Party MCP Package Is Downloaded and Executed with API Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 76–90
Vulnerability Type: Unpinned runtime dependency execution
Risk Level: High

Vulnerable Code

markdown
Add to the user's MCP config (Cursor: `~/.cursor/mcp.json`, Claude Desktop: `claude_desktop_config.json`):

```json
{
  "mcpServers": {
    "n8n": {
      "command": "npx",
      "args": ["-y", "@automatelab/n8n-mcp"],
      "env": {
        "N8N_API_URL": "https://your-n8n.example.com",
        "N8N_API_KEY": "n8n_..."
      }
    }
  }
}
text

### Technical Analysis

The configuration invokes `npx -y @automatelab/n8n-mcp` without pinning an exact package version. The `-y` option suppresses confirmation, allowing the package manager to retrieve and execute the registry-selected package release automatically. The project provides no lockfile, integrity hash, vendored implementation, or other mechanism for ensuring that the code executed later is identical to the code reviewed during this audit.

The resulting MCP process is also given `N8N_API_URL` and `N8N_API_KEY`. These values are necessary for the Skill's declared live-instance features, but they significantly increase the consequences of unsafe dependency execution. A malicious or compromised package version would execute locally under the MCP host user's account and receive the API credentials through its environment.

Merely mentioning the MCP configuration paths does not establish unauthorized credential-file access. No hardcoded operational credential or covert exfiltration endpoint was identified in the supplied file. The vulnerability is the mutable, unverified dependency being executed in a credential-bearing process.

### Attack Path

1. An attacker compromises the npm package, one of its dependencies, its maintainer account, or the relevant package publication process.
2. The attacker publishes a malicious release that is selected because the configuration do
...[truncated 1263 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin @automatelab/n8n-mcp to a reviewed exact version rather than allowing registry resolution to select a mutable release.
  2. Install the package ahead of time using a committed lockfile with integrity metadata, then configure the MCP host to invoke the reviewed local executable. Avoid downloading dependencies when the server starts.
  3. Verify package provenance, publisher identity, release signatures or attestations where available, and the complete transitive dependency tree before deployment.
  4. Remove -y so unexpected package installation cannot occur silently, although this is not a substitute for version pinning and integrity verification.
  5. Use a dedicated, revocable n8n API key with only the permissions required for the intended operations. Separate read-only audit access from workflow creation or activation access where n8n's access model permits it.
  6. Do not provide N8N_API_KEY for users who only require the four documented stateless tools.
  7. Run the MCP server in a sandbox or container with restricted filesystem access, a minimal environment, and outbound network access limited to the expected n8n endpoint and required package infrastructure.
  8. Rotate the API key after suspected package compromise and review n8n audit logs, workflow modifications, activation events, and execution access for unauthorized activity.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly recommends a default chain that can create and then activate workflows on a live n8n instance once environment variables are configured, but it does not require an explicit user confirmation or warn that these steps change production state. In an agentic context, this raises the risk of unintended deployment or activation of workflows, especially because 'generate, then ship' frames mutation as a normal default path rather than a guarded action.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.