T09 · Insecure Skill Coding Practices
- Location
scripts/n8n_status.py:27- Finding
Diagnostic commands send state-changing requests to production workflows
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly aligned with n8n automation, but its checks and triggers can send credentials and business data externally and may run real workflows during diagnostics.
Install only if you are comfortable giving the skill access to an n8n API key and letting it trigger real connected workflows. Use a dedicated least-privilege key, restrict the webhook host to HTTPS, avoid storing secrets in shell profiles, test against staging workflows first, and be cautious with status or validator commands because they POST to workflow endpoints.
scripts/n8n_status.py:27Diagnostic commands send state-changing requests to production workflows
scripts/n8n_trigger.py:23API credentials and sensitive payloads can be sent to unvalidated or insecure destinations
scripts/n8n_trigger.py:178Arbitrary content URLs can cause server-side requests from the n8n host
references/setup-guide.md:72Reusable n8n API key is persisted in plaintext shell startup files
references/setup-guide.md:26Documentation installs unpinned packages globally
scripts/n8n_status.py:78Status output discloses the configured webhook base URL despite a no-disclosure rule
SKILL.md:363Workflow targets and error details are retained in persistent Agent memory
The script reads N8N_WEBHOOK_BASE_URL from the environment and uses it directly to build outbound requests without validating the destination. If an attacker can influence that environment variable, the script can be turned into an SSRF primitive that sends authenticated requests with the X-N8N-API-KEY header to arbitrary internal or external endpoints. In this skill context, the risk is higher because the code is explicitly designed to contact automation/webhook infrastructure and repeatedly probes multiple derived paths.
import time
start = time.time()
try:
with urllib.request.urlopen(req, timeout=timeout):
ms = int((time.time() - start) * 1000)
return True, ms
except urllib.error.HTTPError as e:
The request destination is built from the N8N_WEBHOOK_BASE_URL environment variable and then used directly in urllib.request.urlopen without validating the scheme, host, or trust boundary. If an attacker can influence the environment or deployment configuration, they can redirect sensitive workflow payloads and the X-N8N-API-KEY header to an arbitrary server, creating an SSRF-style outbound exfiltration path. In this skill context, the script regularly sends CRM, invoice, meeting, and lead data, which makes misrouting especially sensitive.
req = urllib.request.Request(url, data=body, headers=headers, method=method)
try:
with urllib.request.urlopen(req, timeout=30) as response:
raw = response.read().decode("utf-8")
return json.loads(raw) if raw else {}
except urllib.error.HTTPError as e:
The script constructs an outbound HTTP request using N8N_WEBHOOK_BASE_URL taken directly from an environment variable, then sends the API key in a header to that destination. If an attacker can influence the environment or deployment configuration, they can redirect requests to an arbitrary host and capture the N8N API key or use the validator as an SSRF primitive against internal services. In an automation skill that is expected to run with real credentials, this makes the issue more dangerous because the validator actively transmits sensitive authentication material.
)
try:
with urllib.request.urlopen(req, timeout=10) as response:
return response.status, "ok"
except urllib.error.HTTPError as e:
# 404 = webhook not found, 200/201 = ok, others = workflow exists but errored
The declared description promises a tool that triggers n8n workflows from natural-language instructions to perform various automations. The supplied code instead functions as an n8n/OpenClaw status dashboard: it pings a health endpoint and eight fixed workflow paths, reports whether they appear active, and outputs status data. While the named workflows overlap thematically with the description, the code does not launch or control those workflows based on user intent. Its primary purpose is operational monitoring, not automation execution. This is a material description-behavior mismatch.
The code generally aligns with the core theme of triggering n8n automations for several listed business workflows, including lead nurturing, CRM updates, social posting, meeting follow-ups, competitor monitoring, and invoice reminders. However, the description claims triggering workflows 'using natural language' by simply describing what you want done, while the supplied code does not implement any natural-language parsing or intent interpretation; it is a command-line tool with fixed subcommands and explicit arguments. Additionally, the code includes undeclared capabilities such as an n8n health check, content repurposing, and daily business briefing triggers, which are not mentioned in the declared description. These differences are material enough to count as a mismatch, though the overall domain and many listed workflow types do match.
The declared description says the skill lets users trigger n8n workflows using natural language to perform automations. This code does not parse natural language, choose workflows based on user intent, or run business automations as requested. Instead, it is a setup validation script: it checks required environment variables and POSTs a minimal test payload to a hardcoded list of webhook endpoints to see whether they are active/responding. That is a materially different primary purpose from the declared functionality, so this is a clear description-behavior mismatch.
The README promotes automatic webhook-triggered actions with real external effects—posting content, updating CRM data, sending reminders, and returning daily digests—without a prominent warning that user data will be transmitted to an external n8n instance and may cause irreversible side effects. In this business automation context, that omission can lead to privacy, integrity, and operational risks if users trigger workflows without understanding what data leaves the agent or what downstream systems will be modified.
The README states that users can speak in plain language and the skill will automatically fire the matching n8n webhook, which implies broad activation with insufficient constraints. In an automation skill that can send emails, post to social media, and update CRM systems, ambiguous natural-language matching increases the risk of unintended or adversarially induced external actions.
The skill declares access to environment variables and describes executing Python scripts and calling remote webhooks, but it does not define an explicit tool scope such as allowed-tools or permissions. That weakens containment and reviewability, making it easier for a broadly triggered skill to access secrets or perform network actions beyond what users expect.
Claiming the skill can be triggered by 'any of these natural language phrases' without strict activation boundaries makes prompt-trigger injection and accidental execution much more likely. Because the skill is designed to drive external automations and may use API-backed webhooks, ambiguous activation materially increases the risk of unauthorized or unintended side effects.
The trigger phrases are broad and overlap with ordinary user language such as 'update CRM', 'check competitors', or 'send invoice reminder'. In a conversational agent, this can cause accidental activation of networked business automations, leading to unintended emails, CRM writes, social posts, or external data collection from casual conversation.
The example phrases at these lines are extremely short and generic (e.g., 'Check competitors' / 'Run competitor report'), making accidental invocation plausible during normal conversation. In this skill, triggering a competitor-monitor workflow could cause unintended external requests, data collection, or downstream automation execution without clear user intent beyond casual wording.
The daily-briefing triggers are highly vague and overlap with ordinary conversational requests like 'What happened overnight?' and 'Give me my briefing.' In the context of an automation skill connected to inbox, CRM, and social data, these phrases can unintentionally activate a workflow that aggregates and exposes sensitive business information to the current chat context.
The document instructs users to update credentials, connect third-party accounts, and export API keys, but it provides no security guidance on secret handling, least-privilege configuration, or the privacy implications of sending lead, email, CRM, and social data through external services. In an automation skill centered on moving user and customer data across systems, that omission increases the likelihood of credential leakage, overbroad access, or unintended disclosure of personal/business data.
The competitor-monitor template directs users to scrape external sites and send extracted content to an LLM API, but it omits warnings about target-site terms/permissions, robots restrictions, rate limiting, and the fact that scraped data is being forwarded to another external processor. This can lead to legal/compliance issues, privacy leakage, and uncontrolled transmission of third-party content or accidentally captured sensitive data.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
1. Go to app.n8n.cloud and sign up for free trial
2. Your webhook base URL will be:
`https://[your-username].app.n8n.cloud/webhook`
3. Go to Settings → API → Create API Key
4. Copy the API key
5. Export both in terminal:
The Docker command pulls n8nio/n8n without a version tag or immutable digest, so users may receive different images over time, including breaking changes or a compromised upstream image. In a setup guide for an automation platform that will handle credentials and outbound actions, this increases supply-chain and reproducibility risk.
The guide tells users to append N8N_API_KEY to shell startup files, which makes a sensitive credential persist in plaintext in a commonly read file and increases exposure through backups, dotfile syncing, local compromise, or accidental disclosure. Because this skill is explicitly designed to trigger automation workflows, theft of the API key could allow unauthorized workflow management or invocation depending on n8n permissions.
The manifest describes a skill for triggering n8n workflows from natural language to perform business automations. This file's documented purpose and implemented behavior are limited to checking instance and workflow endpoint status, measuring response times, and printing a dashboard; it does not execute the described automations.
The code hardcodes eight workflow paths and sends POST-based ping requests to determine whether endpoints exist and respond. That behavior is operational monitoring, not the natural-language workflow triggering promised by the manifest description.
The skill sends user-supplied contact and business information to external n8n webhooks with no explicit warning, confirmation, or visibility into where the data is going. While outbound transmission is the purpose of the tool, the lack of disclosure and confirmation increases the chance of accidental data leakage, especially when handling emails, CRM notes, invoice details, and meeting follow-up content.
The markdown instructs users to trigger a workflow with an email address and a named user record, which could affect external systems or leak personal data if replaced with real information. There is no warning to use non-production recipients, sandbox accounts, or synthetic test data when validating the automation.
The manifest describes triggering n8n workflows for lead nurturing, email sequences, CRM updates, social posting, meeting follow-ups, competitor monitoring, and invoice reminders. This file also exposes content repurposing and daily business briefing workflows, which are separate capabilities not reflected in the manifest description and broaden the apparent skill scope.
No suspicious patterns detected.