Back to skill

Security audit

n8n Workflow Automation

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with n8n automation, but its checks and triggers can send credentials and business data externally and may run real workflows during diagnostics.

Install only if you are comfortable giving the skill access to an n8n API key and letting it trigger real connected workflows. Use a dedicated least-privilege key, restrict the webhook host to HTTPS, avoid storing secrets in shell profiles, test against staging workflows first, and be cautious with status or validator commands because they POST to workflow endpoints.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (7)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/n8n_status.py:27
Finding

Diagnostic commands send state-changing requests to production workflows

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/n8n_trigger.py:23
Finding

API credentials and sensitive payloads can be sent to unvalidated or insecure destinations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/n8n_trigger.py:178
Finding

Arbitrary content URLs can cause server-side requests from the n8n host

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/setup-guide.md:72
Finding

Reusable n8n API key is persisted in plaintext shell startup files

Content
View full analysis
> ~/.zshrc echo 'export N8N_API_KEY="your-key-here"' >> ~/.zshrc source ~/.zshrc ``` ``` ### Technical Analysis The setup guide recommends writing a reusable API key directly into a shell startup file. Shell profiles are frequently included in backups, diagnostic archives, dotfile repositories, support bundles, and terminal configuration synchronization. Their permissions may also be broader than those of a dedicated secret store. The persistence is intentional configuration rather than a hidden system backdoor, so it is not classified as system persistence. The security issue is plaintext secret storage. ### Attack Path 1. A user follows the permanent setup instructions. 2. The API key is written verbatim to `~/.zshrc`. 3. The profile is read by another local process, copied into a dotfile repository, included in a backup, or shared during troubleshooting. 4. Another party recovers the key. 5. The key is used against the associated n8n instance within its granted authorization scope. ### Impact Assessment The exposed privilege is limited to the actual permissions of `N8N_API_KEY`, but the project uses that same key for every workflow and diagnostic request. Compromise may therefore affect multiple workflows and associated business integrations. The endpoint URL is also disclosed, simplifying use of a stolen key. ]]>
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/setup-guide.md:26
Finding

Documentation installs unpinned packages globally

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/n8n_status.py:78
Finding

Status output discloses the configured webhook base URL despite a no-disclosure rule

Content
View full analysis
Remediation
View remediation

other

Note
Location
SKILL.md:363
Finding

Workflow targets and error details are retained in persistent Agent memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Tainted flow: 'req' from os.environ.get (line 34, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The script reads N8N_WEBHOOK_BASE_URL from the environment and uses it directly to build outbound requests without validating the destination. If an attacker can influence that environment variable, the script can be turned into an SSRF primitive that sends authenticated requests with the X-N8N-API-KEY header to arbitrary internal or external endpoints. In this skill context, the risk is higher because the code is explicitly designed to contact automation/webhook infrastructure and repeatedly probes multiple derived paths.

Content

Scanner excerpt · scripts/n8n_status.py (reported line 41)May include surrounding context.

python
import time
    start = time.time()
    try:
        with urllib.request.urlopen(req, timeout=timeout):
            ms = int((time.time() - start) * 1000)
            return True, ms
    except urllib.error.HTTPError as e:

Tainted flow: 'req' from os.environ.get (line 47, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The request destination is built from the N8N_WEBHOOK_BASE_URL environment variable and then used directly in urllib.request.urlopen without validating the scheme, host, or trust boundary. If an attacker can influence the environment or deployment configuration, they can redirect sensitive workflow payloads and the X-N8N-API-KEY header to an arbitrary server, creating an SSRF-style outbound exfiltration path. In this skill context, the script regularly sends CRM, invoice, meeting, and lead data, which makes misrouting especially sensitive.

Content

Scanner excerpt · scripts/n8n_trigger.py (reported line 50)May include surrounding context.

python
req = urllib.request.Request(url, data=body, headers=headers, method=method)

    try:
        with urllib.request.urlopen(req, timeout=30) as response:
            raw = response.read().decode("utf-8")
            return json.loads(raw) if raw else {}
    except urllib.error.HTTPError as e:

Tainted flow: 'req' from os.environ.get (line 65, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The script constructs an outbound HTTP request using N8N_WEBHOOK_BASE_URL taken directly from an environment variable, then sends the API key in a header to that destination. If an attacker can influence the environment or deployment configuration, they can redirect requests to an arbitrary host and capture the N8N API key or use the validator as an SSRF primitive against internal services. In an automation skill that is expected to run with real credentials, this makes the issue more dangerous because the validator actively transmits sensitive authentication material.

Content

Scanner excerpt · scripts/n8n_validator.py (reported line 70)May include surrounding context.

python
)

    try:
        with urllib.request.urlopen(req, timeout=10) as response:
            return response.status, "ok"
    except urllib.error.HTTPError as e:
        # 404 = webhook not found, 200/201 = ok, others = workflow exists but errored

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a tool that triggers n8n workflows from natural-language instructions to perform various automations. The supplied code instead functions as an n8n/OpenClaw status dashboard: it pings a health endpoint and eight fixed workflow paths, reports whether they appear active, and outputs status data. While the named workflows overlap thematically with the description, the code does not launch or control those workflows based on user intent. Its primary purpose is operational monitoring, not automation execution. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The code generally aligns with the core theme of triggering n8n automations for several listed business workflows, including lead nurturing, CRM updates, social posting, meeting follow-ups, competitor monitoring, and invoice reminders. However, the description claims triggering workflows 'using natural language' by simply describing what you want done, while the supplied code does not implement any natural-language parsing or intent interpretation; it is a command-line tool with fixed subcommands and explicit arguments. Additionally, the code includes undeclared capabilities such as an n8n health check, content repurposing, and daily business briefing triggers, which are not mentioned in the declared description. These differences are material enough to count as a mismatch, though the overall domain and many listed workflow types do match.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill lets users trigger n8n workflows using natural language to perform automations. This code does not parse natural language, choose workflows based on user intent, or run business automations as requested. Instead, it is a setup validation script: it checks required environment variables and POSTs a minimal test payload to a hardcoded list of webhook endpoints to see whether they are active/responding. That is a materially different primary purpose from the declared functionality, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes automatic webhook-triggered actions with real external effects—posting content, updating CRM data, sending reminders, and returning daily digests—without a prominent warning that user data will be transmitted to an external n8n instance and may cause irreversible side effects. In this business automation context, that omission can lead to privacy, integrity, and operational risks if users trigger workflows without understanding what data leaves the agent or what downstream systems will be modified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that users can speak in plain language and the skill will automatically fire the matching n8n webhook, which implies broad activation with insufficient constraints. In an automation skill that can send emails, post to social media, and update CRM systems, ambiguous natural-language matching increases the risk of unintended or adversarially induced external actions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill declares access to environment variables and describes executing Python scripts and calling remote webhooks, but it does not define an explicit tool scope such as allowed-tools or permissions. That weakens containment and reviewability, making it easier for a broadly triggered skill to access secrets or perform network actions beyond what users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Claiming the skill can be triggered by 'any of these natural language phrases' without strict activation boundaries makes prompt-trigger injection and accidental execution much more likely. Because the skill is designed to drive external automations and may use API-backed webhooks, ambiguous activation materially increases the risk of unauthorized or unintended side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad and overlap with ordinary user language such as 'update CRM', 'check competitors', or 'send invoice reminder'. In a conversational agent, this can cause accidental activation of networked business automations, leading to unintended emails, CRM writes, social posts, or external data collection from casual conversation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example phrases at these lines are extremely short and generic (e.g., 'Check competitors' / 'Run competitor report'), making accidental invocation plausible during normal conversation. In this skill, triggering a competitor-monitor workflow could cause unintended external requests, data collection, or downstream automation execution without clear user intent beyond casual wording.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The daily-briefing triggers are highly vague and overlap with ordinary conversational requests like 'What happened overnight?' and 'Give me my briefing.' In the context of an automation skill connected to inbox, CRM, and social data, these phrases can unintentionally activate a workflow that aggregates and exposes sensitive business information to the current chat context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document instructs users to update credentials, connect third-party accounts, and export API keys, but it provides no security guidance on secret handling, least-privilege configuration, or the privacy implications of sending lead, email, CRM, and social data through external services. In an automation skill centered on moving user and customer data across systems, that omission increases the likelihood of credential leakage, overbroad access, or unintended disclosure of personal/business data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The competitor-monitor template directs users to scrape external sites and send extracted content to an LLM API, but it omits warnings about target-site terms/permissions, robots restrictions, rate limiting, and the fact that scraped data is being forwarded to another external processor. This can lead to legal/compliance issues, privacy leakage, and uncontrolled transmission of third-party content or accidentally captured sensitive data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 13)May include surrounding context.

md
1. Go to app.n8n.cloud and sign up for free trial
2. Your webhook base URL will be:
   `https://[your-username].app.n8n.cloud/webhook`
3. Go to Settings → API → Create API Key
4. Copy the API key
5. Export both in terminal:

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The Docker command pulls n8nio/n8n without a version tag or immutable digest, so users may receive different images over time, including breaking changes or a compromised upstream image. In a setup guide for an automation platform that will handle credentials and outbound actions, this increases supply-chain and reproducibility risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide tells users to append N8N_API_KEY to shell startup files, which makes a sensitive credential persist in plaintext in a commonly read file and increases exposure through backups, dotfile syncing, local compromise, or accidental disclosure. Because this skill is explicitly designed to trigger automation workflows, theft of the API key could allow unauthorized workflow management or invocation depending on n8n permissions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill for triggering n8n workflows from natural language to perform business automations. This file's documented purpose and implemented behavior are limited to checking instance and workflow endpoint status, measuring response times, and printing a dashboard; it does not execute the described automations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code hardcodes eight workflow paths and sends POST-based ping requests to determine whether endpoints exist and respond. That behavior is operational monitoring, not the natural-language workflow triggering promised by the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-supplied contact and business information to external n8n webhooks with no explicit warning, confirmation, or visibility into where the data is going. While outbound transmission is the purpose of the tool, the lack of disclosure and confirmation increases the chance of accidental data leakage, especially when handling emails, CRM notes, invoice details, and meeting follow-up content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The markdown instructs users to trigger a workflow with an email address and a named user record, which could affect external systems or leak personal data if replaced with real information. There is no warning to use non-production recipients, sandbox accounts, or synthetic test data when validating the automation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes triggering n8n workflows for lead nurturing, email sequences, CRM updates, social posting, meeting follow-ups, competitor monitoring, and invoice reminders. This file also exposes content repurposing and daily business briefing workflows, which are separate capabilities not reflected in the manifest description and broaden the apparent skill scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.