Back to skill

Security audit

n8n Hub

Security checks across malware telemetry and agentic risk

Overview

This is a coherent n8n API helper, but it can affect live workflows and sensitive n8n tenant data if used with a powerful API key.

Install this only for agents you trust to operate your n8n instance. Use the least-privilege n8n API key available, prefer a test workspace for changes, and require explicit human confirmation before activation, deactivation, retries, deletes, credential changes, role changes, or project transfers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The file documents a much broader administrative API surface than the skill description suggests, including user, project, credential, variable, and data-table management. In an agent context, this capability expansion increases the chance that the skill is used to perform unintended tenant-wide administrative or destructive actions beyond workflow planning and lifecycle tasks.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documentation includes user enumeration, creation, deletion, and role-change operations even though the skill is described primarily as a workflow hub. In an LLM-driven or semi-automated environment, exposing identity and privilege-management actions without strong scoping can enable unauthorized account changes, privilege escalation, or tenant takeover if invoked improperly.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Credential creation, modification, deletion, and transfer are highly sensitive operations because they directly affect stored secrets and access paths to external systems. In an agent setting, documenting and normalizing these actions without restrictive guardrails can lead to secret replacement, exfiltration pathways, service disruption, or cross-project movement of privileged credentials.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Project creation, deletion, and membership/role changes materially affect authorization boundaries and ownership within the n8n tenant. When bundled into a broadly described operational skill, these capabilities can be misused to add users, alter access, or remove project ownership structures, causing privilege abuse or loss of control.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documents multiple state-changing API operations such as activate, deactivate, webhook triggering, and execution retry, but does not clearly warn that these actions can modify production workflow state or re-run automations with real side effects. In an agent skill context, this increases the chance that an automated agent or user invokes impactful operations without explicit confirmation, potentially causing outages, duplicate processing, or unintended downstream actions.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The markdown lists numerous destructive and sensitive operations such as deleting users, workflows, credentials, projects, variables, data rows, and retrying executions, but provides no user-facing warnings, approval guidance, or safety constraints. In an agent-assisted workflow, this omission makes accidental or unsafe invocation more likely and obscures the potential data-loss, privilege, and service-impact consequences.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.