Back to skill

Security audit

n8n Automation

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says, but it gives an agent commands that can change or delete n8n workflows without clear safety checks.

Install only if you are comfortable letting the agent use an n8n API key that may change or delete workflows. Use a least-privilege key where possible, prefer a test or non-production instance first, and require explicit confirmation plus a workflow export or backup before activation, deactivation, creation, deletion, or webhook-triggering actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

High
Confidence
87% confidence
Finding
The skill includes a direct workflow deletion command without any warning about irreversibility, backup, or confirmation. In a tool intended to manage production automations, this increases the likelihood of accidental destructive actions that could disrupt business processes or permanently remove workflow definitions.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.