Back to skill

Security audit

N8n Operator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches n8n administration, but it also tells agents to create persistent local scheduled jobs and use high-impact live operations without enough safeguards.

Review carefully before installing. Use this only with an n8n instance and API key you are comfortable letting the agent administer, prefer HTTPS or loopback-only HTTP, require explicit confirmation before create/update/delete/activate/deactivate/execute actions, avoid the direct OpenClaw jobs.json cron approach, and do not use the root Desktop bind-mount example on sensitive host data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T06 · System Persistence

Error
Location
SKILL.md:287
Finding

Persistent Scheduled Webhook Execution Through Direct OpenClaw Cron Modification

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/desktop-write.md:15
Finding

Root n8n Container Receives Writable Access to the Host Desktop

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/n8n_tester.py:193
Finding

Purported Dry Run Executes the Live Workflow and Its Side Effects

Content
View full analysis
Dict: """Execute workflow with test data""" # Load test data if from file if test_data_file: with open(test_data_file, 'r') as f: test_data = json.load(f) print(f"Running workflow {workflow_id} with test data...") # Execute workflow execution_result = self.client.execute_workflow(workflow_id, data=test_data) execution_id = execution_result.get('data', {}).get('executionId') if not execution_id: return { 'status': 'failed', 'error': 'No execution ID returned', 'result': execution_result } print(f"Execution started: {execution_id}") print("Waiting for execution to complete...") max_attempts = 30 attempt = 0 while attempt < max_attempts: time.sleep(2) attempt += 1 try: execution = self.client.get_execution(execution_id) finished = execution.get('finished', False) if finished: success = execution.get('data', {}).get( 'resultData', {} ).get('error') is None return { 'status': 'success' if success else 'failed', 'execution_id': execution_id, 'finished': True, 'started_at': execution.get('startedAt'), 'stopped_at': execution.get('stoppedAt'), 'mode': execution.get('mode'), 'data': execution.get('data', {}) } except Exception as e: print(f"Error checking execution status: { ...[truncated 2170 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/n8n_api.py:19
Finding

Administrative n8n API Key Can Be Sent Over Unencrypted HTTP

Content
View full analysis
Dict[str, Any]: """Make API request""" url = f"{self.base_url}/api/v1/{endpoint.lstrip('/')}" response = self.session.request(method, url, **kwargs) ``` The documented configuration permits HTTP: ```text N8N_BASE_URL=http://localhost:5678 N8N_API_KEY= ``` ### Technical Analysis The client attaches `X-N8N-API-KEY` to every request made through its session. It does not validate that `base_url` uses HTTPS, nor does it restrict plaintext HTTP to loopback destinations. The documented loopback example is normally confined to the local host, but users can configure `N8N_BASE_URL` to a remote HTTP address. In that case, the API key and response data traverse the network without transport encryption. The client also lacks a request timeout. This is primarily an availability issue, but it makes unsafe or unreachable destinations capable of indefinitely blocking operations. ### Attack Path 1. The client is configured with a remote `http://` n8n base URL. 2. The API key is loaded from `N8N_API_KEY`. 3. The client automatically adds the key to `X-N8N-API-KEY`. 4. A workflow-management request is sent over plaintext HTTP. 5. A network-positioned attacker ca ...[truncated 623 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/node-templates.md:436
Finding

Generic HTTP Template Sends the Entire Input Record to an External API

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/workflow-patterns.md:589
Finding

Batch Notification Template Discloses User Email Addresses to Slack

Content
View full analysis
({ json: u }));" }, "id": "code-001", "name": "Generate User List", "type": "n8n-nodes-base.code", "typeVersion": 2, "position": [470, 300] }, { "parameters": { "jsCode": "const users = $input.all();\nreturn [{ json: { batch: users.map(u => u.json.email).join(', '), count: users.length } }];" }, "id": "code-002", "name": "Format Batch", "type": "n8n-nodes-base.code", "typeVersion": 2, "position": [910, 300] }, { "parameters": { "channel": "#notifications", "text": "={{ 'Sending notification to: ' + $json.batch + ' (' + $json.count + ' users)' }}" }, "id": "slack-001", "name": "Send Batch Notification", "type": "n8n-nodes-base.slack", "typeVersion": 2.2, "position": [1130, 300], "credentials": { "slackApi": { "id": "CREDENTIAL_ID", "name": "Slack" } } } ``` ### Technical Analysis The example collects all user email addresses in the current batch, concatenates them into a single string, and posts that string to a Slack channel. Email addresses are personal identifiers and are not needed to report only batch-processing status. The example uses placeholder addresses, so the repository itself does not contain real personal data. The vulnerability arises when the pattern is adapted to real workflow inputs, as the template explicitly encourages. Slack is an external service, and channel members ...[truncated 1034 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The stated purpose is REST-based n8n workflow management, but the document also instructs performance analysis, reporting, local cron/job-file editing, and use of separate CLI/Python utilities. This mismatch weakens user consent and reviewability because the skill can induce actions outside the expected n8n-management scope, including local system changes and broader operational analysis.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The auto-activation criteria are extremely broad, including essentially any n8n-related request or automation-design discussion. Overbroad triggering raises the chance the skill is invoked in contexts where the user only wanted advice, causing unintended access to credentials, workflow mutation, execution, or deletion.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 515)May include surrounding context.

md
python3 scripts/n8n_api.py list-workflows --active true --pretty

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 516)May include surrounding context.

md
python3 scripts/n8n_api.py list-workflows --active true --pretty

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/references/api.md (reported line 55)May include surrounding context.

删除工作流

text
DELETE /workflows/{id}

执行记录(Executions)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/references/api.md (reported line 72)May include surrounding context.

删除执行记录

text
DELETE /executions/{id}

重试执行

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to environment variables and documents file/network operations, but does not constrain its tool scope with explicit permissions or allowed-tools. In practice this can let an agent apply broader capabilities than users expect, including reading secrets like N8N_API_KEY and making outbound or local-file modifications without a clearly bounded contract.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description is written to operate in Chinese and does not indicate that the user may choose another language or locale. Per the policy, forcing a specific language without opt-in is a natural-language policy issue unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill documents destructive operations like delete, activate/deactivate, execute, and local file modification without prominent risk warnings or confirmation requirements. In an agent setting, missing safeguards make accidental service disruption, workflow loss, or persistent local changes more likely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

| 详情 | GET | /executions/{id} | | 重试 | POST | /executions/{id}/retry |

常用 curl 示例

bash
# 列出所有工作流

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to edit a local OpenClaw cron jobs.json file to trigger webhooks, which extends from remote n8n administration into local persistence and scheduled execution. This is dangerous because it creates durable system behavior outside the declared REST API boundary and could be used to establish unauthorized recurring network activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document explicitly instructs writing files to the user's Windows Desktop, which is a user-owned, high-visibility location, without any warning, confirmation, or guidance about the risks of modifying local files. In the context of an agent skill that can design and manage workflows, this lowers the barrier to creating automations that overwrite or drop files onto the host desktop, increasing the chance of unintended data modification or abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file includes ready-to-copy templates for Slack, email, Telegram, WeChat Work, DingTalk, and generic HTTP Request nodes that send {{$json...}} data to external services. The surrounding documentation explains configuration details but does not warn users that workflow data may be transmitted to third parties or that credentials and recipient targets should be reviewed before use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document provides templates for MySQL/PostgreSQL/Redis/MongoDB and file read/write operations, including references to update/delete-capable database nodes and filesystem access. While these are example templates, the markdown does not warn that such nodes can alter stored data or access local files and should be used only with reviewed paths, queries, and permissions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/references/api.md (reported line 104)May include surrounding context.

列出已激活的工作流

bash
curl -s -H "X-N8N-API-KEY: $N8N_API_KEY" \
  "$N8N_BASE_URL/api/v1/workflows?active=true&limit=50"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document provides ready-to-use workflow examples that perform outbound HTTP requests, send Slack messages, read/write databases, and instruct activation of workflows, but it does not consistently warn users about data egress, side effects, credential scope, or production impact. In an agent skill context, these examples can be operationalized directly, increasing the chance that sensitive data is transmitted or systems are modified without explicit user awareness or confirmation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/node-templates.md (reported line 441)May include surrounding context.

md
},
    {
      "parameters": {
        "url": "https://api.example.com/orders?updated_after={{ $now.minus({days: 1}).toISO() }}",
        "method": "GET",
        "options": { "response": { "response": { "responseFormat": "json" } } }
      },

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflow-patterns.md (reported line 183)May include surrounding context.

md
},
    {
      "parameters": {
        "url": "https://api.example.com/orders?updated_after={{ $now.minus({days: 1}).toISO() }}",
        "method": "GET",
        "options": { "response": { "response": { "responseFormat": "json" } } }
      },

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflow-patterns.md (reported line 493)May include surrounding context.

md
},
    {
      "parameters": {
        "url": "https://api.example.com/orders?updated_after={{ $now.minus({days: 1}).toISO() }}",
        "method": "GET",
        "options": { "response": { "response": { "responseFormat": "json" } } }
      },

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring explicitly states it manages "workflows, executions, and credentials via n8n REST API," which expands the apparent scope beyond the manifest's description of a workflow assistant. Credential management is materially more sensitive than ordinary workflow CRUD and is not mentioned in the stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code creates workflows via a POST request to the n8n API, which changes remote system state, but this path has no confirmation prompt or user-facing disclosure at the call site. While the method docstring names the action, the CLI flow provides no explicit warning before creating resources from a file or template.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

These methods activate or deactivate workflows in the remote n8n environment, which can materially affect automation behavior, but there is no confirmation prompt, logging, or user-facing warning when the CLI invokes them. The docstrings are internal developer documentation and do not provide runtime disclosure to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The execute_workflow method POSTs workflow input data to the n8n API, which may transmit user or system data, but there is no visible disclosure or warning in the code path that this data will be sent over the network. The CLI accepts arbitrary JSON via --data and immediately transmits it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The dry-run path forwards user-supplied test data directly to the remote n8n service via execute_workflow without any explicit user-facing warning, confirmation, or redaction step. In a workflow-testing tool, operators may assume local validation semantics, but this function can transmit secrets, personal data, or internal payloads to a live service and potentially trigger downstream workflow actions during testing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest frames the skill as an n8n operator for workflow lifecycle management. The WeChat API limits and access-token handling guidance describe domain-specific third-party API behavior, which is not necessary to justify the core capability of managing n8n workflows and suggests unrelated operational specialization.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.