Back to skill

Security audit

n8n Task Router

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent n8n routing guide, but it exposes a concrete credential-vault locator and directs users toward unaudited local automation setup that can create persistent workflows.

Review this before installing in a shared or broadly privileged agent environment. Replace the concrete 1Password credential locator with a generic configuration reference, verify the external n8n start script separately, use a least-privilege n8n API key, and require explicit user approval before resolving secrets or activating workflows.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:91
Finding

Exposure of Internal Credential-Vault Reference and Automation Service Details

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- Weekly competitive intel run → **~$10–20/month saved**
  - Recurring "check X, send Y" tasks → **97% cheaper in n8n**

> **Note:** Social publishing (LinkedIn, X) uses Buffer (`skills/buffer-publisher/SKILL.md`). Typefully cancelled 2026-03-25.

If a task runs daily and takes no reasoning, it should be in n8n. Full stop.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file documents sensitive operational details, including localhost service location and a credential reference, without any warning to avoid exposing, copying, or retrieving secrets. In an agent skill, this can normalize unsafe secret handling and encourage downstream agents or users to treat the referenced credential as part of normal task execution rather than protected material.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documentation includes a concrete secret locator for the n8n API key (op://.../credential) even though the skill’s stated purpose is only task-routing guidance. Exposing the existence and exact storage path of a credential lowers the effort required for an attacker or over-privileged agent to target and retrieve that secret, and the routing context does not justify disclosing it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.