N8n 1.0.2

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward n8n API helper that can change or run workflows only through explicit user-directed commands.

Install only if you want an agent to interact with your n8n instance. Use the least-privileged n8n API key available, keep it out of shared shell environments, and manually review workflow IDs and payloads before activating, deactivating, executing, or deleting workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation encourages activation, deactivation, execution, and deletion actions without warning that these can trigger external side effects, interrupt business processes, or remove forensic history. In an automation platform, seemingly simple workflow actions may send messages, modify data, call third-party systems, or disrupt running operations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal