Back to skill

Security audit

n8n ops

Security checks for vulnerabilities and agentic risk

Overview

This n8n automation skill is coherent, but it gives an agent broad workflow-control powers and includes under-scoped templates that can run workflows, send data externally, and share AI memory by default.

Install only with a dedicated, least-privilege n8n API key and prefer a staging n8n instance first. Before letting the skill run, delete, activate, or test workflows, confirm the exact workflow ID and expected side effects. Review templates before deployment, especially any OpenAI, Slack, webhook, HTTP Request, credential, or memory nodes; replace the shared `default` memory fallback with authenticated per-user session keys and avoid sending sensitive webhook payloads to third-party services unless intended.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
templates.md:102
Finding

Shared AI Memory Fallback Enables Cross-User Context Leakage

Content
View full analysis

Vulnerability Details

File Location: templates.md, line 102
Vulnerability Type: Shared memory namespace caused by an insecure default session key
Risk Level: Medium

Complete Code Snippet:

json
{
  "id": "4", "name": "Memory", "type": "@n8n/n8n-nodes-langchain.memoryBufferWindow", "typeVersion": 1,
  "position": [550, 550],
  "parameters": {
    "sessionIdType": "customKey",
    "sessionKey": "={{ $json.body.sessionId ?? 'default' }}",
    "contextWindowLength": 20
  }
}

Technical Analysis

The AI-agent workflow template uses a client-supplied sessionId as its memory key and substitutes the constant value default when that field is absent. Consequently, every webhook request that omits sessionId is assigned to the same memory namespace.

In a multi-user deployment, the buffer-window memory may place messages from unrelated users into one shared conversation. The template also does not demonstrate authentication, authorization, tenant binding, or server-side session-ID generation. Even when a session ID is supplied, accepting it directly from the request allows a caller to attempt session-key reuse or guessing.

This is an insecure coding/configuration practice rather than deliberate persistent agent-memory poisoning. The affected memory is workflow conversation state, and the audited material does not establish that it modifies the Skill's own long-term instructions.

Attack Path

  1. An operator deploys the documented AI-agent webhook template without replacing the fallback behavior.
  2. An attacker sends requests to the webhook while omitting body.sessionId.
  3. The workflow stores the attacker's messages under the shared default memory key.
  4. A victim also sends a request without a session ID and is assigned the same key.
  5. The AI agent receives conversation context containing messages from both callers.
  6. The victim may receive information derived from the att ...[truncated 853 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the global fallback and reject requests without a valid authenticated session identity:

    javascript
    ={{ (() => {
      if (!$json.authenticatedUserId || !$json.body.sessionId) {
        throw new Error('Authenticated user and session ID are required');
      }
      return `${$json.authenticatedUserId}:${$json.body.sessionId}`;
    })() }}
    
  2. Derive the memory key from trusted server-side authentication context rather than accepting identity solely from the webhook body.

  3. Bind the key to both tenant/user identity and a high-entropy session identifier.

  4. Validate the identifier's format and length, and prevent callers from selecting another user's namespace.

  5. Add webhook authentication and authorization before invoking the AI agent or memory node.

  6. Define retention limits and clear memory when sessions expire.

  7. Avoid placing credentials or unnecessary sensitive data in conversational memory.

  8. Add tests proving that requests from different users, including requests with missing or reused IDs, cannot read or influence one another's memory.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- **Create** workflows from natural language descriptions via `POST /api/v1/workflows`
- **Read & analyze** existing workflows via `GET /api/v1/workflows/:id`
- **Update** workflow nodes, connections, parameters via `PUT /api/v1/workflows/:id`
- **Delete** workflows (always confirm first) via `DELETE /api/v1/workflows/:id`
- **Activate/Deactivate** workflows via `POST /api/v1/workflows/:id/activate|deactivate`

### Execution Monitoring

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

A DELETE endpoint that accepts a workflow ID is inherently high risk for tool-parameter abuse when exposed through an autonomous agent. If an attacker can influence the ID selection or prompt the agent into acting on the wrong resource, they can delete arbitrary workflows, disrupting automation and potentially causing significant operational downtime.

Content

Scanner excerpt · api-reference.md (reported line 61)May include surrounding context.

Delete Workflow

text
DELETE /api/v1/workflows/:id

Activate Workflow

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

The execution deletion endpoint can be abused through attacker-controlled or mistaken parameters to erase selected execution records. Although less severe than deleting workflows, it can still remove evidence, impair debugging, and hide traces of misuse or failure.

Content

Scanner excerpt · api-reference.md (reported line 109)May include surrounding context.

Delete Execution

text
DELETE /api/v1/executions/:id

Run Workflow

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The AI agent template forwards webhook-supplied message content to OpenAI and persists conversation state via memory, but provides no warning or safeguards around handling sensitive user input. In an automation skill focused on creating deployable workflows, this is dangerous because users may expose confidential webhook data to third-party LLM providers and unintentionally retain it across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to send test payloads to webhook endpoints but does not require a warning, consent checkpoint, or data-safety guidance before transmitting sample or user-provided content. In this context, webhook tests can send sensitive data to external systems or trigger side effects, so the omission creates a real risk of unintended disclosure or actions during testing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api-reference.md (reported line 7)May include surrounding context.

All requests require the X-N8N-API-KEY header:

bash
curl -H "X-N8N-API-KEY: YOUR_API_KEY" http://localhost:5678/api/v1/...

Generate an API key: n8n Settings > API > Create API Key

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation exposes a destructive workflow deletion endpoint with no warning, confirmation guidance, or scope limitations. In the context of an autonomous workflow-management agent, this increases the chance that the agent or a user prompt could trigger irreversible deletion of production automations, causing outage or loss of workflow definitions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The execution deletion endpoint is documented without caution that it permanently removes execution history and forensic/debugging data. For an operations agent focused on monitoring and debugging, silent deletion can hinder incident response, auditing, and root-cause analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manual run endpoint is presented as routine usage without warning that invoking a workflow can execute arbitrary downstream actions such as external API calls, data modification, messaging, or credential-backed operations. In this skill's context, natural-language-driven automation makes accidental or prompt-induced triggering especially risky because inactive workflows can still be run via API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes a workflow template that fetches data from an external API and posts processed results to Slack, which can transmit user or system data to third-party services. The surrounding description presents these as ready-to-use templates but does not include any warning about privacy, external data sharing, or the need to review what data is being sent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · templates.md (reported line 43)May include surrounding context.

md
{
      "id": "2", "name": "Fetch Data", "type": "n8n-nodes-base.httpRequest", "typeVersion": 4,
      "position": [500, 300],
      "parameters": { "method": "GET", "url": "https://api.example.com/status", "options": {} }
    },
    {
      "id": "3", "name": "Process", "type": "n8n-nodes-base.code", "typeVersion": 2,

Static analysis

No suspicious patterns detected.