T09 · Insecure Skill Coding Practices
- Location
scripts/n8n_tester.py:194- Finding
Misleading “Dry Run” Performs Real Workflow Execution
- Content
View full analysis
Dict: """Execute workflow with test data""" # Load test data if from file if test_data_file: with open(test_data_file, 'r') as f: test_data = json.load(f) print(f"Running workflow {workflow_id} with test data...") # Execute workflow execution_result = self.client.execute_workflow(workflow_id, data=test_data) execution_id = execution_result.get('data', {}).get('executionId') ``` ```python # scripts/n8n_api.py:103-108 def execute_workflow(self, workflow_id: str, data: Dict = None) -> Dict: """Manually trigger workflow execution""" payload = {'workflowId': workflow_id} if data: payload['data'] = data return self._request('POST', f'workflows/{workflow_id}/execute', json=payload) ``` ### Technical Analysis The operation named `dry_run` does not implement simulation, mocking, transaction rollback, workflow cloning, node substitution, or staging-environment enforcement. It directly calls `execute_workflow`, which sends a real `POST` request to the n8n workflow execution endpoint. This behavior conflicts with documentation presenting the feature as “Dry-Run Testing” and recommending it for testing workflows before activation. A user can therefore reasonably assume that the operation is non-destructive when it actually executes every reachable workflow node. The risk is especially significant because n8n workflows commonly contain nodes that: - Send email or external notifications. - Create or update database records. - Invoke third-party HTTP APIs. - Modify CRM or spreadsheet data. - Initiate payment-related operations. ...[truncated 1819 chars]- Remediation
View remediation
