Back to skill

Security audit

n8n

Security checks for vulnerabilities and agentic risk

Overview

This n8n skill is mostly purpose-aligned, but its advertised dry-run/test path can trigger real workflows and its high-impact automation actions are under-safeguarded.

Review carefully before installing. Use only with a test or staging n8n instance first, set N8N_BASE_URL to a trusted HTTPS n8n host, use a least-privilege API key, and treat dry-run/test-suite/manual execution as live workflow execution that may affect external systems.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/n8n_tester.py:194
Finding

Misleading “Dry Run” Performs Real Workflow Execution

Content
View full analysis
Dict: """Execute workflow with test data""" # Load test data if from file if test_data_file: with open(test_data_file, 'r') as f: test_data = json.load(f) print(f"Running workflow {workflow_id} with test data...") # Execute workflow execution_result = self.client.execute_workflow(workflow_id, data=test_data) execution_id = execution_result.get('data', {}).get('executionId') ``` ```python # scripts/n8n_api.py:103-108 def execute_workflow(self, workflow_id: str, data: Dict = None) -> Dict: """Manually trigger workflow execution""" payload = {'workflowId': workflow_id} if data: payload['data'] = data return self._request('POST', f'workflows/{workflow_id}/execute', json=payload) ``` ### Technical Analysis The operation named `dry_run` does not implement simulation, mocking, transaction rollback, workflow cloning, node substitution, or staging-environment enforcement. It directly calls `execute_workflow`, which sends a real `POST` request to the n8n workflow execution endpoint. This behavior conflicts with documentation presenting the feature as “Dry-Run Testing” and recommending it for testing workflows before activation. A user can therefore reasonably assume that the operation is non-destructive when it actually executes every reachable workflow node. The risk is especially significant because n8n workflows commonly contain nodes that: - Send email or external notifications. - Create or update database records. - Invoke third-party HTTP APIs. - Modify CRM or spreadsheet data. - Initiate payment-related operations. ...[truncated 1819 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/n8n_api.py:18
Finding

Unvalidated Base URL Can Expose the n8n API Key

Content
View full analysis
Dict[str, Any]: """Make API request""" url = f"{self.base_url}/api/v1/{endpoint.lstrip('/')}" response = self.session.request(method, url, **kwargs) ``` ### Technical Analysis The client accepts `N8N_BASE_URL` without parsing or validating its scheme, hostname, port, or embedded user information. It then configures a persistent `requests.Session` to attach the privileged `X-N8N-API-KEY` header to requests constructed from that value. There is no control that: - Requires HTTPS for non-local connections. - Rejects an attacker-controlled hostname. - Warns before sending credentials over plaintext HTTP. - Restricts the destination to an approved n8n host. - Rejects malformed or unexpected URL components. - Confirms that the configured endpoint is actually an n8n service. Consequently, a configuration mistake or maliciously supplied environment variable can redirect the API key to an unintended server. If an `http://` URL is used, a network-positioned attacker may also observe or alter the request in transit. The code does not contain a hardcoded exfiltration endpoint. Exploitation requires influence over configuration or the transport path, but the lack of destination validation makes credential disclosure possib ...[truncated 1702 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly uses sensitive capabilities including environment variables, local file access, and network/API access, yet it declares no explicit permissions or guardrails. This weakens policy enforcement and user awareness, increasing the chance that the skill is invoked with broader authority than expected and that secrets or local files are accessed implicitly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented description frames the skill as management/debugging, but the content also enables creation, deletion, testing, optimization, and potentially destructive state changes. That mismatch is dangerous because users and orchestration layers may authorize or invoke the skill under a less risky mental model than its actual behavior, leading to unintended modification of live automation systems.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file advertises testing and 'dry-runs', but the implementation includes a path that actually triggers workflow execution through the n8n API. In the context of automation workflows, this can cause real side effects such as sending emails, mutating databases, calling third-party APIs, or triggering downstream systems when an operator expects a safe validation-only action.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The method name and CLI action label imply a non-executing dry run, yet the code calls self.client.execute_workflow(workflow_id, data=test_data), which performs a real execution. This mismatch is dangerous because users and higher-level agents may rely on the name to assume safety and inadvertently trigger production automations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README instructs users to activate and execute workflows but does not clearly warn that these actions can trigger live automations with real external side effects such as sending emails, posting messages, modifying records, or invoking third-party APIs. In an automation skill for n8n, this omission is more dangerous because execution is the core function and users may reasonably test commands against production-connected workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The README shows setting API credentials via environment variables without any warning about protecting secrets, avoiding shell history leakage, or using least-privilege tokens. While this is common practice, documentation that omits basic secret-handling guidance can contribute to accidental exposure through copied commands, logs, screenshots, or shared shell sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Activation and deactivation directly change live workflow state, but the documentation presents them as routine commands without a prominent warning about production impact. In an automation platform, toggling a workflow can stop business processes or unexpectedly enable downstream actions, so omission of caution increases operator error risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Manual execution examples encourage triggering workflows with arbitrary input but do not warn that executions may send emails, call third-party APIs, modify records, or incur costs. In this skill context, executing workflows is inherently capable of causing real-world side effects, making the omission materially risky.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
90% confidence
Finding

The client includes irreversible workflow deletion functionality with no confirmation, no soft-delete, and no safeguard against accidental or automated invocation. In an agent-skill context, destructive operations without explicit user acknowledgement can turn prompt mistakes or unintended tool use into immediate loss of automation assets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Execution deletion is destructive and can remove audit/debug history, yet the method provides no confirmation or retention safeguard. In operational environments, losing execution records can hinder incident response, troubleshooting, and forensic review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code triggers workflow execution over the network without any explicit warning, confirmation, or safeguard that the so-called dry-run may execute real actions against external systems. Given this skill manages n8n workflows and automations, the context increases risk because workflows commonly interact with sensitive infrastructure, credentials, SaaS APIs, and production data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.