Back to skill

Security audit

n8n工作流自动化

Security checks across malware telemetry and agentic risk

Overview

This is a simple text-only skill for generating n8n workflow JSON, with no code execution, install hooks, credential access, or persistence shown in the artifacts.

This appears safe to install as a workflow-generation helper. Review any generated n8n JSON before importing or running it, especially workflows that use credentials, external APIs, triggers, deletion, posting, or business-system actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger condition is defined as any message containing the skill name or a related instruction, which is overly broad and can cause accidental or unintended activation. In an automation skill that generates production-grade n8n workflows, ambiguous triggering increases the risk of unauthorized workflow generation, prompt confusion, or misuse in contexts where the user did not explicitly intend to invoke this capability.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.