Back to skill

Security audit

N8n Integration

Security checks for vulnerabilities and agentic risk

Overview

This n8n integration is coherent but needs Review because its webhook server can trigger agents and send results plus its token to caller-supplied callback URLs.

Install only in a controlled local or private environment after setting strong unique secrets, replacing the documented default token, restricting callback URLs to trusted n8n endpoints, avoiding token forwarding to callbacks, and reviewing n8n API permissions before enabling workflow deletion or credential access.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
src/webhook-server.js:113
Finding

Caller-Controlled Callback URL Enables SSRF and Sensitive Data Exfiltration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/webhook-server.js:21
Finding

Publicly Documented Hard-Coded Default Authentication Token

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/webhook-handler.js:11
Finding

Secondary Webhook Handler Silently Disables Authentication

Content
View full analysis
{ try { const payload = JSON.parse(body); // Verify signature if secret is configured if (this.secret) { const signature = req.headers['x-n8n-signature']; if (!this.verifySignature(body, signature)) { res.writeHead(401); res.end('Invalid signature'); return; } } this.requestCount++; // Emit event for processing this.emit('webhook', { payload, headers: req.headers, timestamp: new Date().toISOString(), requestId: this.requestCount }); ``` The server is started without a host restriction: ```javascript this.server.listen(this.port, () => { console.log(`[Webhook] Server listening on port ${this.port}`); console.log(`[Webhook] Path: ${this.path}`); resolve(); }); ``` ### Technical Analysis Signature verification occurs only when `this.secret` has been configured. If neither `options.secret` nor `WEBHOOK_SECRET` exists, all POST requests to the configured path are accepted and emitted as trusted `webhook` events. The handler does not fail startup when authentication is absent. In addition, `server.listen(this.port)` does not explicitly bind to loopback, potentially exposing the listener on network interfaces available to the process. This behavior contradicts the documented security expectation that webhook requests are token-protected and creates a fail-open access-control boundary. ### Attack Path 1. An application imports and starts `WebhookHandler` wit ...[truncated 1244 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/webhook-handler.js:42
Finding

Unbounded Webhook Request Body Accumulation Enables Memory Exhaustion

Content
View full analysis
{ body += chunk.toString(); }); req.on('end', async () => { ``` ### Technical Analysis The raw HTTP webhook handler appends every received chunk to a JavaScript string without enforcing a maximum request size. Authentication is evaluated only after the complete body has been received and parsed. An unauthenticated remote client can therefore cause the process to allocate increasingly large strings. Multiple concurrent uploads can amplify memory pressure. A client may also transmit data slowly, retaining connections and associated resources for an extended period. The Express-based server uses the default JSON parser limit, but that protection does not apply to this separate raw HTTP implementation. ### Attack Path 1. The attacker connects to the `WebhookHandler` port. 2. The attacker sends a POST request to the configured webhook path. 3. The attacker streams a very large request body or opens multiple concurrent requests. 4. Each incoming chunk is converted to a string and appended to `body`. 5. The process continues allocating memory because no byte threshold is enforced. 6. Memory pressure causes garbage-collection overhead, service degradation, request failures, or process termination. ### Impact Assessment Exploitation can cause: - Increased process memory consumption. - Event-loop and garbage-collection degradation. - Denial of service for legitimate webhook requests. - Process termination due to out-of-memory conditions. - Broader service disruption when the Skill shares a process with other Agent components. No authentication is needed to consume the memory because signature validation occurs only after body collection. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/webhook-server.js:21
Finding

Configured Callback Timeout Is Not Enforced

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
node src/webhook-server.js

Known Vulnerable Dependency: path-to-regexp==0.1.12 — 1 advisory(ies): CVE-2024-45296 (path-to-regexp vulnerable to Regular Expression Denial of Service via multiple r)

High
Category
Supply Chain
Confidence
98% confidence
Finding

The lockfile includes path-to-regexp 0.1.12, which the advisory flags for Regular Expression Denial of Service. In an Express-based integration, route matching occurs on inbound requests, so a vulnerable route parser can make externally reachable endpoints susceptible to CPU exhaustion from crafted paths, making this materially relevant in context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file content consistently forces a specific language for skill documentation and instructions, and there is no indication that users may choose another language or that the skill is intentionally region-specific. Under SQP-3, a language/locale policy violation exists when a specific language is imposed without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown specifies a flow where n8n triggers a webhook, the agent executes using request parameters, and results are sent back via callback. For markdown files, SQP-2 applies when the description omits warnings about behaviors that could affect privacy or system integrity; here, data is sent over webhooks/HTTP with no caution about what data may be transmitted or exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly advertises automatic callbacks of agent execution results to a caller-supplied callback URL, but it does not warn users that results may be transmitted to arbitrary external endpoints. In an agent context, execution results can contain sensitive prompts, tool output, internal data, or user content, so this creates a real risk of unintended exfiltration or SSRF-like outbound delivery if callback destinations are not constrained.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

3. 触发 Agent

bash
curl -X POST http://localhost:3002/webhook/trigger \
  -H "Content-Type: application/json" \
  -H "X-N8N-Token: n8n-webhook-token" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The CRM example shows agent output being used to update external business records, but the skill does not warn that this integration can modify third-party or production data. That omission is risky because users may deploy the workflow without approval gates, validation, or human review, allowing incorrect or manipulated agent output to alter important records.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow exposes a POST webhook on a fixed path and immediately forwards attacker-controlled fields to an internal service without any visible authentication, origin restriction, input validation, or trigger constraints. In this context, the broad webhook is more dangerous because it acts as an unauthenticated entry point that can invoke downstream agent behavior and pass through arbitrary callback URLs and parameters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains natural-language content in comments and log messages exclusively in Chinese, such as the header description and startup/shutdown messages. Under the stated policy, forcing a specific language without user opt-in is a language/locale policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code exposes a destructive delete operation via deleteWorkflow() but provides no confirmation prompt, logging, or explicit warning beyond the brief method comment. For a code file, destructive or irreversible operations should have some visible disclosure unless the warning is documented elsewhere, which is not shown in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

listCredentials() retrieves credential-related data from the n8n API, which is a sensitive operation, but the file does not include any user-facing warning, logging, or explicit explanatory comment beyond the generic method label. The code also uses an API key from environment variables, reinforcing that this client handles sensitive access paths without disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code receives webhook payloads and headers and emits them for downstream processing, which is a network-driven data intake path that can include user or system data. While the file has brief developer comments, it lacks any explicit user-facing warning or disclosure about handling incoming webhook data or associated headers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The server accepts an arbitrary callbackUrl from the request body and then POSTs workflow/action/result data plus the shared X-N8N-Token to that destination. This creates an SSRF-style data exfiltration path and leaks the authentication token to attacker-controlled endpoints, which can enable further unauthorized requests to the service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The example HTTP Request node posts workflow JSON to http://localhost:3000/webhook/trigger, but the markdown does not warn readers that this is an insecure example if adapted beyond local development. In markdown guidance, networked behaviors that may affect privacy or system integrity should be accompanied by a caution when examples could be operationalized.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language policy violations include forcing a specific language without user opt-in. This file presents all instructional content in Chinese and does not indicate that the skill is region-specific or provide an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
31% confidence
Finding

The workflow emits a fixed English status/message structure, but this does not clearly amount to forcing a language policy on users. Because the file contains only minimal string literals and no explicit language requirement, this is at best a weak signal.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: body-parser==1.20.4 — 1 advisory(ies): CVE-2026-12590 (body-parser vulnerable to denial of service when invalid limit value silently di)

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The lockfile pins body-parser 1.20.4, and the provided advisory indicates a denial-of-service condition related to invalid limit handling. Even though this file is only dependency metadata and not exploit code, shipping a vulnerable parser in a server-side Express stack can expose request-processing paths to resource exhaustion or crashes if the application uses body parsing on attacker-controlled input.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.14.2 — 3 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-8723 (qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/u); CVE-2026-82562 (qs array-limit bypass via bracket-key comma parsing)

Low
Category
Supply Chain
Confidence
82% confidence
Finding

The qs package is present at 6.14.2 and the supplied advisories describe multiple denial-of-service and parser-bypass issues. Because qs is commonly used to parse attacker-controlled query strings and form bodies in Express applications, these flaws can be relevant if the application accepts untrusted request data, though the listed impacts are still primarily low-severity DoS or parsing edge cases.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency on Express is version-ranged with a caret (^4.18.2), which allows automatic installation of newer compatible releases rather than a single fixed version. This can introduce supply-chain risk and reduce build reproducibility, especially for an integration skill that may expose webhook-facing network functionality.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"author": "yuyonghao-123",
  "license": "MIT",
  "dependencies": {
    "express": "^4.18.2"
  },
  "engines": {
    "node": ">=18.0.0"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file's natural-language content, including the header documentation and runtime log messages, is written in Chinese only. Under the stated policy, forcing a specific language without user opt-in is a locale/language policy concern because the skill does not offer any alternative language choice or document a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's natural-language documentation and runtime log strings are written in Chinese, which effectively fixes the operator-facing language without any opt-in or locale selection. Under the policy, language constraints should either be optional, user-selectable, or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JavaScript file contains natural-language strings such as the header comment and console output in Chinese, which imposes a specific language on users or maintainers reading test output. The policy allows fixed locale only when justified or when users are given a choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/webhook-server.js:25

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/webhook-server.js:25