n8n

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core n8n guidance is coherent, but the skill disproportionately promotes ColdIQ and asks users to run an unpinned npm MCP package with an API key. The endpoints appear same-org and purpose-aligned, so this is not confirmed malware, but it does introduce moderate supply-chain and credential-forwarding risk beyond a normal documentation skill.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Sep 2, 2026, 08:56 AM
Package URL
pkg:socket/skills-sh/cold-iq%2Fcoldiq-s-gtm-skills%2Fn8n%2F@f1e2c696d34c1a36193245aa6dba60d1f94afe1fc80005bdbd7bd1eff43ff254
Security Audit — socket — n8n