skills/delorenj/skills/n8n/Gen Agent Trust Hub

n8n

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of documentation and code snippets intended for use within the n8n platform. It provides high-quality guidance on building and operating automated workflows.
  • [INDIRECT_PROMPT_INJECTION]: The documentation includes a dedicated section on the risk of indirect prompt injection when building AI agents. It provides appropriate remediation strategies, such as using read-only database users, implementing human-in-the-loop gates for destructive actions, and constraining system prompts to ignore instructions within fetched content.
  • [DATA_EXFILTRATION]: No evidence of data exfiltration or credential harvesting was found. The skill actively discourages hardcoding secrets and provides instructions on using the platform's native credential system to reference API keys and tokens securely.
  • [COMMAND_EXECUTION]: The skill documents legitimate uses of command execution for tasks like database backups (e.g., pg_dump). These examples are provided in a purely educational context and are not used to perform unauthorized operations.
  • [OBFUSCATION]: No malicious obfuscation was detected. Standard encoding techniques like Base64 and Hex are mentioned only within the context of routine data processing tasks (e.g., decoding workflow JSON or formatting Basic Auth headers).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — n8n