n8n
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell-based commands (specifically
curl) to communicate with the n8n REST API. These commands are used for standard operational tasks such as creating, updating, activating, and deleting workflows, as well as inspecting execution logs. - [EXTERNAL_DOWNLOADS]: The documentation references the
n8n-mcpserver (available at github.com/czlonkowski/n8n-mcp), which is the recognized community standard for connecting n8n instances to Model Context Protocol clients. The skill provides instructions for running this tool vianpxor Docker to facilitate agent-based workflow management. - [PROMPT_INJECTION]: As the skill is designed to ingest and execute workflow designs in JSON format, it possesses a surface for indirect prompt injection if the source of those designs is not properly vetted. The skill addresses this by providing specific validation and sanitization steps.
- Ingestion points: Workflow JSON payloads processed by the
POST /workflowsendpoint or provided as arguments to then8n_create_workflowMCP tool. - Boundary markers: The instructions explicitly recommend performing validation (using
n8n_validate_workflow) prior to any creation or update operation. - Capability inventory: The skill facilitates full CRUD (Create, Read, Update, Delete) operations on workflows and management of execution data through the API and MCP tools.
- Sanitization: The skill identifies
n8n_autofix_workflowas a mechanism to repair and sanitize structural errors within workflow JSON before deployment. - [SAFE]: The skill demonstrates a strong security posture by advising against hardcoding credentials, encouraging the use of least-privilege API scopes, and recommending the
DISABLED_TOOLSenvironment variable to prevent unauthorized destructive actions in agent-facing environments.
Audit Metadata