n8n
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core REST capability is coherent and mostly benign for the stated purpose, but the skill also steers users toward a third-party MCP server that would receive the n8n API key, and it enables high-impact live actions such as activation, execution, and hard delete. Data flows otherwise match official n8n API usage, so this is not confirmed malware, but it carries medium security risk due to credential forwarding and autonomous operational side effects.
Confidence: 87%Severity: 61%
Audit Metadata