n8n-architect
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
This skill is coherent with its stated purpose of n8n workflow engineering, and its file access, credential handling, and network actions mostly fit that role. The main risk is supply-chain trust: it tells the agent to execute third-party npm CLIs via `npx --yes`, giving downloaded code broad control over local files, credentials, and n8n operations. Overall this is suspicious from an install-trust and operational-risk perspective, but not malicious based on the provided content.
Confidence: 84%Severity: 62%
Audit Metadata