n8n-architect

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is coherent with its stated purpose of n8n workflow engineering, and its file access, credential handling, and network actions mostly fit that role. The main risk is supply-chain trust: it tells the agent to execute third-party npm CLIs via `npx --yes`, giving downloaded code broad control over local files, credentials, and n8n operations. Overall this is suspicious from an install-trust and operational-risk perspective, but not malicious based on the provided content.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 17, 2026, 05:54 AM
Package URL
pkg:socket/skills-sh/EtienneLescot%2Fn8n-as-code%2Fn8n-architect%2F@679df78781bc799fd2af54f56cccffeb8388663b
Security Audit — socket — n8n-architect