cli-anything-n8n
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
cli-anything-n8npackage from the Python Package Index (PyPI). This package is a functional component provided by the author for n8n platform interaction.\n- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external n8n instances to manage workflows and credentials, which presents a surface for indirect prompt injection.\n - Ingestion points: Untrusted data can enter the agent context through commands like
workflow list,execution get, andtag listwhich retrieve content from an external n8n API (SKILL.md).\n - Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the data returned by the API.\n
- Capability inventory: The CLI tool provides significant capabilities, including the ability to create, update, and delete workflows, credentials, and variables (
workflow create/update/delete,credential create/delete).\n - Sanitization: There is no documentation of sanitization or validation of the data retrieved from external sources before it is processed.
Audit Metadata