cli-anything-n8n

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the cli-anything-n8n package from the Python Package Index (PyPI). This package is a functional component provided by the author for n8n platform interaction.\n- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external n8n instances to manage workflows and credentials, which presents a surface for indirect prompt injection.\n
  • Ingestion points: Untrusted data can enter the agent context through commands like workflow list, execution get, and tag list which retrieve content from an external n8n API (SKILL.md).\n
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the data returned by the API.\n
  • Capability inventory: The CLI tool provides significant capabilities, including the ability to create, update, and delete workflows, credentials, and variables (workflow create/update/delete, credential create/delete).\n
  • Sanitization: There is no documentation of sanitization or validation of the data retrieved from external sources before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:21 PM
Security Audit — agent-trust-hub — cli-anything-n8n