n8n-workflow-weapon

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill provides a comprehensive and security-conscious framework for n8n workflow management. It establishes 'Six Critical Directives' that include explicit instructions for protecting credentials, ensuring workflows are correctly published, and validating configurations against official schemas before deployment.
  • [COMMAND_EXECUTION]: The toolkit utilizes instance-native n8n MCP server tools to interact with the n8n environment. These tools include validate_workflow, create_workflow_from_code, and publish_workflow, which are standard operations for automating workflow lifecycle management on the platform.
  • [EXTERNAL_DOWNLOADS]: The research section references official n8n documentation (docs.n8n.io) and public GitHub repositories (n8n-io/n8n). These are well-known technology services, and the skill uses them strictly for documentation and research context, following established safety protocols.
  • [CREDENTIALS_UNSAFE]: The skill explicitly warns against hardcoding secrets and mandates the use of newCredential() references. It identifies that the n8n API omits node credentials to prevent exposure and instructs the user to verify bindings via the UI or test runs rather than attempting to read secrets through the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 03:22 AM
Security Audit — agent-trust-hub — n8n-workflow-weapon