n8n-workflow

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell commands for Proxmox LXC management and service administration (e.g., pct exec 104 -- systemctl restart n8n, systemctl restart cloudflared). These are provided as instructional documentation for maintaining the user's specific n8n instance and Cloudflare Tunnel.
  • [EXTERNAL_DOWNLOADS]: The instructions reference several well-known and trusted external API services (Anthropic, CoinGecko, Alpaca, Reddit) for use in automation workflows. These are standard integrations and do not involve untrusted remote code execution.
  • [DATA_EXFILTRATION]: The skill follows security best practices by instructing the agent to use the n8n credential store rather than hardcoding secrets. It identifies credential fields (e.g., x-api-key, client_secret) without exposing actual values.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for processing external data such as RSS feeds and API responses. While this creates an attack surface common to automation tools, the skill includes guidelines for data normalization and error handling to mitigate risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 01:07 AM
Security Audit — agent-trust-hub — n8n-workflow