n8n

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely aligned with its stated n8n automation purpose and does not use suspicious installers or third-party credential gateways. However, it instructs the agent to read raw secrets from .env on load, forwards the API key to a fully user-configurable endpoint, requires an unconstrained credentials-template URL, and enables autonomous workflow activation/webhook execution with real-world effects. These are proportionate to advanced automation, but the trust boundaries are weak enough to warrant a suspicious classification rather than benign.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 03:09 AM
Package URL
pkg:socket/skills-sh/naveedharri%2Fbenai-skills%2Fn8n%2F@2d732dabf12319338853b594fa08c931a5fcd68f