n8n-skills
Fail
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: A hardcoded Freepik API key was found in the configuration of the 'Freepik API' node within the Auto Service content generation template.
- Evidence: File 'resources/templates/ai-chatbots/4600--ai-content-generation-for-auto-service-automate-your-social.md' contains 'x-freepik-api-key' with value 'FPSX38a53a81a693e71a0e9437a657de6342'.
- Impact: Exposure of API keys can lead to unauthorized service usage, potential billing exploitation, and data access risks.
- [INDIRECT_PROMPT_INJECTION]: Multiple workflow templates are designed to ingest untrusted data from external services and feed it directly into AI Agents with significant tool-access capabilities.
- Ingestion points: templates/ai-chatbots/4557 (Gmail), 4722 (Gmail), 4827 (WhatsApp), 5449 (Web Scraping).
- Boundary markers: None observed; untrusted content is directly interpolated into agent system prompts using standard n8n template syntax (e.g., {{ $json.text }}).
- Capability inventory: The affected templates connect AI Agents to powerful tools like Gmail (read/send), WhatsApp (send), and database operations (read/write).
- Sanitization: There is no implementation of input filtering or instruction-guarding delimiters to prevent data-embedded commands from influencing the agent's behavior.
Recommendations
- AI detected serious security threats
Audit Metadata