n8n

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The direct n8n API usage is purpose-aligned and mostly benign, but the optional MCP integration materially increases risk: it auto-executes an unpinned third-party package from a personal publisher and hands it a potentially full-access n8n API key. Not confirmed malware, but the credential-forwarding and supply-chain posture are disproportionate enough to warrant caution.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/phuetz%2Fcode-buddy%2Fn8n%2F@df6f78cf02b133e4f8b18144030d77ff64210a2d