n8n-workflow-patterns

Warn

Audited by Snyk on Mar 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill documentation (SKILL.md) explicitly instructs workflows to use Webhook and HTTP Request nodes (see "Webhook Processing", "HTTP API Integration", and examples like "Fetch GitHub issues" and the AI Assistant example referencing HTTP Request Tool and webhooks), which fetch and ingest public/third-party API and user-submitted content that the agent is expected to read and act on; this clearly exposes the agent to untrusted third‑party content (see webhook_processing.md and http_api_integration.md references).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 8, 2026, 02:53 PM
Security Audit — snyk — n8n-workflow-patterns