n8n-hebrew-workflows

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security threats detected across any analyzed category.
  • [PROMPT_INJECTION]: Instructions are informative and technical. No attempts to override agent behavior, bypass safety filters, or extract system prompts were found.
  • [DATA_EXFILTRATION]: The skill references several legitimate Israeli business and government APIs (Morning, Hebcal, data.gov.il, various payment and SMS gateways). It correctly advises users to store sensitive credentials in environment variables or n8n's native credential store rather than hardcoding them.
  • [COMMAND_EXECUTION]: Code snippets use n8n's standard Code nodes and discuss the Execute Command node in the context of automation. These are used for their intended purpose (e.g., bank scraping, text formatting) and do not include malicious payloads.
  • [REMOTE_CODE_EXECUTION]: Recommends the installation of israeli-bank-scrapers and its maintained fork, which are standard community libraries for the described use case. No dangerous shell piping (e.g., curl|bash) or unverified script downloads were detected.
  • [OBFUSCATION]: Content is written in plain text (English and Hebrew). A reference to the UTF-8 Byte Order Mark (\uFEFF) is present in the troubleshooting section, which is a legitimate technical solution for CSV encoding issues.
  • [INDIRECT_PROMPT_INJECTION]: While the workflows described process external data, the skill provides templates for validation and boundary checking. As a documentation-focused skill, it does not create a direct vulnerability surface.
  • [PRIVILEGE_ESCALATION]: No usage of sudo, chmod, or other privilege escalation techniques were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 06:38 AM
Security Audit — agent-trust-hub — n8n-hebrew-workflows