n8n-workflow-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional documentation and architectural patterns for n8n workflows. It does not include any malicious code, obfuscated content, or instructions designed to bypass security filters.\n- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for processing external data via webhooks and APIs, which inherentely creates a surface for indirect prompt injection. However, the documentation includes specific warnings and mitigation strategies, such as human-in-the-loop review and read-only access scopes, to address these risks.\n- [COMMAND_EXECUTION]: The documentation provides examples of using JavaScript child_process within n8n Code nodes for legitimate administrative tasks like database backups (e.g., pg_dump). These are presented as educational examples for users and do not represent a threat within the context of the AI agent skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:12 PM
Security Audit — agent-trust-hub — n8n-workflow-patterns