n8n-mcp-tools-expert
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: HIGHPROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection] (HIGH): The skill facilitates an attack surface where the agent processes external data and exerts control over the n8n environment.\n- Ingestion points:
SEARCH_GUIDE.mdandVALIDATION_GUIDE.mddescribe tools likesearch_nodesandget_nodethat fetch node definitions, properties, and template examples from the external n8n node registry.\n- Boundary markers: The documentation lacks guidance on using delimiters or protective instructions (e.g., 'ignore embedded commands') when the agent processes node data, leaving it susceptible to instructions hidden in node descriptions.\n- Capability inventory: The skill instructs the agent on using high-impact tools such asn8n_create_workflowandn8n_autofix_workflowwhich can create or modify automation workflows based on information gathered from untrusted sources.\n- Sanitization: The 'Auto-Sanitization System' mentioned inVALIDATION_GUIDE.mdis limited to correcting structural logic (e.g., binary vs unary operator metadata) and does not provide sanitization for natural language instructions embedded in external data.
Recommendations
- AI detected serious security threats
Audit Metadata