n8n-mcp-orchestrator
Pass
Audited by Gen Agent Trust Hub on Feb 15, 2026
Risk Level: LOWNO_CODE
Full Analysis
- NO_CODE (LOW): The analyzed file (SUMMARY.txt) is a content breakdown and quality report rather than a functional skill file. It does not contain instructions or code for an agent to execute.
- PROMPT_INJECTION (INFO): Surface analysis of the described architecture reveals a significant indirect prompt injection attack surface (Category 8). Evidence Chain: 1. Ingestion points: 'Email Sender', 'Support Ticket Creation', and 'Knowledge Base Search' (SUMMARY.txt); 2. Boundary markers: Not described; 3. Capability inventory: 'Database Query Tool', 'E-commerce Order Processing', and 'System monitoring and remediation' (SUMMARY.txt); 4. Sanitization: Not described.
- METADATA_POISONING (LOW): The summary includes several self-referential claims of safety and quality (e.g., 'Security Best Practices', 'Quality Metrics: Excellent', 'Production-ready: Yes') which are treated as data to be evaluated rather than authoritative conclusions.
- DYNAMIC_EXECUTION (INFO): The document references 'Dynamic Workflow Generation' as an advanced pattern (Example 13), which is a high-risk category for code injection if untrusted data influences the generation process.
Audit Metadata