n8n-cli

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s functions match n8n administration, but it centers on a non-official third-party CLI and forwards a high-value API key to that tool. Data flows appear intended for the user’s n8n instance rather than an obvious exfiltration endpoint, so this is not confirmed malware, but the install/provenance and credential-forwarding risks are significant.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 22, 2026, 09:57 AM
Package URL
pkg:socket/skills-sh/n8n-io%2Fn8n%2Fn8n-cli%2F@d78b55504839863970128db4c57c7d9279f5e032