no-code-pipelines

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/hubspot-to-personize.json

The code is a legitimate-looking n8n workflow that reads HubSpot contact data and forwards contact PII to an external service (Personize) via a hard-coded API endpoint. There is no evidence of obfuscation, dynamic code execution, or classic malware techniques. The primary security risk is privacy and data-exfiltration: unredacted PII is sent to a third-party service. Confirm that this data transfer is intended, that legal/consent/compliance requirements are met, and that the Personize endpoint is trusted and properly secured. Also verify that the referenced credentials are stored securely and that n8n logging/retention settings do not leak PII. If the transfer is not intended, remove or modify the HTTP node before deployment.

Confidence: 85%Severity: 65%
Audit Metadata
Analyzed At
Mar 8, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/personizeai%2Fpersonize-skills%2Fno-code-pipelines%2F@196b85598a5ca145de551c34a85739031cfd1da8