n8n-automation

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill documentation implements expected actions for managing n8n via its REST API and is internally consistent with its purpose. There are no signs of malicious code, obfuscated payloads, remote download-and-execute instructions, or third-party credential forwarding. The primary security concerns are operational: the API key is high-privilege and advice to store it in plaintext or export it into environment variables can lead to credential leakage. Webhook endpoints are unauthenticated by design and exposing webhook URLs can allow arbitrary triggers. Overall this appears benign in intent but operationally moderate risk if credentials or URLs are mishandled.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:15 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Fn8n-automation%2F@b5ed00dc3323281c6f64b35153a03f5539bcf778