n8n

@sirrlock/n8n-nodes-sirr

002b4c4f-3f27-5063-97fb-5dcd882ab580 | v1.0.13
55/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (55/100) still counts them.

Analysis record

Analysed
6 months ago
Version
v1.0.0
Artifact
SHA256 636…E65
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

20 detail rows

YARA Rule Matches

7 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 1
package/dist/nodes/Sirr/Sirr.node.e2e.test.js
-
LOWpostinstall file download 2
package/dist/nodes/Sirr/Sirr.node.e2e.test.jspackage/README.md
-
LOWSQLInjection 2
package/dist/nodes/Sirr/Sirr.node.e2e.test.jspackage/dist/nodes/Sirr/Sirr.node.js
-
LOWpostinstall file manipulation 4
package/dist/nodes/Sirr/Sirr.node.e2e.test.jspackage/dist/nodes/Sirr/Sirr.node.test.jspackage/dist/nodes/Sirr/Sirr.node.js +1 more
-
LOWpostinstall obfuscation 1
package/dist/nodes/Sirr/Sirr.node.js
-
LOWpostinstall network communication 2
package/LICENSEpackage/dist/nodes/Sirr/Sirr.node.test.js
-
LOWpostinstall system command 5
package/dist/nodes/Sirr/Sirr.node.e2e.test.jspackage/dist/nodes/Sirr/Sirr.node.test.jspackage/dist/nodes/Sirr/Sirr.node.js +2 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

50 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

3
Network
50
IoC Indicators

YARA Rules Matched

7 rules(17 hits)
credential env files postinstall file download SQLInjection postinstall file manipulation postinstall obfuscation postinstall network communication postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This n8n node package for Sirr ephemeral secret management shows no evidence of malicious behavior. The 71 total findings are entirely explainable as scanner noise and false positives.

Tool Poisoning Assessment: The package has 0 tool-poisoning findings. This is the defining threat for MCP/agent packages, and its absence is significant. There are no hidden AI directives, no XML-style instruction tags, and no suspicious tool descriptions that would indicate tool poisoning.

Credential Access: The scanner detected 0 secret findings and 0 credential-access findings. The package reads no sensitive paths (.ssh, .aws, .kube) and has no evidence of credential harvesting. The code-smell findings (17 total) are low-severity noise from generic patterns.

Network Activity: The 3 network findings are all in test files, specifically package/dist/nodes/Sirr/Sirr.node.e2e.test.js:64 (NET-FETCH), not production code. The only domain detected is sirrlock.com (XIOC-DOMAIN-sirrlock.com), which is the legitimate service domain for this package.

IOC False Positives: The 51 IOC findings are clearly scanner noise from known false-positive patterns:

Strongest Counterargument: The high finding count (71) and "GitHub Actions" developer name could suggest automated/malicious publishing. However, the findings themselves contain no malicious patterns—no credential theft, no suspicious domains, no tool poisoning. The developer name "GitHub Actions" is common for automated CI/CD publishing and doesn't indicate malice.

Conclusion: This package is a legitimate n8n node for Sirr secret management with no evidence of malicious behavior. All findings are false positives from known scanner noise patterns.

Key Reasons

  • Zero tool-poisoning findings (defining MCP threat absent)
  • Zero secret/credential-access findings
  • All IOC findings are false positives from file extensions, badge URLs, and property access chains
  • Network activity only in test files (e2e.test.js)
  • Only legitimate domain detected: sirrlock.com

False Positive Considerations

  • File extensions misread as domains (.map files)
  • Badge URLs from img.shields.io
  • Property access chains (body.events, principal.me)
  • Placeholder domains (example.com)

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

About This Extension

n8n community node for Sirr — ephemeral secret management

Frequently Asked Questions