n8n

n8n-nodes-sunlink

004c2ca9-b68c-5b1f-b8a5-c0f19f15e497 | v0.2.5
37/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v0.2.5
Artifact
SHA256 A1C…165
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

19 detail rows

YARA Rule Matches

5 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 2
package/dist/nodes/SunLink/SunLink.node.jspackage/dist/nodes/SunLink/descriptions/OtherResourcesDescription.js
-
LOWpostinstall file manipulation 11
package/dist/nodes/SunLink/descriptions/ArticleDescription.jspackage/dist/nodes/SunLink/descriptions/OtherResourcesDescription.jspackage/dist/nodes/SunLink/SunLinkApi.credentials.js +8 more
-
LOWpostinstall obfuscation 1
package/dist/nodes/SunLink/SunLink.node.js
-
LOWpostinstall network communication 4
package/dist/nodes/SunLink/descriptions/ArticleDescription.jspackage/dist/nodes/SunLink/descriptions/FileDescription.jspackage/dist/nodes/SunLink/descriptions/OtherResourcesDescription.js +1 more
-
LOWpostinstall system command 1
package/dist/nodes/SunLink/SunLink.node.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

21 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

21
IoC Indicators

YARA Rules Matched

5 rules(19 hits)
postinstall file download postinstall file manipulation postinstall obfuscation postinstall network communication postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Tool Poisoning Assessment

No tool-poisoning findings detected. The findings summary explicitly shows "tool-poisoning":"0". This is the defining threat for MCP servers and AI agent packages, and its absence is a strong indicator of benign behavior. Unlike malicious packages that embed hidden AI directives in tool descriptions, this package contains no evidence of manipulation instructions, XML-style tags, or Unicode steganography aimed at AI agents.

Credential and Network Access

No credential theft or exfiltration architecture detected. The findings summary shows "secret":"0" with zero credential-access findings. There are no detections targeting sensitive paths like .ssh/, .aws/credentials, .kube/config, or application_default_credentials.json. Additionally, the findings summary shows "network":"0" — no NET-FETCH or NET-SOCKET_IO findings exist. The combination of credential reads plus network calls to unknown domains (the exfiltration signal) is absent.

IoC Findings Analysis

All 23 IoC findings are false positives from the XIOC extractor:

  • XIOC-DOMAIN-date.now and XIOC-DOMAIN-this.name are JavaScript property access patterns misidentified as domains
  • XIOC-URL-http://www.w3.org/2000/svg and XIOC-URL-http://www.w3.org/1999/xlink are standard W3C XML namespaces
  • XIOC-DOMAIN-sunlinkapi.credentials.js.map is a source map filename, not a domain
  • [email protected] is a placeholder email address
  • XIOC-DOMAIN-docs.n8n.io and XIOC-URL-https://docs.n8n.io/credentials/' reference official n8n documentation
  • XIOC-DOMAIN-github.com and XIOC-URL-https://github.com/DuanPeng1314/SunLink-n8n.git reference the package's GitHub repository
  • XIOC-URL-https://www.dp7575.com.cn/api' is the only potentially real domain, but it aligns with the package's stated purpose ("SunLink (Anheyu Blog) API") and appears in configuration, not exfiltration code

Code-Smell Findings

The 19 code-smell findings ("code-smell":"19") are YARA rule noise from generic JavaScript patterns. These are classified as severity:low and do not indicate malicious behavior. No malware-signature or malware findings exist ("malware-signature":"0", "malware":"0").

Strongest Counterargument

The package has zero users ("user_count":0) and references a Chinese domain (dp7575.com.cn). However, zero users is common for new or niche n8n nodes, and the domain matches the package's documented purpose (SunLink API integration). Without network findings showing actual data transmission to this domain, or credential-access findings showing secret harvesting, there is no evidence of malicious intent. The package appears to be a legitimate workflow automation node for the SunLink blog platform.

Conclusion

This package exhibits no indicators of malicious behavior. All findings are explainable as false positives from IoC extraction artifacts and code-smell rules. The absence of tool-poisoning, credential theft, malware signatures, and network exfiltration findings supports a false positive verdict.

Key Reasons

  • Zero tool-poisoning findings (the defining MCP threat)
  • Zero credential-access or secret findings
  • Zero network findings (no exfiltration architecture)
  • All IoC findings are false positives from XIOC extractor noise
  • Zero malware-signature or malware findings

False Positive Considerations

  • XIOC-DOMAIN-date.now and this.name are JavaScript patterns misidentified as domains
  • W3C namespace URLs (w3.org/2000/svg, w3.org/1999/xlink) flagged as IoCs
  • Source map filename (sunlinkapi.credentials.js.map) misidentified as domain
  • Code-smell findings from generic YARA rules on JavaScript patterns

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 72%.

About This Extension

n8n Code for SunLink (Anheyu Blog) API

Frequently Asked Questions