Score-based assessment (medium risk, 59/100). No analyst review available.
Analysis record
- Analysed
- 6 months ago
- Version
- v0.1.0
- Artifact
- SHA256 EE8…EB5
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall network communication | 3 | package/LICENSE.mdpackage/dist/tsconfig.tsbuildinfopackage/dist/pnpm-lock.yaml | - |
| LOW | postinstall registry modification | 2 | package/dist/pnpm-lock.yamlpackage/README.md | - |
| LOW | postinstall obfuscation | 3 | package/dist/tsconfig.tsbuildinfopackage/dist/pnpm-lock.yamlpackage/dist/nodes/EnigmaNode/EnigmaNode.node.js | - |
| LOW | postinstall environment access | 1 | package/dist/pnpm-lock.yaml | - |
| LOW | postinstall file manipulation | 2 | package/dist/pnpm-lock.yamlpackage/dist/tsconfig.tsbuildinfo | - |
| LOW | postinstall system command | 5 | package/dist/tsconfig.tsbuildinfopackage/dist/pnpm-lock.yamlpackage/dist/nodes/EnigmaNode/EnigmaNode.node.d.ts +2 more | - |
| LOW | postinstall crypto operations | 6 | package/dist/nodes/EnigmaNode/EnigmaNode.node.jspackage/dist/package.jsonpackage/README.md +3 more | - |
| LOW | postinstall file download | 2 | package/dist/tsconfig.tsbuildinfopackage/README.md | - |
| LOW | postinstall persistence mechanism | 1 | package/dist/tsconfig.tsbuildinfo | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
9 rules(25 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality absent.
Security analysis for n8n-nodes-enigma indicates no detected threats. The evidence bundle provided is empty (findings_by_category: {}), which suggests the scanning process yielded zero security signals or artifacts matching known malicious patterns, tool-poisoning rules, or credential exfiltration signatures. As a community node for the n8n workflow automation platform, this package integrates the Cubbit Enigma encryption library. In the context of n8n, this architecture is standard: the node acts as a wrapper/adapter to expose specific library functionality (encryption/decryption) within the n8n canvas. While encryption tools are inherently powerful, there is no evidence of tool poisoning (hidden AI directives), environment variable exfiltration, or suspicious network activity in the provided data. The absence of findings does not guarantee code safety, but it aligns with expectations for a functional integration node from a community developer.
Key Reasons
- Empty evidence bundle provided (findings_by_category is empty)
- Zero network IoCs detected
- Zero tool-poisoning signatures detected
- Stated purpose (n8n encryption node) matches expected behavior
False Positive Considerations
- Insufficient scan data
Reviewed 2026-04-13; recommended action: no action; model confidence 60%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace