n8n

n8n-nodes-viacep-br

1c652ba3-edf7-533a-bf73-fbc102ccff02 | v0.1.4
23/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
6 months ago
Version
v0.1.4
Artifact
SHA256 178…80B
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1 detail row

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Tool Poisoning Assessment

The findings summary shows "tool-poisoning":"0" — zero tool-poisoning findings were detected. This is a critical indicator that no hidden AI manipulation directives exist in this package. The code-smell findings (YARA--postinstall_file_manipulation and YARA--postinstall_network_communication in /tmp/extract-178087d461a97c933ba18dfb0af028fc32eaff3d776c0a83ae3c38a392cef80b-3709846637/package/dist/nodes/ViaCep/ViaCep.node.js) are low-severity YARA matches on basic Node.js patterns and are documented false positives per the CVEQ guidelines. These rules fire on almost any non-trivial JavaScript and should never drive a verdict.

Credential and Network Access

No credential-access findings, secret findings, or network findings exist in this bundle. The package reads no sensitive paths (.ssh, .aws, .kube, credentials files) and contains no exfiltration architecture. The IoC findings are all legitimate and expected for this package's stated purpose:

  • XIOC-DOMAIN-viacep.com.br and XIOC-URL-https://viacep.com.br/ws/$ — The package description states it queries ViaCEP (Brazilian postal code lookup service). These are the legitimate API endpoints the package is designed to call.
  • XIOC-DOMAIN-github.com and XIOC-URL-https://github.com/Marcosnb/viacep-n8n.git — Source repository reference.
  • XIOC-DOMAIN-www.w3.org — Standard XML namespace reference.
  • [email protected] and XIOC-DOMAIN-gmail.com — Developer contact information.

None of these domains represent suspicious exfiltration destinations. The package does not combine credential reads with network calls to unknown domains.

Strongest Counterargument

The 9 medium-severity IoC findings could suggest suspicious network activity. However, every single IoC is explainable: viacep.com.br is the documented service the package queries, github.com hosts the source code, and w3.org is a standard namespace. The package description explicitly states it queries ViaCEP for CEP (postal code) lookups, making these network destinations expected and legitimate. No IoC represents an unknown or suspicious domain.

Conclusion

This n8n node performs a single, well-defined function: querying the ViaCEP API for Brazilian postal code data. All findings are either documented false positives (code-smell YARA rules) or legitimate functionality (expected API calls to viacep.com.br). There is no evidence of tool poisoning, credential theft, exfiltration, or any malicious behavior.

Key Reasons

  • Zero tool-poisoning findings detected
  • All IoC findings are legitimate (viacep.com.br is the documented API the package queries)
  • Code-smell findings are documented false positives (YARA rules on basic Node.js patterns)
  • No credential-access or exfiltration architecture present
  • Package purpose (CEP lookup via ViaCEP) matches all network destinations

False Positive Considerations

  • YARA code-smell rules firing on basic Node.js patterns in dist/ files
  • IoC findings for legitimate API endpoint (viacep.com.br) that matches package purpose
  • No tool-poisoning findings detected
  • No credential-access or secret findings

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

About This Extension

N8N Community Node para consulta de CEP via ViaCEP

Frequently Asked Questions