Based on the RiskyPlugins AI security review of the observed evidence.
No individual score drivers were recorded for this analysis.
Analysis record
- Analysed
- 6 months ago
- Version
- v1.1.9
- Artifact
- SHA256 CB9…042
- Source
- Findings (non-IoC)
No Findings
All security checks passed
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Tool-Poisoning Assessment:
Zero tool-poisoning findings were detected. The findings summary explicitly shows "tool-poisoning":"0". This is a critical indicator that the package does not contain hidden AI manipulation directives, which is the defining threat for MCP/automation packages. Without any tool-poisoning findings, there is no evidence of instructions embedded in tool descriptions aimed at manipulating AI agent behavior.
Credential and Network Access:
The findings summary shows "secret":"0" and "network":"0" - no credential access or suspicious network activity findings. The 14 IoC findings are all benign URLs and domains:
XIOC-URL-https://docs.n8n.io/credentials/'- n8n documentation linkXIOC-URL-https://github.com/kiro-dev/n8n-nodes-api-key-validator.git- Package's own GitHub repositoryXIOC-DOMAIN-github.com- GitHub domainXIOC-DOMAIN-kiro.ai- Developer domainXIOC-DOMAIN-www.w3.org- W3C standards organization[email protected]- Developer contact email
These IoCs represent standard documentation references and repository links, not exfiltration endpoints. There is no combination of credential-access findings with network calls to unknown domains, which would indicate exfiltration architecture.
Code-Smell Findings:
The 6 code-smell findings are all low-severity. Per the CVEQ false-positive documentation, code-smell rules (postinstall_*, credential_*, NoUseEval, SQLInjection, etc.) fire on almost any non-trivial JavaScript and should NEVER drive a verdict. These are noise from the YARA code-smell scanner.
Strongest Counterargument:
The user count of 0 could suggest an unvetted package, but this alone does not indicate malice. The package name n8n-nodes-api-key-validator matches its stated purpose of validating API keys, and all extracted URLs are legitimate (n8n docs, GitHub, W3C). The developer name marcos345 differs from the GitHub organization kiro-dev, but this is a common pattern for team-maintained packages and does not constitute typosquatting or impersonation.
Conclusion:
This package exhibits no malicious indicators. All findings are explainable as documentation URLs, repository references, and code-smell noise. The zero tool-poisoning, zero secret, and zero network findings confirm this is a legitimate n8n community node for API key validation.
Key Reasons
- Zero tool-poisoning findings - no hidden AI directives
- All IoC URLs are benign (GitHub, n8n docs, W3C)
- Zero secret or network findings - no exfiltration architecture
- Code-smell findings are low-severity noise
False Positive Considerations
- IoC URLs are legitimate documentation and repository links (n8n.io, github.com, w3.org)
- Code-smell findings are low-severity YARA noise
- Zero tool-poisoning findings
- Zero credential access or network exfiltration findings
Reviewed 2026-04-27; recommended action: no action; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace