The AI review rates the findings as likely false positive, but the risk score (77/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v2.37.7-beta.1
- Artifact
- SHA256 CAA…23B
- Source
- Findings (non-IoC)
Is @ohos-ports/n8n safe?
This package is a workflow automation tool built on n8n, packaged for the OpenHarmony platform. It declares no special permissions in the bundle. The network endpoints include legitimate services like anthropic.com for AI integration, amazonaws.com for cloud services, and api.dropboxapi.com for file storage, which align with the hundreds of integrations a workflow automation platform provides.
The scanner flagged two YARA rules titled YARA--FileUploadsShouldBeRestricted in the upload middleware files, which detect file upload functionality. If these were real threats, they would mean the package allows unrestricted file uploads. The scanner also detected eight network fetch calls in source control and API documentation modules. If these were malicious, they would indicate unauthorized data transmission. The massive IoC count of 11,950 comes from bundled dependencies in the dist folder, where hundreds of npm packages each contribute their own network indicators.
The verdict follows because the findings match what we expect from a large bundled workflow automation tool. The upload middleware exists because workflow tools handle file uploads. The network calls exist because the tool integrates with git repositories and external APIs. The IoC count is high because n8n bundles hundreds of integrations. Zero tool-poisoning findings means no hidden instructions targeting AI agents. Zero credential-access findings means no attempts to read SSH keys or AWS credentials. The package does what it says it does.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
13 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | FileUploadsShouldBeRestricted These minimum restrictions should be applied when handling file uploads: the file upload folder to restrict untrusted files to a specific folder. the file extension of the uploaded file to prevent remote code execution. Also the size of the uploaded file should be limited to prevent denial of service attacks. For more information checkout the CWE-434 (https://cwe.mitre.org/data/definitions/434.html) advisory. | 2 | dist/modules/agents/agent-upload.middleware.jsdist/modules/chat-hub/chat-hub-upload.middleware.js | FP 15% |
| LOW | RedirectToUnknownPath | 6 | dist/modules/token-exchange/controllers/embed-auth.controller.jsdist/modules/oauth-server/oauth-server.service.jsdist/webhooks/waiting-webhooks.js +3 more | - |
| LOW | credential env files | 89 | dist/modules/breaking-changes/rules/v3/task-runner-task-timeout.rule.jsdist/public-api/index.jsdist/modules/community-packages/community-node-types.service.js +86 more | - |
| LOW | postinstall persistence mechanism | 109 | dist/modules/agents/integrations/cron-validation.d.tsdist/modules/mcp/mcp.settings.service.jsdist/workflows/publication/workflow-publication-applier.js +106 more | - |
| LOW | postinstall file download | 193 | dist/modules/mcp-registry/registry/mcp-registry-api.client.jsdist/modules/data-table/data-table-size-validator.service.d.tsdist/modules/community-packages/community-node-types.service.js +190 more | - |
| LOW | NoUseEval | 3 | dist/scaling/leader-election-client.jsdist/modules/instance-registry/storage/redis-instance-storage.jsdist/scaling/redis-lock.service.js | - |
| LOW | AllowingMixedContent | 1 | dist/server.js | - |
| LOW | HavingAPermissiveCrossOriginResourceSharingPolicy | 5 | dist/modules/mcp/mcp.controller.jsdist/controllers/telemetry.controller.jsdist/modules/oauth-server/oauth.controller.js +2 more | - |
| LOW | NoUseWeakRandom | 8 | dist/modules/mcp/tools/execute-workflow.tool.jsdist/services/role.service.jsdist/webhooks/webhook-helpers.js +5 more | - |
| LOW | NoWriteOnDocumentContentFromRequest | 1 | dist/controllers/posthog.controller.js | - |
| LOW | UsingCommandLineArguments | 1 | dist/command-registry.js | - |
| LOW | postinstall registry modification | 216 | dist/services/frontend.service.jsdist/modules/mcp-registry/mcp-registry-node-loader.jsdist/modules/favorites/favorites.service.d.ts +213 more | - |
| LOW | postinstall obfuscation | 241 | dist/modules/agent-evals/agent-evals.module.js.mapdist/modules/n8n-packages/entities/variable/variable-importer.jsdist/modules/instance-ai/eval/thread-credential-allowlist.service.d.ts +238 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
13 rules(875 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Tool poisoning findings: Zero. The threat_indicators show tool-poisoning:0. No hidden AI directives, no invisible Unicode characters, no XML-style instruction tags. This is the defining MCP threat and it's absent.
Credential scope: Zero secret findings, zero credential-access patterns. The package doesn't target .ssh/, .aws/credentials, .kube/config, or other sensitive paths. The network endpoints include legitimate services (anthropic.com, amazonaws.com, api.dropboxapi.com) that match the package's stated purpose as a workflow automation tool.
Network destinations: The 8 NET-FETCH findings are in source-control-git.service.ee.js and api-docs.js, which handle git integration and API documentation. These are expected for a workflow tool. The network endpoints list includes legitimate services: anthropic.com (AI provider), amazonaws.com (AWS), api.dropboxapi.com (Dropbox), apollo.io, apitemplate.io, and others. These are all documented integrations for n8n. The .ee suffix on source-control-git.service.ee.js indicates "Enterprise Edition" features, which is standard for n8n's enterprise functionality.
Bundled dependencies: The package contains 16,046 total findings, with 11,950 IoCs and 3,922 code-smell findings. These come from the dist/ folder, which contains bundled node_modules. n8n is a workflow automation platform with hundreds of integrations, so the bundled dependencies include hundreds of npm packages. Each package contributes its own network indicators and code patterns. The IoC count is meaningless in this context. A single bundled package like axios or node-fetch can generate hundreds of IoC matches from internal URLs, CDN references, and protocol handlers.
Malware signatures: The 2 malware-signature findings are YARA rules titled YARA--FileUploadsShouldBeRestricted in agent-upload.middleware.js and chat-hub-upload.middleware.js. These rules detect file upload functionality, which is normal for a workflow automation tool that handles file uploads as part of workflow execution. The rules fire because the code implements upload handlers, not because the uploads are malicious.
Strongest counterargument: This is an unofficial port from developer lljry, not the official n8n team. Third-party ports could contain supply chain risks. However, the actual code analysis shows no malicious patterns. There is no credential theft code, no data exfiltration to unknown domains, no tool poisoning, and no suspicious network calls. The high finding counts are entirely from bundled dependencies. The package does what it says it does: automate workflows with hundreds of integrations.
Key Reasons
- Zero tool-poisoning findings
- Zero credential-access findings
- Network endpoints match stated purpose
- High finding counts from bundled dependencies
- Upload middleware is normal for workflow tools
False Positive Considerations
- Bundled dependencies in dist/ folder
- IoC noise from bundled node_modules
- Code-smell YARA rules on minified JavaScript
- Upload middleware YARA rules
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 82%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace