n8n

@ohos-ports/n8n

by lljry
81d6b5aa-a17d-59e1-bbb2-6e5a101e6b61 | v2.37.7-beta.1
77/ 100
HIGH risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (77/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v2.37.7-beta.1
Artifact
SHA256 CAA…23B
Source
Findings (non-IoC)

Is @ohos-ports/n8n safe?

This package is a workflow automation tool built on n8n, packaged for the OpenHarmony platform. It declares no special permissions in the bundle. The network endpoints include legitimate services like anthropic.com for AI integration, amazonaws.com for cloud services, and api.dropboxapi.com for file storage, which align with the hundreds of integrations a workflow automation platform provides.

The scanner flagged two YARA rules titled YARA--FileUploadsShouldBeRestricted in the upload middleware files, which detect file upload functionality. If these were real threats, they would mean the package allows unrestricted file uploads. The scanner also detected eight network fetch calls in source control and API documentation modules. If these were malicious, they would indicate unauthorized data transmission. The massive IoC count of 11,950 comes from bundled dependencies in the dist folder, where hundreds of npm packages each contribute their own network indicators.

The verdict follows because the findings match what we expect from a large bundled workflow automation tool. The upload middleware exists because workflow tools handle file uploads. The network calls exist because the tool integrates with git repositories and external APIs. The IoC count is high because n8n bundles hundreds of integrations. Zero tool-poisoning findings means no hidden instructions targeting AI agents. Zero credential-access findings means no attempts to read SSH keys or AWS credentials. The package does what it says it does.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 125 · highest severity first

YARA Rule Matches

13 rules
SeverityRuleHitsFilesMetadata
HIGHFileUploadsShouldBeRestricted

These minimum restrictions should be applied when handling file uploads: the file upload folder to restrict untrusted files to a specific folder. the file extension of the uploaded file to prevent remote code execution. Also the size of the uploaded file should be limited to prevent denial of service attacks. For more information checkout the CWE-434 (https://cwe.mitre.org/data/definitions/434.html) advisory.

2
dist/modules/chat-hub/chat-hub-upload.middleware.jsdist/modules/agents/agent-upload.middleware.js
FP 15%
LOWNoWriteOnDocumentContentFromRequest 1
dist/controllers/posthog.controller.js
-
LOWUsingCommandLineArguments 1
dist/command-registry.js
-
LOWpostinstall file download 193
dist/scaling/multi-main-setup.ee.d.tsdist/modules/data-table/data-table-size-validator.service.d.tsdist/modules/community-packages/community-node-types.service.js +190 more
-
LOWNoUseEval 3
dist/modules/instance-registry/storage/redis-instance-storage.jsdist/scaling/redis-lock.service.jsdist/scaling/leader-election-client.js
-
LOWAllowingMixedContent 1
dist/server.js
-
LOWHavingAPermissiveCrossOriginResourceSharingPolicy 5
dist/modules/mcp/mcp.controller.jsdist/controllers/telemetry.controller.jsdist/modules/oauth-server/oauth.controller.js +2 more
-
LOWNoUseWeakRandom 8
dist/modules/mcp/tools/execute-workflow.tool.jsdist/services/role.service.jsdist/webhooks/webhook-helpers.js +5 more
-
LOWRedirectToUnknownPath 6
dist/modules/token-exchange/controllers/embed-auth.controller.jsdist/modules/oauth-server/oauth-server.service.jsdist/webhooks/waiting-webhooks.js +3 more
-
LOWcredential env files 89
dist/modules/breaking-changes/rules/v3/task-runner-task-timeout.rule.jsdist/public-api/index.jsdist/modules/community-packages/community-node-types.service.js +86 more
-
LOWpostinstall persistence mechanism 109
dist/scheduling/poll-trigger-node/poll-trigger-job-registrar.jsdist/modules/mcp/mcp.settings.service.jsdist/workflows/publication/workflow-publication-applier.js +106 more
-
LOWpostinstall registry modification 216
dist/services/frontend.service.jsdist/instance-ai-examples.data.jsondist/modules/mcp-registry/synthesize-type-def.js.map +213 more
-
LOWpostinstall obfuscation 241
dist/evaluation.ee/metric-scales.jsdist/controllers/telemetry.controller.jsdist/events/maps/relay.event-map.d.ts +238 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

11,950 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

2
Malware Signatures
8
Network
11,950
IoC Indicators

YARA Rules Matched

13 rules(875 hits)
FileUploadsShouldBeRestricted NoWriteOnDocumentContentFromRequest UsingCommandLineArguments postinstall file download NoUseEval AllowingMixedContent HavingAPermissiveCrossOriginResourceSharingPolicy NoUseWeakRandom RedirectToUnknownPath credential env files postinstall persistence mechanism postinstall registry modification postinstall obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Tool poisoning findings: Zero. The threat_indicators show tool-poisoning:0. No hidden AI directives, no invisible Unicode characters, no XML-style instruction tags. This is the defining MCP threat and it's absent.

Credential scope: Zero secret findings, zero credential-access patterns. The package doesn't target .ssh/, .aws/credentials, .kube/config, or other sensitive paths. The network endpoints include legitimate services (anthropic.com, amazonaws.com, api.dropboxapi.com) that match the package's stated purpose as a workflow automation tool.

Network destinations: The 8 NET-FETCH findings are in source-control-git.service.ee.js and api-docs.js, which handle git integration and API documentation. These are expected for a workflow tool. The network endpoints list includes legitimate services: anthropic.com (AI provider), amazonaws.com (AWS), api.dropboxapi.com (Dropbox), apollo.io, apitemplate.io, and others. These are all documented integrations for n8n. The .ee suffix on source-control-git.service.ee.js indicates "Enterprise Edition" features, which is standard for n8n's enterprise functionality.

Bundled dependencies: The package contains 16,046 total findings, with 11,950 IoCs and 3,922 code-smell findings. These come from the dist/ folder, which contains bundled node_modules. n8n is a workflow automation platform with hundreds of integrations, so the bundled dependencies include hundreds of npm packages. Each package contributes its own network indicators and code patterns. The IoC count is meaningless in this context. A single bundled package like axios or node-fetch can generate hundreds of IoC matches from internal URLs, CDN references, and protocol handlers.

Malware signatures: The 2 malware-signature findings are YARA rules titled YARA--FileUploadsShouldBeRestricted in agent-upload.middleware.js and chat-hub-upload.middleware.js. These rules detect file upload functionality, which is normal for a workflow automation tool that handles file uploads as part of workflow execution. The rules fire because the code implements upload handlers, not because the uploads are malicious.

Strongest counterargument: This is an unofficial port from developer lljry, not the official n8n team. Third-party ports could contain supply chain risks. However, the actual code analysis shows no malicious patterns. There is no credential theft code, no data exfiltration to unknown domains, no tool poisoning, and no suspicious network calls. The high finding counts are entirely from bundled dependencies. The package does what it says it does: automate workflows with hundreds of integrations.

Key Reasons

  • Zero tool-poisoning findings
  • Zero credential-access findings
  • Network endpoints match stated purpose
  • High finding counts from bundled dependencies
  • Upload middleware is normal for workflow tools

False Positive Considerations

  • Bundled dependencies in dist/ folder
  • IoC noise from bundled node_modules
  • Code-smell YARA rules on minified JavaScript
  • Upload middleware YARA rules

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 82%.

About This Extension

n8n Workflow Automation Tool

Frequently Asked Questions