ClawAudit verdict
npm-n8n-nodes
Developer skill for building and publishing n8n custom community nodes to npm; network_in is for documentation patterns and the full lifecycle is legitimate developer tooling.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Possible hardcoded credential
references/examples/credentials/api-key-patterns.md ยท code ยท api_key: '={{$credentials.apiKey}}
Instructs covert action โ may act without user awareness
references/concepts/error-handling.md ยท prose ยท downgraded ยท silently
References webhook/callback URL
references/examples/nodes/webhook-node.md ยท code ยท webhookUrl
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_in Is this flag fair?
Thanks โ recorded.