Cursor n8n BuilderSAFE
Cursor n8n Workflow Builder MCP
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/MIT) [](https://nodejs.org/)
A Model Context Protocol (MCP) server that enables AI assistants in Cursor IDE to manage n8n workflows through the n8n REST API.
Features
- Workflow Management: Create, update, delete, and list workflows
- Workflow Activation: Activate and deactivate workflows
- Execution Management: View execution history and details
- Webhook Triggering: Trigger workflows via webhook URLs
- Self-Documentation: Built-in help system for AI assistants
- Node Information: Common n8n node types and configurations
- Error Handling: Automatic retry with exponential backoff
Quick Start
Installation
git clone https://github.com/alicankiraz1/cursor-n8n-mcp.git cd cursor-n8n-mcp npm install npm run build node dist/index.js setup
Or use the install script:
./install.sh
Manual Configuration
Create or edit ~/.cursor/mcp.json for global configuration:
{
"mcpServers": {
"cursor-n8n-mcp": {
"command": "node",
"args": ["/path/to/cursor-n8n-mcp/dist/index.js"],
"env": {
"MCP_MODE": "stdio",
"LOG_LEVEL": "error",
"N8N_API_URL": "https://your-n8n-instance.com",
"N8N_API_KEY": "your-api-key"
}
}
}
}Getting n8n API Key
- Log in to your n8n instance
- Go to Settings > API
- Click Create API Key
- Copy the generated key
Available Tools
Documentation & Help
Workflow Management
e31ddc66cbf9OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cursor-n8n-mcp --env N8N_API_KEY=${N8N_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"cursor-n8n-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"N8N_API_KEY": "${N8N_API_KEY}"
}
}
}
}Exposed tools (14)
8 read · 4 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
n8n_activate_workflow | read | Activate a workflow so it can be triggered. The workflow must have a valid trigger node. |
n8n_create_workflow | write | Create a new workflow with nodes and connections. The workflow will be created in inactive state. |
n8n_deactivate_workflow | write | Deactivate a workflow to stop it from being triggered. |
n8n_delete_execution | destructive | Delete an execution record. |
n8n_delete_workflow | destructive | Permanently delete a workflow. This action cannot be undone. |
n8n_get_execution | read | Get detailed information about a specific execution including input/output data. |
n8n_get_node_info | read | Get information about common n8n node types and their configurations. |
n8n_get_workflow | read | Get detailed information about a specific workflow including all nodes and connections. |
n8n_health_check | read | Check the connection to the n8n instance and verify API credentials. |
n8n_list_executions | read | List workflow executions. Can filter by workflow ID and status. |
n8n_list_workflows | read | List all workflows in the n8n instance. Returns workflow IDs, names, and active status. |
n8n_tools_help | read | Get documentation and usage guide for n8n MCP tools. Call this first to understand available capabilities. |
n8n_trigger_webhook | write | Trigger a workflow via its webhook URL. The workflow must be active and have a Webhook trigger node. |
n8n_update_workflow | write | Update an existing workflow. You can update name, nodes, connections, or settings. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
n8n_delete_execution, n8n_delete_workflow
@modelcontextprotocol/sdk, dotenv, zod, @types/node, typescript
Gates applied: no_behavioural_pass.
e31ddc66cbf9full audit observations/trust-audit/mcp-server/alicankiraz1__cursor-n8n-builder.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e31ddc66cbf9 | SAFE | B | 89 | first audit |
Questions
What is the Cursor n8n Builder MCP server?
Cursor n8n Workflow Builder MCP
What tools does Cursor n8n Builder expose?
14 in total: 8 read-only, 4 that write, and 2 that can delete or overwrite (n8n_delete_execution, n8n_delete_workflow). Every one is listed on this page with its risk.
Is Cursor n8n Builder safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Cursor n8n Builder need?
It reads N8N_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Cursor n8n Builder run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as cursor-n8n-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (e31ddc66cbf9), read on 2026-10-08. The repository is watched and re-audited when it changes.