n8nSAFE
MCP server that provides tools and resources for interacting with n8n API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://badge.fury.io/js/%40leonardsellem%2Fn8n-mcp-server)
A Model Context Protocol (MCP) server that allows AI assistants to interact with n8n workflows through natural language.
Overview
This project provides a Model Context Protocol (MCP) server that empowers AI assistants to seamlessly interact with n8n, a popular workflow automation tool. It acts as a bridge, enabling AI assistants to programmatically manage and control n8n workflows and executions using natural language commands.
Installation
Prerequisites
- Node.js 20 or later
- n8n instance with API access enabled
Install from npm
npm install -g @leonardsellem/n8n-mcp-server
Install from source
# Clone the repository git clone https://github.com/leonardsellem/n8n-mcp-server.git cd n8n-mcp-server # Install dependencies npm install # Build the project npm run build # Optional: Install globally npm install -g .
Docker Installation
You can also run the server using Docker:
# Pull the image docker pull leonardsellem/n8n-mcp-server # Run the container with your n8n API configuration docker run -e N8N_API_URL=http://your-n8n:5678/api/v1 \ -e N8N_API_KEY=your_n8n_api_key \ -e N8N_WEBHOOK_USERNAME=username \ -e N8N_WEBHOOK_PASSWORD=password \ leonardsellem/n8n-mcp-server
Updating the Server
How you update the server depends on how you initially installed it.
1. Installed globally via npm
If you installed the server using npm install -g @leonardsellem/n8n-mcp-server:
- Open your terminal or command prompt.
- Run the following command to get the latest version:
npm install -g @leonardsellem/n8n-mcp-server@latest
- If the server is currently running (e.g., as a background process or service), you'll need to restart it for the changes to take effect.
2. Installed from source
If you cloned the
fdebac001389OBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add n8n-mcp-server -- npx -y @leonardsellem/[email protected]
{
"mcpServers": {
"n8n-mcp-server": {
"command": "npx",
"args": [
"-y",
"@leonardsellem/[email protected]"
]
}
}
}Exposed tools (11)
6 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
activate_workflow | read | Activate a workflow in n8n |
create_workflow | write | Create a new workflow in n8n |
deactivate_workflow | read | Deactivate a workflow in n8n |
delete_execution | destructive | Delete a specific workflow execution from n8n |
delete_workflow | destructive | Delete a workflow from n8n |
get_execution | read | Retrieve detailed information about a specific workflow execution |
get_workflow | read | Retrieve a specific workflow by ID |
list_executions | read | Retrieve a list of workflow executions from n8n |
list_workflows | read | Retrieve a list of all workflows available in n8n |
run_webhook | write | Execute a workflow via webhook with optional input data |
update_workflow | write | Update an existing workflow in n8n |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
delete_execution, delete_workflow
.babelrc
import { N8nApiService } from '../../api/n8n-client.js';import { formatExecutionDetails } from '../../utils/execution-formatter.js';import { formatResourceUri } from '../../utils/resource-formatter.js';import { McpError, ErrorCode } from '../../errors/index.js';import { N8nApiService } from '../../api/n8n-client.js';@modelcontextprotocol/sdk, axios, dotenv, find-config, @babel/core, @babel/plugin-transform-modules-commonjs, @babel/preset-env, @babel/preset-typescript
Gates applied: no_behavioural_pass.
fdebac001389full audit observations/trust-audit/mcp-server/leonardsellem__n8n-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | fdebac001389 | SAFE | B | 89 | source changed, verdict held |
Questions
What is the n8n MCP server?
MCP server that provides tools and resources for interacting with n8n API
What tools does n8n expose?
11 in total: 6 read-only, 3 that write, and 2 that can delete or overwrite (delete_execution, delete_workflow). Every one is listed on this page with its risk.
Is n8n safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does n8n need?
No credential environment variables were found in its source, so it appears to need none.
How does n8n run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @leonardsellem/n8n-mcp-server at 0.1.8.
How current is this page?
The grade is for one exact copy of the source (fdebac001389), read on 2026-09-24. The repository is watched and re-audited when it changes.