Atlas / MCP servers / leonardsellem / n8n

n8nSAFE

mcp/leonardsellem/n8n-2

MCP server that provides tools and resources for interacting with n8n API

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
11 6r · 3w · 2d
Transport
stdio
License
MIT
Stars
1,633
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://badge.fury.io/js/%40leonardsellem%2Fn8n-mcp-server)

A Model Context Protocol (MCP) server that allows AI assistants to interact with n8n workflows through natural language.

Overview

This project provides a Model Context Protocol (MCP) server that empowers AI assistants to seamlessly interact with n8n, a popular workflow automation tool. It acts as a bridge, enabling AI assistants to programmatically manage and control n8n workflows and executions using natural language commands.

Installation

Prerequisites

  • Node.js 20 or later
  • n8n instance with API access enabled

Install from npm

npm install -g @leonardsellem/n8n-mcp-server

Install from source

# Clone the repository
git clone https://github.com/leonardsellem/n8n-mcp-server.git
cd n8n-mcp-server

# Install dependencies
npm install

# Build the project
npm run build

# Optional: Install globally
npm install -g .

Docker Installation

You can also run the server using Docker:

# Pull the image
docker pull leonardsellem/n8n-mcp-server

# Run the container with your n8n API configuration
docker run -e N8N_API_URL=http://your-n8n:5678/api/v1 \
-e N8N_API_KEY=your_n8n_api_key \
-e N8N_WEBHOOK_USERNAME=username \
-e N8N_WEBHOOK_PASSWORD=password \
leonardsellem/n8n-mcp-server

Updating the Server

How you update the server depends on how you initially installed it.

1. Installed globally via npm

If you installed the server using npm install -g @leonardsellem/n8n-mcp-server:

  1. Open your terminal or command prompt.
  2. Run the following command to get the latest version:
npm install -g @leonardsellem/n8n-mcp-server@latest
  1. If the server is currently running (e.g., as a background process or service), you'll need to restart it for the changes to take effect.

2. Installed from source

If you cloned the

Read from source at commit fdebac001389OBSERVED · 2026-09-24
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add n8n-mcp-server -- npx -y @leonardsellem/[email protected]
claude-desktop
{
  "mcpServers": {
    "n8n-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@leonardsellem/[email protected]"
      ]
    }
  }
}
03

Exposed tools (11)

6 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
activate_workflowreadActivate a workflow in n8n
create_workflowwriteCreate a new workflow in n8n
deactivate_workflowreadDeactivate a workflow in n8n
delete_executiondestructiveDelete a specific workflow execution from n8n
delete_workflowdestructiveDelete a workflow from n8n
get_executionreadRetrieve detailed information about a specific workflow execution
get_workflowreadRetrieve a specific workflow by ID
list_executionsreadRetrieve a list of workflow executions from n8n
list_workflowsreadRetrieve a list of all workflows available in n8n
run_webhookwriteExecute a workflow via webhook with optional input data
update_workflowwriteUpdate an existing workflow in n8n
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_execution, delete_workflow
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.babelrc
.babelrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/dynamic/execution.ts:8
import { N8nApiService } from '../../api/n8n-client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/dynamic/execution.ts:9
import { formatExecutionDetails } from '../../utils/execution-formatter.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/dynamic/execution.ts:10
import { formatResourceUri } from '../../utils/resource-formatter.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/dynamic/execution.ts:11
import { McpError, ErrorCode } from '../../errors/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/dynamic/workflow.ts:8
import { N8nApiService } from '../../api/n8n-client.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, dotenv, find-config, @babel/core, @babel/plugin-transform-modules-commonjs, @babel/preset-env, @babel/preset-typescript
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-24 · audit v0.4.1 · source sha fdebac001389full audit observations/trust-audit/mcp-server/leonardsellem__n8n-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-24fdebac001389SAFEB89source changed, verdict held
06

Questions

What is the n8n MCP server?

MCP server that provides tools and resources for interacting with n8n API

What tools does n8n expose?

11 in total: 6 read-only, 3 that write, and 2 that can delete or overwrite (delete_execution, delete_workflow). Every one is listed on this page with its risk.

Is n8n safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does n8n need?

No credential environment variables were found in its source, so it appears to need none.

How does n8n run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @leonardsellem/n8n-mcp-server at 0.1.8.

How current is this page?

The grade is for one exact copy of the source (fdebac001389), read on 2026-09-24. The repository is watched and re-audited when it changes.

Advertisement