Atlas / MCP servers / makafeli / N8n Workflow Builder

N8n Workflow BuilderSAFE

mcp/makafeli/n8n-workflow-builder-1

AI assistant integration for n8n workflow automation through Model Context Protocol (MCP). Connect Claude Desktop, ChatGPT, and other AI assistants to n8n for natural language workflow management.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
35 14r · 14w · 7d
Transport
stdio
License
MIT
Stars
544
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The ultimate AI assistant integration for n8n workflow automation - Connect Claude Desktop, ChatGPT, and other AI assistants directly to your n8n instance for seamless workflow management, creation, and execution through the Model Context Protocol (MCP).

Read from source at commit 0deebedc2b6eOBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add n8n-workflow-builder --env N8N_API_KEY=${N8N_API_KEY} -- npx -y @makafeli/[email protected]
claude-desktop
{
  "mcpServers": {
    "n8n-workflow-builder": {
      "command": "npx",
      "args": [
        "-y",
        "@makafeli/[email protected]"
      ],
      "env": {
        "N8N_API_KEY": "${N8N_API_KEY}"
      }
    }
  }
}
03

Exposed tools (35)

14 read · 14 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
activate_workflowreadActivate an n8n workflow
add_nodewriteAdd a single node to an existing workflow
connect_nodesreadConnect two nodes in a workflow
create_credentialwriteCreate a new credential for workflow authentication. Use get_credential_schema first to understand required fields for the credential type.
create_tagwriteCreate a new workflow tag for organization and categorization
create_workflowwriteCreate and configure n8n workflows programmatically
create_workflow_and_activatewriteCreate and activate an n8n workflow
deactivate_workflowreadDeactivate an n8n workflow
delete_credentialdestructiveDelete a credential by ID. This will remove the credential and make it unavailable for workflows. Use with caution as this action cannot be undone.
delete_executiondestructiveDelete a workflow execution record from the n8n instance
delete_tagdestructiveRemove unused tags from the system
delete_workflowdestructiveDelete an n8n workflow
disconnect_nodesdestructiveRemove a connection between two nodes
download_workflowwriteDownload a workflow and save it to a local JSON file (avoids dumping to chat)
execute_workflowwriteTrigger immediate execution of a workflow by its ID. Starts the workflow manually regardless of its normal triggers (webhooks, schedules, etc.). Returns execution details including status, start time, and any immediate results or errors.
generate_auditreadGenerate a comprehensive security audit report for the n8n instance
get_credential_schemareadGet the schema for a specific credential type to understand what fields are required when creating credentials.
get_executionreadGet detailed information about a specific workflow execution
get_tagreadRetrieve individual tag details by ID
get_workflowreadGet an n8n workflow
get_workflow_tagsreadGet all tags associated with a specific workflow
idreadThe ID of the workflow
list_executionsreadList workflow executions with filtering and pagination support
list_tagsreadList all workflow tags with pagination support
list_workflowsreadList all workflows from your n8n instance. Returns a comprehensive list of all workflows with their IDs, names, status (active/inactive), creation dates, and basic metadata. Perfect for getting an overview of your automation landscape.
list_workflows_fullreadList all workflows with complete data including nodes and connections. Warning: high token usage.
remove_nodedestructiveRemove a node from a workflow (also removes its connections)
update_nodewriteUpdate a specific node
update_node_from_filewriteUpdate a node parameter by reading value from a file (ideal for long SQL queries, scripts, templates)
update_tagwriteModify tag names for better organization
update_workflowwriteUpdate an existing n8n workflow
update_workflow_namewriteRename a workflow without sending the full workflow object
update_workflow_settingswriteUpdate workflow settings without sending full workflow
update_workflow_tagsdestructiveAssign or remove tags from workflows
upload_workflowwriteUpload a workflow from a local JSON file to n8n (creates new workflow)
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_credential, delete_execution, delete_tag, delete_workflow, disconnect_nodes, remove_node, update_workflow_tags
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, zod, @types/jest, @types/node, dotenv, jest, jest-junit
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:487
- You can revoke access anytime by disabling the API key
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
RELEASE_SETUP.md:18
2. **Navigate to Access Tokens**: Profile → Access Tokens
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
TROUBLESHOOTING.md:167
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.0/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 0deebedc2b6efull audit observations/trust-audit/mcp-server/makafeli__n8n-workflow-builder-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-290deebedc2b6eSAFEB89first audit
06

Questions

What is the N8n Workflow Builder MCP server?

AI assistant integration for n8n workflow automation through Model Context Protocol (MCP). Connect Claude Desktop, ChatGPT, and other AI assistants to n8n for natural language workflow management.

What tools does N8n Workflow Builder expose?

35 in total: 14 read-only, 14 that write, and 7 that can delete or overwrite (delete_credential, delete_execution, delete_tag, delete_workflow, disconnect_nodes). Every one is listed on this page with its risk.

Is N8n Workflow Builder safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does N8n Workflow Builder need?

It reads N8N_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does N8n Workflow Builder run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @makafeli/n8n-workflow-builder at 0.11.0.

How current is this page?

The grade is for one exact copy of the source (0deebedc2b6e), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement