N8n Workflow BuilderCAUTION
AI-powered n8n workflow automation through natural language. MCP server enabling Claude AI & Cursor IDE to create, manage, and monitor workflows via Model Context Protocol. Multi-instance support, 17 tools, comprehensive docs. Build workflows conversationally without manual JSON editing.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
AI-Powered Workflow Automation Through Natural Language
Build, manage, and monitor n8n workflows using Claude AI and Cursor IDE via the Model Context Protocol
[](https://salacoste.github.io/mcp-n8n-workflow-builder/) [](https://www.npmjs.com/package/@kernel.salacoste/n8n-workflow-builder) [](https://www.npmjs.com/package/@kernel.salacoste/n8n-workflow-builder) [](https://opensource.org/licenses/MIT)
Features • Quick Start • Documentation • Examples • API Reference
🎯 What is This?
n8n Workflow Builder MCP Server transforms workflow automation by enabling you to create and manage n8n workflows through conversational AI. No more manual JSON editing or complex UI navigation—just describe what you need in natural language, and let AI build it for you.
The Problem It Solves
- ❌ Manual workflow building is time-consuming and error-prone
- ❌ Complex JSON editing requires deep technical knowledge
- ❌ Switching between IDE and n8n UI breaks your development flow
- ❌ Managing multiple n8n environments (dev, staging, prod) is tedious
The Solution
- ✅ Build workflows conversationally using Claude AI or Cursor IDE
- ✅ Natural language interface - describe workflo
f5889b4aa908OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add n8n-workflow-builder --env N8N_API_KEY=${N8N_API_KEY} -- npx -y @kernel.salacoste/[email protected]{
"mcpServers": {
"n8n-workflow-builder": {
"command": "npx",
"args": [
"-y",
"@kernel.salacoste/[email protected]"
],
"env": {
"N8N_API_KEY": "${N8N_API_KEY}"
}
}
}
}Exposed tools (13)
12 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
api_url | read | URL of the external API to call |
filter_condition | read | JavaScript condition to filter items (e.g. item.status === |
filter_path | read | JSON path to the array in the API response |
id | read | The ID of the workflow |
interval_value | read | Polling interval in minutes (1-60) |
processing_code | read | JavaScript code to process the API response |
response_message | read | Message to include in the response |
sample_data | read | Sample JSON data to transform |
schedule_expression | write | Cron expression for schedule (e.g. */5 * * * * for every 5 minutes) |
transformation_code | read | JavaScript code for data transformation |
webhook_path | read | Path for the webhook (e.g. |
workflow_message | read | Message to include in the workflow execution |
workflow_name | read | Name of the workflow |
Trust audit
CAUTIONgrade D · trust 69/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
password: 'secure_password_here'
const API_KEY = 'n8n_api_1234567890abcdef';
accessToken: "xoxb-your-token-here"
accessToken: "xoxb-your-bot-token"
accessToken: 'xoxb-1234567890-1234567890-ABC123XYZ789'
accessToken: 'xoxb-1234567890-1234567890-ABC123XYZ789'
echo '<div style="background: #ff6b6b; color: white; padding: 10px; text-align: center; position: fixed; top: 0; width: 100%; z-index: 9999;">⚠️ Preview Deployment - PR #${{ github.event.pull_request..config.json.example
.config.test.json
.eslintignore
.pages
path.join(__dirname, '../../.config.json'), // Relative to build/config/configLoader.js
path.join(__dirname, '../../../.config.json') // In case of different build structure
path.join(__dirname, '../../.env'), // Relative to build/config/configLoader.js
import { ConfigLoader } from '../../config/configLoader';import { N8NInstance } from '../../types/config';'transport_type': 'beacon'
@modelcontextprotocol/sdk, axios, cors, dotenv, express, node-fetch, @types/cors, @types/express
- No evidence of POST /credentials/test or similar endpoint
**Endpoint:** POST /credentials/test (or similar)
- API keys grant full access to your n8n instance
3. Regenerate with full permissions if needed
- Full access to all workflows in n8n instance
- GET - Read credential by ID (2.6.2) - Security informative ✅
**Prerequisites:** Access to n8n instance with API key
Gates applied: no_behavioural_pass.
f5889b4aa908full audit observations/trust-audit/mcp-server/salacoste__n8n-workflow-builder-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | f5889b4aa908 | CAUTION | D | 69 | first audit |
Questions
What is the N8n Workflow Builder MCP server?
AI-powered n8n workflow automation through natural language. MCP server enabling Claude AI & Cursor IDE to create, manage, and monitor workflows via Model Context Protocol. Multi-instance support, 17 tools, comprehensive docs. Build workflows conversationally without manual JSON editing.
What tools does N8n Workflow Builder expose?
13 in total: 12 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is N8n Workflow Builder safe to connect to an agent?
With care. The audit graded it D (69/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does N8n Workflow Builder need?
It reads N8N_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does N8n Workflow Builder run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @kernel.salacoste/n8n-workflow-builder at 0.9.3.
How current is this page?
The grade is for one exact copy of the source (f5889b4aa908), read on 2026-10-06. The repository is watched and re-audited when it changes.