Atlas / MCP servers / salacoste / N8n Workflow Builder

N8n Workflow BuilderCAUTION

mcp/salacoste/n8n-workflow-builder-2

AI-powered n8n workflow automation through natural language. MCP server enabling Claude AI & Cursor IDE to create, manage, and monitor workflows via Model Context Protocol. Multi-instance support, 17 tools, comprehensive docs. Build workflows conversationally without manual JSON editing.

Verdict
CAUTION
Grade
D
Trust score
69 /100
Exposed tools
13 12r · 1w · 0d
Transport
stdio
License
MIT
Stars
234
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AI-Powered Workflow Automation Through Natural Language

Build, manage, and monitor n8n workflows using Claude AI and Cursor IDE via the Model Context Protocol

[](https://salacoste.github.io/mcp-n8n-workflow-builder/) [](https://www.npmjs.com/package/@kernel.salacoste/n8n-workflow-builder) [](https://www.npmjs.com/package/@kernel.salacoste/n8n-workflow-builder) [](https://opensource.org/licenses/MIT)

Features • Quick Start • Documentation • Examples • API Reference

🎯 What is This?

n8n Workflow Builder MCP Server transforms workflow automation by enabling you to create and manage n8n workflows through conversational AI. No more manual JSON editing or complex UI navigation—just describe what you need in natural language, and let AI build it for you.

The Problem It Solves

  • ❌ Manual workflow building is time-consuming and error-prone
  • ❌ Complex JSON editing requires deep technical knowledge
  • ❌ Switching between IDE and n8n UI breaks your development flow
  • ❌ Managing multiple n8n environments (dev, staging, prod) is tedious

The Solution

  • ✅ Build workflows conversationally using Claude AI or Cursor IDE
  • ✅ Natural language interface - describe workflo
Read from source at commit f5889b4aa908OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add n8n-workflow-builder --env N8N_API_KEY=${N8N_API_KEY} -- npx -y @kernel.salacoste/[email protected]
claude-desktop
{
  "mcpServers": {
    "n8n-workflow-builder": {
      "command": "npx",
      "args": [
        "-y",
        "@kernel.salacoste/[email protected]"
      ],
      "env": {
        "N8N_API_KEY": "${N8N_API_KEY}"
      }
    }
  }
}
03

Exposed tools (13)

12 read · 1 write · 0 destructive.

ToolRiskDescription
api_urlreadURL of the external API to call
filter_conditionreadJavaScript condition to filter items (e.g. item.status ===
filter_pathreadJSON path to the array in the API response
idreadThe ID of the workflow
interval_valuereadPolling interval in minutes (1-60)
processing_codereadJavaScript code to process the API response
response_messagereadMessage to include in the response
sample_datareadSample JSON data to transform
schedule_expressionwriteCron expression for schedule (e.g. */5 * * * * for every 5 minutes)
transformation_codereadJavaScript code for data transformation
webhook_pathreadPath for the webhook (e.g.
workflow_messagereadMessage to include in the workflow execution
workflow_namereadName of the workflow
04

Trust audit

CAUTIONgrade D · trust 69/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/api/credentials-api.md:460
password: 'secure_password_here'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/n8n-api-docs/02-AUTHENTICATION.md:462
const API_KEY = 'n8n_api_1234567890abcdef';
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/features/credentials-security.md:187
accessToken: "xoxb-your-token-here"
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/features/credentials-security.md:512
accessToken: "xoxb-your-bot-token"
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/n8n-api-docs/30-CREDENTIALS-API.md:431
accessToken: 'xoxb-1234567890-1234567890-ABC123XYZ789'
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/n8n-api-docs/30-CREDENTIALS-API.md:1190
accessToken: 'xoxb-1234567890-1234567890-ABC123XYZ789'
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
docs/stories/epic-8/story-8.3-cicd-pipeline-deployment.md:532
echo '<div style="background: #ff6b6b; color: white; padding: 10px; text-align: center; position: fixed; top: 0; width: 100%; z-index: 9999;">⚠️ Preview Deployment - PR #${{ github.event.pull_request.
LOWInventory / provenance · inv.hidden_file · CWE-1104
.config.json.example
.config.json.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.config.test.json
.config.test.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintignore
.eslintignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.pages
.pages
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/config/configLoader.ts:37
path.join(__dirname, '../../.config.json'), // Relative to build/config/configLoader.js
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/config/configLoader.ts:38
path.join(__dirname, '../../../.config.json') // In case of different build structure
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/config/configLoader.ts:117
path.join(__dirname, '../../.env'), // Relative to build/config/configLoader.js
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/__tests__/environmentManager.test.ts:2
import { ConfigLoader } from '../../config/configLoader';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/__tests__/environmentManager.test.ts:3
import { N8NInstance } from '../../types/config';
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
docs/assets/javascripts/extra.js:51
'transport_type': 'beacon'
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, cors, dotenv, express, node-fetch, @types/cors, @types/express
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/EPIC-2-CORRECTION-REPORT.md:18
- No evidence of POST /credentials/test or similar endpoint
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/EPIC-2-CORRECTION-REPORT.md:154
**Endpoint:** POST /credentials/test (or similar)
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/getting-started/installation/configuration.md:98
- API keys grant full access to your n8n instance
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/troubleshooting/error-reference.md:191
3. Regenerate with full permissions if needed
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/troubleshooting/faq.md:682
- Full access to all workflows in n8n instance
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/EPIC-2-COMPLETION-SUMMARY.md:183
- GET - Read credential by ID (2.6.2) - Security informative ✅
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/RELEASE-0.9.1-GUIDE.md:170
**Prerequisites:** Access to n8n instance with API key
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha f5889b4aa908full audit observations/trust-audit/mcp-server/salacoste__n8n-workflow-builder-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06f5889b4aa908CAUTIOND69first audit
06

Questions

What is the N8n Workflow Builder MCP server?

AI-powered n8n workflow automation through natural language. MCP server enabling Claude AI & Cursor IDE to create, manage, and monitor workflows via Model Context Protocol. Multi-instance support, 17 tools, comprehensive docs. Build workflows conversationally without manual JSON editing.

What tools does N8n Workflow Builder expose?

13 in total: 12 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is N8n Workflow Builder safe to connect to an agent?

With care. The audit graded it D (69/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does N8n Workflow Builder need?

It reads N8N_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does N8n Workflow Builder run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @kernel.salacoste/n8n-workflow-builder at 0.9.3.

How current is this page?

The grade is for one exact copy of the source (f5889b4aa908), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement