C1 Identity & least privilege
Minimal 0.23 / 1.00
An n8n agent acts with whatever stored credentials the workflow author attaches to each tool node, and n8n's built-in OAuth credentials request very broad scopes by default (full Gmail mailbox access, Slack scopes that include profile and user-group writes). Before a run, n8n checks that the workflow's project is allowed to use every credential it references, so a workflow cannot borrow another project's credentials. Nothing narrows authority per request or per end user: everyone who chats with or triggers an agent acts with the author's credentials. A hijacked agent therefore holds full-account access to every connected service.
C2 Approval gates
Minimal 0.30 / 1.00
By default the AI Agent node executes every tool call the model makes with no human approval: tool calls are routed straight to the tool node. n8n ships a solid opt-in Human-in-the-Loop layer: an author can place a Slack, email, Telegram or chat 'Human review' node in front of chosen tools, and the approver is shown the exact tool name and parameters, the approved arguments are exactly what runs, and rejection is fed back to the agent. But it only covers the tools the author remembers to wire through it, and the actions it protects (sending email, posting messages, writing to databases, arbitrary HTTP calls) are mostly irreversible.
C3 Tool & action scoping
Minimal 0.45 / 1.00
n8n narrows tools well in one respect: an author turns a regular node into a tool and chooses which parameters the model may fill (via $fromAI placeholders, which get typed schemas), so a Gmail tool can have a fixed recipient. File nodes are confined to ~/.n8n-files with real-path and symlink checks, and Execute Command is excluded by default. But generic tools stay generic: the HTTP Request tool can be given a model-chosen URL, SSRF protection is off by default, database tools accept raw model-written SQL, and the MCP client tool exposes every server tool by default. Misused tools act directly on production systems.
C4 Code-execution isolation
Minimal 0.33 / 1.00
Code written in Code nodes and the Code tool (the agent passes it inputs) runs in n8n's task runner. By default the runner is a child process of n8n, with a scrubbed environment, Node's vm module, frozen globals and code-generation-from-strings disabled. Node's vm module is not a security boundary, and the child runs as the same OS user as n8n, so an escape can read ~/.n8n/config (the credential encryption key) and the database, which means every stored credential. A hidden legacy LangChain Code node still runs code in-process through vm2. A separate runner container is available but opt-in.
C5 Untrusted input blast radius
Minimal 0.15 / 1.00
Agents commonly read attacker-reachable content (webhook and chat input, inbound email triggers, web pages and API responses returned by tools), and those tool results go into the model's context with no marking or provenance. Nothing in the agent loop limits what a hijacked agent can do after reading untrusted content. The opt-in Guardrails node can screen text for jailbreaks or PII, but it is a detector the author has to place by hand. In the common setup (email or chat in, credentials to mail and other services, HTTP or send tools out) a successful injection can leak data and take irreversible actions with no human involved.
C6 Memory, context & configuration integrity
Minimal 0.25 / 1.00
Conversation memory (Simple, Postgres, Redis, MongoDB, Zep and others) stores past turns, including what the agent said after reading injected content, and replays them as chat history in later turns, where they can steer tool use. Reads and writes are recorded in execution data, but nothing validates, tags or expires what is stored. Sessions are separated by a session ID that, for chat triggers, comes from the request body rather than from an authenticated user. There are no auto-loaded repo instruction files, which removes a common poisoning path.
C7 Third-party extensions
Minimal 0.40 / 1.00
Community nodes are third-party npm packages an instance owner or admin can install from the UI, and the feature is on by default. Installs skip npm lifecycle scripts, resolve to an exact version that is recorded, and n8n-vetted packages are checked against a known checksum. Unverified packages are allowed by default with no integrity check, and installed nodes load into the main n8n process, where they can reach every credential the instance holds. MCP client tools connect only to remote servers, so no third-party code runs locally that way.
C8 Secrets & sensitive-data protection
Minimal 0.40 / 1.00
Credentials are encrypted at rest in n8n's database and injected by node code at execution time, so the model never sees them, and the task runner gets a scrubbed environment. The encryption key sits next to the data in ~/.n8n/config, readable by the n8n user. Execution records store full prompts, tool inputs and outputs unredacted by default, and anonymous telemetry is on by default (content-free on self-hosted). Credentials are long-lived and broad, and by default may be sent to any domain from the HTTP Request tool.
C9 Audit & traceability
Moderate 0.53 / 1.00
Every execution is saved by default with each node run, including each agent tool call, its inputs and outputs, timestamps, and HITL approvals or denials, in n8n's database, and an event log is written by default. That gives a structured, replayable trajectory. Records don't identify the requesting end user, aren't tamper-evident, can be switched off per workflow, and are written when the execution finishes rather than as each step happens, so a crash can lose them.
C10 Limits & kill switch
Minimal 0.40 / 1.00
The AI Agent node stops after 10 tool iterations by default, and stopping an execution signals the agent to cancel. Code tasks time out after 5 minutes. There is no token or cost cap, the overall execution timeout is unlimited by default, production concurrency is unlimited, and sub-agents get their own fresh iteration budget. Triggers can start a workflow again and again with no rate limit.