CSINT AI Security

CSINT AI Security

Inspect which data, tools and external systems your AI agents can reach before you run them.

Upload a workflow

Choose an n8n export, set a policy if you need one, then start the analysis yourself. The file is never executed.

The file is sent to the server

The analysis runs in memory only; the file is not stored and not logged. Remove real credentials and customer data before sending.

An intentionally unsafe teaching fixture. Never run it in production.

If the file must stay on your device, the local browser scan remains a separate option.

Trust Canvas

The trust relationships in the workflow. Every node and edge comes from the analysis result; nothing here is generated for display.

The trust map appears here once an analysis finishes.

Findings

Select a finding and the related nodes and edges are highlighted on the canvas.

No analysis yet. Choose a file and start the analysis.

Account and access

Sign in first. Your file is opened only in this browser.

Checking the account…

Local scan

Scan your n8n workflow JSON on this device.

The file is read once in browser memory. It is not uploaded to a server, the payment provider, or an AI service.

The scan area is available once account access is active.

The scan is static and heuristic. It cannot verify credential scope, runtime authorization, model behaviour, or controls in external systems.

Research and lab

The real CSINT work behind this tool, and the outputs it has produced.

Method and limits

What this tool does, and what it does not.

  • The analysis is static; the file itself is read.
  • The workflow is never executed.
  • Community node packages are never installed or downloaded.
  • Credential values are never read or shown; only the credential type is listed.
  • The file is not stored.
  • The raw workflow is not logged; logs carry the request id, duration, decision and finding count only.
  • Results can include false positives and false negatives.
  • Critical use still needs human review.

Service address: https://csint-workflow-trust-gate.ahmetgoker30.workers.dev