CSINT n8n Workflow Change Receipt
Change B: Optional Jira ticket creation, shipped disabled
A human-readable evidence record for one workflow change. This is not a security certificate.
Delivery status, CLIENT-READY
Human validation complete. Release decision requiredStatic evidence is available, but no passing staging receipt is bound to this exact candidate.
Review subject
- Review ID
- wcr-05bb7fab494f-2fc05b8d
- Generated
- 2026-09-30T12:00:00.000Z
- Baseline
- Scanner Alert Triage
2fc05b8d1ae62bb8 - Candidate
- Scanner Alert Triage
05bb7fab494f8aff
- Customer or project
- Public MIT template scanner-inc/agents, not a client
- Reviewer
- Ahmet Göker
Measured release view
Workflow nodes
Baseline7
Candidate9
Connection delta: +4 / -1
Review disposition
Blocker 0To review 3Improvements 0Context 5
Open findings
Critical1
High3
Medium2
Low1
Candidate access surface
- AI agents
- 1
- Tool nodes
- 3
- External domains
- 3
- Credential types
- 4
What changed
CR-001review
A write path was added but ships disabled: Create Jira Issue
The step can write to an external system. It is disabled in this export, so one toggle in the n8n editor makes it live without a new review. The gate in front of it (Create Jira?) decides on model output from Alert Triage Agent, so the model would choose when it writes.
CR-002review
Security-relevant configuration changed: Alert Triage Agent
The node behaviour changed outside layout-only fields. Review the candidate configuration and the attached staging evidence.
CR-003review
Security-relevant configuration changed: Send a message
The node behaviour changed outside layout-only fields. Review the candidate configuration and the attached staging evidence.
CR-004context
An existing finding now covers different steps: A prompt-injection source can steer a privileged action through the AI agent
The same rule matched before this change with the same start and end, or on the same steps. Only the steps in between or the listed nodes changed, so it is listed with the findings that were already present.
CR-005context
An existing finding now covers different steps: A model can reach an external write action without an approval step
The same rule matched before this change with the same start and end, or on the same steps. Only the steps in between or the listed nodes changed, so it is listed with the findings that were already present.
CR-006context
A workflow step was added: Create Jira Issue
The candidate introduces n8n-nodes-base.jira. Review its inputs, permissions and failure behaviour.
CR-007context
A workflow step was added: Create Jira?
The candidate introduces n8n-nodes-base.if. Review its inputs, permissions and failure behaviour.
CR-008context
A workflow step was added: Split Output
The candidate introduces n8n-nodes-base.code. Review its inputs, permissions and failure behaviour.
Staging evidence
not-runNo candidate-bound staging receipt was supplied.
Retest evidence
not-suppliedNo prior ReleaseGuard receipt was supplied for retest comparison.
No longer open after retest: -
Still open after retest: -
New in corrected candidate: -
Human validation register
- TG-100-01, likely
Ahmet Göker, 2026-09-30T13:00:00.000Z
The path from Webhook through Alert Triage Agent to Send a message is real: the whole alert JSON goes into the prompt, and alert fields can hold text an attacker controls, such as a user or resource name. The webhook uses header auth and the end step posts to one fixed Slack channel, so the worst case is a wrong or misleading triage note. I would rate it medium for this template, not critical. - AA-003-02, confirmed
Ahmet Göker, 2026-09-30T13:00:00.000Z
Confirmed. The prompt is built with JSON.stringify of the whole request item, with no step that limits size or strips free text first. For a triage agent this is by design, which is why the tools it can call should stay read-only. - AA-004-03, confirmed
Ahmet Göker, 2026-09-30T13:00:00.000Z
Confirmed and by design: the model output is posted to Slack with no approval step. Posting the triage note is the purpose of the workflow. Approval is not needed here, but it is needed before any step that writes somewhere else. - AA-006-04, needs-environment-evidence
Ahmet Göker, 2026-09-30T13:00:00.000Z
No rate or cost limit is visible in the export. The alerts come from the detection platform behind header auth, so a limit may exist on the sending side; the export cannot show it. Ask the team where the alert rate is capped. - AA-005-05, likely
Ahmet Göker, 2026-09-30T13:00:00.000Z
Partly covered now. Split Output parses the Jira block and requires create to be true, but it checks no field against a schema, and the Slack text is not checked at all. Keep the finding open until labels, priority and summary are checked. - AA-008-06, confirmed
Ahmet Göker, 2026-09-30T13:00:00.000Z
Confirmed. The HTTP tools set no timeout and no retry, so a slow lookup API holds the whole agent run. - AA-010-07, confirmed
Ahmet Göker, 2026-09-30T13:00:00.000Z
Confirmed, low. No error workflow is set, so a failed triage run goes unnoticed unless someone looks at the execution list.
Open findings from this change
This change introduces no open medium, high or critical finding.
Already present before this change
These findings match the baseline as well. They stay listed so nothing is hidden, but they do not decide this change on their own.
- CRITICAL TG-100
A prompt-injection source can steer a privileged action through the AI agent
Break the chain: validate and constrain the input before the model, and require an explicit human approval step before the privileged action. Treat all trigger content as data, never as instructions. - HIGH AA-003
Untrusted input can reach a model without a visible validation boundary
Add a deterministic validation step before the model. Enforce size, type and allowlist rules, separate instructions from data, and test direct and indirect prompt injection cases. - HIGH AA-004
A model can reach an external write action without an approval step
Require explicit human approval for messages, writes, deletions, purchases, account changes and other high-impact actions. Use least-privilege credentials for the final action. - HIGH AA-006
No rate or cost boundary was detected before model usage
Add per-user and per-origin limits, a maximum input size, a model-call budget, timeouts, and a bounded retry policy. - MEDIUM AA-005
No structured model-output validation was detected
Validate model output against a strict schema before it is parsed, stored or passed to another tool. Reject unknown fields and unsafe values. - MEDIUM AA-008
Outbound requests do not show an explicit timeout or retry policy
Set short timeouts and bounded retries with backoff. Make write actions idempotent so a retry cannot publish or charge twice. - LOW AA-010
No workflow-level failure route was detected
Add a failure route that records the error, alerts the operator and prevents partial actions from being treated as success.
n8n instance audit evidence
No n8n instance audit evidence was supplied
Production Evidence Register
No production environment check has been recorded.
Customer acceptance record
not-recordedRecorded with: Customer acceptance pending
Recorded at: -
Acceptance note: -
Coverage still needed
- Production credential permissions and external-service authorization
- n8n instance security audit, installed versions, RBAC and hardening settings
- Identity of the workflow actually published to production
- AI output quality, tool-choice accuracy and model behaviour across a representative test set
Evidence boundaries
- This receipt compares exported JSON and a supplied staging record. It does not inspect production credential scope or external service authorization.
- Runtime evidence is accepted only when its canonical workflow fingerprint matches the candidate in this receipt.
- Local runtime receipts are reproducible evidence records, not cryptographically signed third-party attestations.
- A passing receipt records evidence for the tested policy and contract. It is not a penetration test, compliance certificate or security guarantee.
- Node names, node types, public domains and credential types can appear in the receipt. Prompt text, parameter values and credential values are omitted.
- Automatic findings remain review signals until a person records a manual review status. A score or clean static result is not a vulnerability verdict.
- Instance configuration, published-workflow identity, installed package versions and production permissions require separate environment evidence.