CSINT n8n Workflow Change Receipt

Change C: The agent iteration limit goes from 10 to 100

A human-readable evidence record for one workflow change. This is not a security certificate.

Delivery status, CLIENT-READY

Human validation complete. Release decision required

Static evidence is available, but no passing staging receipt is bound to this exact candidate.

Review subject

Review ID
wcr-de8a24719838-32597b9b
Generated
2026-09-30T12:00:00.000Z
Baseline
Scanner Alert Triage
32597b9b3c204f64
Candidate
Scanner Alert Triage
de8a24719838b955
Customer or project
Public MIT template scanner-inc/agents, not a client
Reviewer
Ahmet Göker

Measured release view

Workflow nodes

Baseline7
Candidate7

Connection delta: +0 / -0

Review disposition

Blocker 0To review 1Improvements 0Context 0

Open findings

Critical1
High3
Medium2
Low1

Candidate access surface

AI agents
1
Tool nodes
3
External domains
3
Credential types
4

What changed

CR-001review

An agent limit was loosened: Alert Triage Agent

maxIterations 10 (n8n default) to 100. One input can now drive more model and tool calls before the run stops, which raises cost and the number of actions a manipulated input can trigger. Confirm the new value is intended and that a cost or rate limit still applies.

Staging evidence

not-run

No candidate-bound staging receipt was supplied.

Retest evidence

not-supplied

No prior ReleaseGuard receipt was supplied for retest comparison.
No longer open after retest: -
Still open after retest: -
New in corrected candidate: -

Human validation register

  1. TG-100-01, likely
    Ahmet Göker, 2026-09-30T13:00:00.000Z
    The path from Webhook through Alert Triage Agent to Send a message is real: the whole alert JSON goes into the prompt, and alert fields can hold text an attacker controls, such as a user or resource name. The webhook uses header auth and the end step posts to one fixed Slack channel, so the worst case is a wrong or misleading triage note. I would rate it medium for this template, not critical.
  2. AA-003-02, confirmed
    Ahmet Göker, 2026-09-30T13:00:00.000Z
    Confirmed. The prompt is built with JSON.stringify of the whole request item, with no step that limits size or strips free text first. For a triage agent this is by design, which is why the tools it can call should stay read-only.
  3. AA-004-03, confirmed
    Ahmet Göker, 2026-09-30T13:00:00.000Z
    Confirmed and by design: the model output is posted to Slack with no approval step. Posting the triage note is the purpose of the workflow. Approval is not needed here, but it is needed before any step that writes somewhere else.
  4. AA-006-04, needs-environment-evidence
    Ahmet Göker, 2026-09-30T13:00:00.000Z
    No rate or cost limit is visible in the export. The alerts come from the detection platform behind header auth, so a limit may exist on the sending side; the export cannot show it. Ask the team where the alert rate is capped.
  5. AA-005-05, confirmed
    Ahmet Göker, 2026-09-30T13:00:00.000Z
    Confirmed. The Slack text is the model output with only a cut at the first siren emoji. No schema check runs on it.
  6. AA-008-06, confirmed
    Ahmet Göker, 2026-09-30T13:00:00.000Z
    Confirmed. The HTTP tools set no timeout and no retry, so a slow lookup API holds the whole agent run.
  7. AA-010-07, confirmed
    Ahmet Göker, 2026-09-30T13:00:00.000Z
    Confirmed, low. No error workflow is set, so a failed triage run goes unnoticed unless someone looks at the execution list.

Open findings from this change

This change introduces no open medium, high or critical finding.

Already present before this change

These findings match the baseline as well. They stay listed so nothing is hidden, but they do not decide this change on their own.

  1. CRITICAL TG-100
    A prompt-injection source can steer a privileged action through the AI agent
    Break the chain: validate and constrain the input before the model, and require an explicit human approval step before the privileged action. Treat all trigger content as data, never as instructions.
  2. HIGH AA-003
    Untrusted input can reach a model without a visible validation boundary
    Add a deterministic validation step before the model. Enforce size, type and allowlist rules, separate instructions from data, and test direct and indirect prompt injection cases.
  3. HIGH AA-004
    A model can reach an external write action without an approval step
    Require explicit human approval for messages, writes, deletions, purchases, account changes and other high-impact actions. Use least-privilege credentials for the final action.
  4. HIGH AA-006
    No rate or cost boundary was detected before model usage
    Add per-user and per-origin limits, a maximum input size, a model-call budget, timeouts, and a bounded retry policy.
  5. MEDIUM AA-005
    No structured model-output validation was detected
    Validate model output against a strict schema before it is parsed, stored or passed to another tool. Reject unknown fields and unsafe values.
  6. MEDIUM AA-008
    Outbound requests do not show an explicit timeout or retry policy
    Set short timeouts and bounded retries with backoff. Make write actions idempotent so a retry cannot publish or charge twice.
  7. LOW AA-010
    No workflow-level failure route was detected
    Add a failure route that records the error, alerts the operator and prevents partial actions from being treated as success.

n8n instance audit evidence

No n8n instance audit evidence was supplied

Production Evidence Register

No production environment check has been recorded.

Customer acceptance record

not-recorded

Recorded with: Customer acceptance pending
Recorded at: -
Acceptance note: -

Coverage still needed

Evidence boundaries