CSINT n8n Workflow Change Receipt
Public-source n8n starter-kit change review
A human-readable evidence record for one workflow change. This is not a security certificate.
Delivery status · DRAFT
Human review requiredStatic evidence is available, but no passing staging receipt is bound to this exact candidate.
Review subject
- Review ID
- wcr-0d10a827199c-733b3cbe
- Generated
- 2026-08-22T06:32:11.976Z
- Baseline
- Demo workflow
733b3cbe0f85cb61 - Candidate
- Demo workflow
0d10a827199c1031
- Customer or project
- n8n-io/self-hosted-ai-starter-kit · public commits
- Reviewer
- Codex-assisted public-source review pending human sign-off
Measured release view
Workflow nodes
Baseline3
Candidate3
Connection delta: +0 / -0
Review disposition
Blocker 0To review 1Improvements 0Context 0
Open findings
Critical0
High0
Medium1
Low1
Candidate access surface
- AI agents
- 2
- Tool nodes
- 0
- External domains
- 0
- Credential types
- 1
What changed
CR-001review
Security-relevant configuration changed: Basic LLM Chain
The node behaviour changed outside layout-only fields. Review the candidate configuration and the attached staging evidence.
Staging evidence
not-runNo candidate-bound staging receipt was supplied.
Retest evidence
not-suppliedNo prior ReleaseGuard receipt was supplied for retest comparison.
No longer open after retest: -
Still open after retest: -
New in corrected candidate: -
Human validation register
- AA-005-01 · needs-environment-evidence
Codex-assisted public-source review pending human sign-off · 2026-08-22T06:32:20.188Z
The public export has no structured output parser. Downstream consumption and the required output contract were not runtime-verified. - AA-010-02 · confirmed
Codex-assisted public-source review pending human sign-off · 2026-08-22T06:32:20.206Z
The candidate export has no errorWorkflow setting or explicit failure-handling node.
Open findings
- MEDIUM AA-005
No structured model-output validation was detected
Validate model output against a strict schema before it is parsed, stored or passed to another tool. Reject unknown fields and unsafe values. - LOW AA-010
No workflow-level failure route was detected
Add a failure route that records the error, alerts the operator and prevents partial actions from being treated as success.
n8n instance audit evidence
No n8n instance audit evidence was supplied
Production Evidence Register
- n8n-version · not-verified
Environment review pending
- · - - credential-permissions · not-verified
Environment review pending
- · - - rbac · not-verified
Environment review pending
- · - - webhook-access · not-verified
Environment review pending
- · - - community-nodes · not-verified
Environment review pending
- · - - network-egress · not-verified
Environment review pending
- · - - backup · not-verified
Environment review pending
- · - - logging · not-verified
Environment review pending
- · - - published-workflow · not-verified
Environment review pending
- · -
Customer acceptance record
not-recordedRecorded with: Customer acceptance pending
Recorded at: -
Acceptance note: -
Coverage still needed
- Production credential permissions and external-service authorization
- n8n instance security audit, installed versions, RBAC and hardening settings
- Identity of the workflow actually published to production
- AI output quality, tool-choice accuracy and model behaviour across a representative test set
Evidence boundaries
- This receipt compares exported JSON and a supplied staging record. It does not inspect production credential scope or external service authorization.
- Runtime evidence is accepted only when its canonical workflow fingerprint matches the candidate in this receipt.
- Local runtime receipts are reproducible evidence records, not cryptographically signed third-party attestations.
- A passing receipt records evidence for the tested policy and contract. It is not a penetration test, compliance certificate or security guarantee.
- Node names, node types, public domains and credential types can appear in the receipt. Prompt text, parameter values and credential values are omitted.
- Automatic findings remain review signals until a person records a manual review status. A score or clean static result is not a vulnerability verdict.
- Instance configuration, published-workflow identity, installed package versions and production permissions require separate environment evidence.