Accepted baseline
4 inactive nodes. Header authentication, a fixed tickets.example.test target, and n8n credential references are visible.
JSONSHA-256 b8fec13c99603085cc5bcf158257453b499e41a49f898b373910e606a3e5923e
Open method lab
We review synthetic or permitted public n8n workflows while keeping automated findings separate from human decisions. Customer workflows are not shared here.
The accepted baseline goes from an authenticated webhook to a fixed `.test` domain. The synthetic candidate removes authentication, reads a callback target from input, adds a credential-like literal, and gives an AI agent an email tool without a visible approval gate.
2 fingerprinted inputs · 4 synthetic pattern fixtures
4 inactive nodes. Header authentication, a fixed tickets.example.test target, and n8n credential references are visible.
JSONSHA-256 b8fec13c99603085cc5bcf158257453b499e41a49f898b373910e606a3e5923e
5 inactive nodes. Authentication is absent, the target resolves at runtime, a credential-like literal is present, and the AI-controlled email action has no visible approval gate.
JSONSHA-256 1c3ad1461b630290307d7654d833e59af35d363ca50d7ad50c6e420a8ee5b234
Automatic records are not verdicts on their own. In this case, the evidence is consolidated into three handoff blockers.
What did the tool flag?
False-positive record: No false positive was confirmed in this synthetic case. Four automated observations were consolidated into three human blockers without double-counting.
Every pattern has a small, harmless, downloadable fixture.
The same sequence is used for public cases, the free tool, and the paid handoff review.
Fingerprint baseline and candidate files with SHA-256; never separate file identity from the decision.
Record node, connection, domain, and credential-type changes without copying values into the report.
Write each rule result with evidence and limits; do not present it as a human verdict.
Validate delivery impact, mark false positives, and select no more than five blockers.
Leave unseen production facts, repair work, and the final release owner explicit.
A customer file is never required for a contribution.
Do not share customer workflows, secrets, credentials, production payloads, personal data, or private files without permission. Contributions may receive named credit after testing and source review.
Suggest a false positive, a new check, or a fixture correction. Discussion uses the existing CSINT membership and moderation system.
Sign in with an email code to comment. Your email address is not shown publicly.