n8n-MCP

A MCP for Claude Desktop / Claude Code / Windsurf / Cursor to build n8n workflows for you

Protocols & Tool Integration TypeScript Grade D Listed MIT
Listing state
Listed
HVTrust
25.5/100 · Grade D
Last push
2026-06-19 · 3d ago
Recent change
Rank +1

Quick Trust Read

Verdict
Thin or incomplete trust evidence. Review carefully before production use.
25.5/100 · Grade D
Strongest Signal
Maintenance
17.9/20
Weakest Signal
Safety / Integrity
3.4/25
What Would Improve It
Add or improve OSSF Scorecard coverage so safety checks are easier to verify.
Recent Changes
2026-06-21
Rank Moved
Rank dropped 16 spots (#240 → #256)
2026-06-20
Newly Listed
First tracked at rank #240
Maintainer Checklist
Add Scorecard coverage Expose the repository to OpenSSF Scorecard checks so supply-chain posture is easier to verify.
Publish provenance Add package provenance or release attestations so users can verify where shipped artifacts came from.
86.6
Activity Score · out of 100
25.5
HVTrust Score · out of 100
#256
Global Rank · of 300
#18

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption. Grade D reflects the trust score band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Full methodology →

Signals refreshed 2026-06-22 00:01 UTC · Repo last pushed 3 days ago

Rank Trend

2026-06-20 2026-06-21

Activity & Reach

Stars
21.9k
Forks
3.5k
Last Push
2026-06-19
3 days ago
Commits (4 wk)
33
Downloads (7d)
HN mentions (30d)
Open Issues
80
Rank Change
=
was #256

Analysis

HVTrust Dimensions

25.5 / 100 · 50.0% confidence
Safety / IntegrityOSSF, provenance, signatures
3.4 / 25
Identity / ProvenanceListing and build link
10.8 / 18
TransparencyLicense and public checks
8.5 / 17
MaintenanceFreshness and commits
17.9 / 20
AdoptionStars and downloads
10.4 / 20

Activity Inputs

86.6 / 100
StarsRepository reach
26.0 / 30
FreshnessLast push recency
24.6 / 25
ActivityRecent commits
19.1 / 25
CommunityFork signal
16.5 / 20

Supply Chain Trust

Package Provenance
None
No package attestations found
OSSF Scorecard
Not available
Signed Commits
69%
of last 100 commits verified

Is n8n-MCP safe?

Public trust evidence for n8n-MCP is thin: several supply-chain signals are missing or weak. This does not mean the project is unsafe — it means an outside observer cannot easily verify the usual integrity checks. Treat with extra scrutiny.
Does n8n-MCP publish package provenance?
No published build provenance is currently detected for n8n-MCP. This is common for open-source projects but means consumers cannot independently verify that the package on the registry matches the GitHub source.
Does n8n-MCP have an OpenSSF Scorecard?
No OpenSSF Scorecard data is currently published for n8n-MCP. Maintainers can enable the Scorecard GitHub Action to get a public score; without it, automated supply-chain hygiene is harder for outsiders to verify.
Is n8n-MCP actively maintained?
Actively maintained. The repository was pushed to within the last 3 day(s).
What license does n8n-MCP use?
n8n-MCP ships under MIT. A declared, OSI-approved license is one of the transparency signals HVTrust scores.
Are n8n-MCP's commits signed?
69% of the last 100 commits to n8n-MCP are verified-signed (GPG, SSH, S/MIME, or GitHub's signing flow). Signed commits help confirm that code was authored by who the commit claims.

Not a safety endorsement. HVTracker describes what public signals show, not whether a project is safe for your use case. Run your own security review before adopting in production.

AI agent surface

Profile context only

HVTrust currently ranks supply-chain and project-integrity trust only. This public view shows a compact AI-agent surface snapshot from repo docs and manifests. These fields are descriptive context and do not affect the production HVTrust rank. An experimental local preview remains available in Score Lab →, and the policy boundary is tracked on the roadmap →

MCP Server Support
high confidence
Implemented
n8n-MCP appears to expose MCP server capabilities.
Detailed evidence is not shown in the public view.
External Service Dependencies
high confidence
2 detected
Public provider/service dependencies detected.
  • OpenAI
  • Supabase
Credential signal: API keys or service config markers documented.
Tool / Plugin Surface
high confidence
Declared
Declared plugin/integration surface detected.
  • code
  • search
  • shell
Detailed evidence is not shown in the public view.
Package Provenance Drift
N/A
No package source configured
Detailed evidence is not shown in the public view.
  • MCP signal live
  • External deps live
  • Tool / plugin surface live
  • Package provenance drift live

Maintain n8n-MCP?

HVTrust scores n8n-MCP from public signals only — we never contact maintainers first. If a signal is wrong, stale, or missing (provenance you publish, a Scorecard you run, signed releases), tell us and we'll review it. Corrections are public and tracked on GitHub.

Reputation Timeline

Listed 1Rank 1
2026-06-21
Rank Moved
Rank dropped 16 spots (#240 → #256)
2026-06-20
Newly Listed
First tracked at rank #240

Embed Badge Badge guide for maintainers →

HVTrust 25.5 Grade D
Markdown:
[![HVTrust](https://hvtracker.net/badge/n8n-mcp.svg)](https://hvtracker.net/agents/n8n-mcp)
HTML:
<a href="https://hvtracker.net/agents/n8n-mcp"><img src="https://hvtracker.net/badge/n8n-mcp.svg" alt="HVTrust"></a>

Other agents in Protocols & Tool Integration

Data sources
GitHub REST API (repo, commits, stars, forks, license)
Each agent's signals refresh once daily across 6 staggered batches. Methodology v3.2 · Raw JSON