leadup-n8n-workflow-builder — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited leadup-n8n-workflow-builder (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Design an n8n workflow LeadUp can paste into the editor: trigger, nodes, data mapping, credentials (as placeholders), error handling, manual approval points, and a test plan. Output works for cloud n8n or self-hosted on leadup-server.
Use when the user wants an n8n graph designed. Do not trigger for the WhatsApp template / opt-in design only (use leadup-whatsapp-automation-planner), AI feature design (use leadup-ai-feature-planner), or the broader funnel (use leadup-lead-funnel-builder).
Trigger phrases: "n8n workflow", "automation workflow", "build workflow", "webhook automation", "connect APIs", "workflow builder", "n8n graph", "automate this".
CRM sync, invoice creation, AI-summary on event, etc.).
Anthropic API, OpenAI, n8n itself).
Ask at most 2 clarifying questions if the trigger or systems are unclear.
references/n8n-workflow-framework.md — node patterns, errorhandling, credential rules.
assets/n8n-workflow.template.md — output shape (workflow as textgraph).
leadup-api-research-builder — for each external API.leadup-whatsapp-automation-planner — for the WhatsApp side.leadup-ai-feature-planner — if an LLM call lives inside theworkflow.
leadup-pii-risk-reviewer — if customer data passes through.leadup-security-review — for payments / sensitive scopes.leadup-status-updater — to record the new automation in projectmemory.
({{n8n_creds.crm_token}}); never paste real values.
dead-letter Google Sheet), idempotency keys.
for sensitive actions (refund, mass email, destructive).
recreate in the n8n editor without ambiguity.
One Markdown plan with these sections, in this order:
sample payload.
output.
lives (vault / env / n8n credentials store).
idempotency).
recreate.
Use placeholders.
payment fields; truncate IDs.
manual approval step or restrict to a verified caller.
(Razorpay HMAC, Stripe signature, WhatsApp BSP signature, GitHub X-Hub-Signature).
side-effect nodes.
consent gate where relevant.
leadup-api-research-builder andleadup-ai-feature-planner.
webhook public URL via Coolify, queue mode for high volume.
a dedicated worker.
hash; route through leadup-ai-feature-planner for cost ledger.
early to normalize; document the canonical shape.
→ approval; else → continue).
leadup-whatsapp-automation-planner)leadup-ai-feature-planner)leadup-api-research-builder)template → Google Sheet log", return an ordered node list, credential placeholders, signature-verified webhook trigger, idempotency key on submission id, retry + dead-letter on downstream failures, fixtures with expected outputs, and a text workflow diagram.
conditions", return a plan with HMAC signature verification, manual-approval node for any refund, audit-log node, and a hand-off to leadup-security-review and leadup-pii-risk-reviewer.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.