Connect agents to GitHub repositories, issues, pull requests, and code search.
n8n-mcp
n8n-mcp is an MCP server for coding workflows on self-hosted. Verified from source metadata and risk-reviewed by AgentMaps.
Preview: the curated catalog plus the latest auto-checked entries. 47 newly auto-checked
What it is good for
n8n-mcp is an MCP server for coding workflows on self-hosted. Verified from source metadata and risk-reviewed by AgentMaps. This profile is auto-verified by the AgentMaps daily pipeline and passed publish review before being listed.
Use cases
- - Coding workflows that need reusable tool or agent integration.
- - Users who already run an MCP-compatible client such as Claude Code, Codex, Cursor, Cline, or a self-hosted agent.
Best for
- - Coding workflows that need reusable tool or agent integration.
- - Users who already run an MCP-compatible client such as Claude Code, Codex, Cursor, Cline, or a self-hosted agent.
Not for
- - Production use without reviewing the upstream documentation and permission scope.
- - Users who require full install, execution, and interface verification before trying a tool.
Limitations
- - Production use without reviewing the upstream documentation and permission scope.
- - Users who require full install, execution, and interface verification before trying a tool.
How to use it & what to watch
AI may help filter, explain, and draft a trial plan, but must not perform write, shell, external side effects, or production publishing before review.
What you'll see
- Start from your task and the platform you use
- Review its setup, source, and permission scope
- Try it first in an isolated or low-permission environment
- For high-risk actions, wait for a review before continuing
Where you can step in
- Adjust task/platform filters
- Add to compare
- Open the source to check
- Stop a high-risk adoption
- Add what you've learned
Actions needing approval
- Approval before writes or state mutation
- Sandbox approval before shell execution
- External network target approval
If something goes wrong
- On trial failure, fall back to source docs, alternatives, or submit what you found for review.
How to judge a trial
- Can you find a task-fit candidate within two minutes
- Can it explain why it's recommended and where it doesn't fit
- Can you see the token, write, shell, network, or local-file risks
- Can you tell 'checked the docs' apart from 'actually verified in a run'
- If a trial fails, is there a fallback or a way to take over manually
Verification evidence
Below is the result of each check — passed, partial, skipped, or not yet tested. It shows how far checking has gone, not that the capability is cleared for production use.
Source, docs, license, or package metadata exists.
Static review assigns permission and risk boundaries.
Install path can be checked, but not necessarily in your environment.
Interface or entrypoint parsed; not a production safety approval.
- Verification tier is risk-reviewed; this reflects automated evidence, not a full install or execution test.
- Static audit status is passed; the source code was reviewed for risk signals but not cloned, installed, or executed.
- Benchmark score is 65 and recommendation score is 59, based on automated evaluation.
- Trust metadata came from read-only GitHub live metadata enrichment.
Evaluation summary
Detailed checkBest for
- - Coding tasks with explicit source and risk review
Avoid when
- - You need unattended publish, production write access, or bypassed manual review.
Risk findings
- - Automated Discovery
- - Unverified Source
Verified evidence
- - L2 static benchmark status: passed
Quality findings
- mediumboundary
Permission and operating boundaries are not explicit.
Recommendation: Add boundary notes for read/write, network, shell, browser, token, and data exposure.
Evidence references
- Canonical source URL
Used only as source evidence; no source code was executed.
- Normalized source artifact
Provides object type, platform fit, risk guess, risk flags, and publish blockers.
- Static trigger prompt generation
Positive, negative, and ambiguous prompts generated from metadata; not a runtime model benchmark.
- L2 benchmark run
Benchmark status: passed.
Score breakdown
Why it scores well
- - Coding workflows that need reusable tool or agent integration.
- - Users who already run an MCP-compatible client such as Claude Code, Codex, Cursor, Cline, or a self-hosted agent.
Watch outs
- - Production use without reviewing the upstream documentation and permission scope.
- - Users who require full install, execution, and interface verification before trying a tool.
Alternatives
Fetch current library documentation and examples directly into coding agents.
Give agents controlled access to Supabase projects, schemas, SQL, and project metadata.