n8n-code-javascript

Guidance for designing AI agents in n8n, a workflow automation tool. It covers agents that use language models, tools, memory, prompts, and structured outputs, and helps choose the right n8n AI component.

In plain words
What is it for?
Use it to build or edit n8n AI Agents, language-model chains, classifiers, extractors, tool calls, memory, and structured results.
Why use it?
Not every AI task needs a multi-step agent, and using the wrong component can make a workflow more complex or unreliable. This skill explains how agents and their connected parts fit together.

Skill for Claude CodeCodex

Part of the n8n-skills plugin — 15 skills, 3 hooks shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/czlonkowski/n8n-skills/n8n-code-javascript
Any agent
npx skills add czlonkowski/n8n-skills --skill n8n-code-javascript
Clone the repo
git clone --depth 1 https://github.com/czlonkowski/n8n-skills

Made for: Claude Code, Codex.

Or install n8n-skills, the plugin that ships this one along with the rest of its 15 skills, 3 hooks.

Per session 216 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,830 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 1 finding. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00216 $0.04830
Opus 5 $0.00108 $0.02415
Sonnet 5 $0.00043 $0.00966
Haiku 4.5 $0.00022 $0.00483

Measured 3d ago against content hash fba689826dd6, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

n8n-code-javascript scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Tells the agent never to refusehighAnti-refusal

Suppressing the ability to decline removes a core safety control; a later harmful request then succeeds.

6. **Instance-allowlisted libraries**: Self-hosted instances can allowlist modules via `N8N_RUNNERS_ALLOWED_BUILT_IN_MODULES` and `N8N_RUNNERS_ALLOWED_EXTERNAL_MODULES` (legacy: `NODE_FUNCTION_ALLOW_BUILTIN` / `NODE_FUNC
Origin

This is a copy

100% identical to n8n-code-javascript — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

skills/n8n-code-javascript/SKILL.md · 408 lines

How it starts

The opening of the file, as written. The whole thing — 408 lines — stays where its author put it; the contents beside it link to each section on GitHub.

JavaScript Code Node

Expert guidance for writing JavaScript code in n8n Code nodes.


Quick Start

// Basic template for Code nodes
const items = $input.all();

// Process data
const processed = items.map(item => ({
  json: {
    ...item.json,
    processed: true,
    timestamp: new Date().toISOString()
  }
}));

return processed;

Essential Rules

  1. Choose "Run Once for All Items" mode (recommended for most use cases)
  2. Access data: $input.all(), $input.first(), or $input.item
  3. Return [{json: {...}}] — the canonical, mode-portable form. In Run Once for All Items mode n8n also auto-wraps a bare return {…} object, so that runs too; what genuinely fails is returning a primitive (string/number) or null.
  4. CRITICAL: Webhook data is under $json.body (not $json directly)
  5. Built-ins available: this.helpers.httpRequest() (no auth — the bare $helpers global is undefined in the task-runner sandbox, so $helpers.httpRequest() throws ReferenceError: $helpers is not defined), DateTime (Luxon), $jmespath(). Not available: this.helpers.httpRequestWithAuthentication (deny-listed), $env (when N8N_BLOCK_ENV_ACCESS_IN_NODE=true), require() (unless allowlisted). For anything beyond a trivial unauthenticated GET (auth, pagination, retries), prefer the HTTP Request node and keep Code nodes for pure logic.
  6. Instance-allowlisted libraries: Self-hosted instances can allowlist modules via N8N_RUNNERS_ALLOWED_BUILT_IN_MODULES and N8N_RUNNERS_ALLOWED_EXTERNAL_MODULES (legacy: NODE_FUNCTION_ALLOW_BUILTIN / NODE_FUNCTION_ALLOW_EXTERNAL). If the user says their instance allows specific modules (e.g. axios, lodash, crypto), use them via require() — don't refuse. If unsure, ask or default to built-ins only.
  7. Wrong skill? If you're writing code for a Custom Code Tool attached to an AI Agent (@n8n/n8n-nodes-langchain.toolCode), stop — that node has a different contract (input via query, must return a string, no $input/$helpers). Use the n8n-code-tool skill.

Read the full file on GitHub · 408 lines

Files

What ships with it

5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 408 lines · 216 tokens per session scan C fba689826dd6

Subscribe to this mod's changes

n8n-code-javascript is a skill published in the GitHub repository czlonkowski/n8n-skills (6,164 stars, last pushed 4d ago), licensed MIT. It adds 216 tokens to every session and 4,830 once invoked, about $0.0011 per session on Opus 5. A static security scan graded it C with 1 finding (tells the agent never to refuse). It is 100% identical to n8n-code-javascript, differing in 0 lines, and is treated as a copy.

Related

Other skills, from other repositories

cordis-plugin-sofagent-inject

启动注入企业约束——四层加载链(seam: apply(ctx))——桥接 @sofagent/harness buildConstrainedSystemPrompt(sofagent 品牌插件 · 主色 #16B8F3)——DSH(DeepSeek Harness)cordis plugin。sofagent 约束层在 DeepSeek Harness 生态的插件形态。.

KongFangXun/sofagent · 86 tokens

n8n-structured-extraction

Extract or classify structured data from text/documents with an LLM in n8n using a real JSON schema. Use when a workflow needs structured fields out of unstructured input (invoice/contract/email extraction, classification), when deciding between an AI Agent and a dedicated extractor node, or when LLM JSON output is…

neurawork-git/n8n-autopilot · 77 tokens

dspy-prompt-optimizer

Tunes prompts iteratively using reflection and success metrics. Use for: optimize this prompt, dspy tune, improve prompt with reflection, self-refine-loop.

Stijnman/grok-custom-skills · 39 tokens

add-prompt

Scaffold a new MCP prompt template. Use when the user asks to add a prompt, create a reusable message template, or define a prompt for LLM interactions.

cyanheads/workflows-mcp-server · 37 tokens

context-fundamentals

This skill should be used to explain or reason about the foundational concepts of context engineering: what context is, the anatomy of a context window, how attention mechanics work, the U-shaped attention curve, why context quality matters more than quantity, and the mental models needed to interpret every other…

muratcankoylan/Agent-Skills-for-Context-Engineering · 125 tokens

enhance-prompt

Transforms vague UI ideas into polished, Stitch-optimized prompts. Enhances specificity, adds UI/UX keywords, injects design system context, and structures output for better generation results.

google-labs-code/stitch-skills · 41 tokens