Getting it into your agent
There is no command for this one: it runs only inside a plugin, and the catalogue could not identify which plugin ships it. The source is linked below.
Wrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/impertio-studio/n8n-claude-skill-package/n8n-agents-review)<a href="https://agentmods.dev/skills/impertio-studio/n8n-claude-skill-package/n8n-agents-review"><img src="https://agentmods.dev/badge/skills/impertio-studio/n8n-claude-skill-package/n8n-agents-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/impertio-studio/n8n-claude-skill-package/n8n-agents-review"><img src="https://agentmods.dev/badge/skills/impertio-studio/n8n-claude-skill-package/n8n-agents-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00102 | $0.03096 |
| Opus 5 | $0.00051 | $0.01548 |
| Sonnet 5 | $0.00020 | $0.00619 |
| Haiku 4.5 | $0.00010 | $0.00310 |
Grade A, and why
n8n-agents-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 295 lines — stays where its author put it; the contents beside it link to each section on GitHub.
n8n Workflow & Code Review Agent
Run this checklist against ANY n8n workflow JSON, custom node code, or deployment configuration to catch errors before they reach production.
Quick Reference: Review Areas
| Area | Critical Checks | Reference |
|---|---|---|
| Workflow JSON | IConnections 3-level nesting, unique node names, required fields | methods.md |
| Connection Wiring | Type matching, correct indices, no orphan nodes | methods.md |
| Expressions | Valid variable refs, context restrictions, JMESPath order | methods.md |
| Credentials | ICredentialType completeness, authenticate method, test endpoint | methods.md |
| Node Types | INodeType interface, execute return type, property types | methods.md |
| Error Handling | Error workflow, continueOnFail, retry config | methods.md |
| Deployment | Encryption key, queue mode, volume mounts, PostgreSQL | methods.md |
| Code Node | Return format, restricted variables, sandbox limits | methods.md |
| Security | No hardcoded secrets, encryption, task runners | methods.md |
| Anti-Patterns | Consolidated list from all skill areas | anti-patterns.md |
Decision Tree: Review Workflow
START: What are you reviewing?
├─ Workflow JSON file (.json)
│ ├─ Run: Workflow JSON checks (Section 1)
│ ├─ Run: Connection Wiring checks (Section 2)
│ ├─ Run: Expression checks on all parameter values (Section 3)
│ ├─ Run: Error Handling checks (Section 6)
│ └─ Run: Anti-Pattern scan (Section 10)
│
├─ Custom node code (.node.ts)
│ ├─ Run: Node Type checks (Section 5)
│ ├─ Run: Credential checks if node uses credentials (Section 4)
│ ├─ Run: Error Handling checks (Section 6)
│ └─ Run: Anti-Pattern scan (Section 10)
│
├─ Credential definition (.credentials.ts)
│ └─ Run: Credential checks (Section 4)
│
├─ Code node content
│ ├─ Run: Code Node checks (Section 8)
│ └─ Run: Anti-Pattern scan (Section 10)
│
├─ Deployment config (docker-compose.yml / env vars)
│ ├─ Run: Deployment checks (Section 7)
│ └─ Run: Security checks (Section 9)
│
└─ Full project audit
└─ Run ALL sections sequentially
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 295 lines · 102 tokens per session scan A e9c2bc87aa75
n8n-agents-review is a skill published in the GitHub repository Impertio-Studio/n8n-Claude-Skill-Package (3 stars, last pushed 2mo ago), licensed MIT. It adds 102 tokens to every session and 3,096 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
review-work
Post-implementation gate review: run manual QA on the real surface yourself, then launch ONE gate reviewer (never a panel) to audit goal, constraints, code quality, security, missed context, and QA evidence. Use before a PR handoff or when the user explicitly asks to review completed work.
critical-code-reviewer
Rigorously review code or pull requests for correctness, security, accessibility, maintainability, tests, and edge cases. Use when users request a critical code review, want a guided walkthrough of findings, need implementer-facing feedback, or want to prepare, create, or submit a GitHub pull request review.
one-way-door
Flags irreversible decisions before commit. Use for data models, infra, auth boundaries, API contracts, event schemas, CI/CD.
map-codebase
Deep architecture report that fans out parallel inspections across different aspects of the codebase (structure, tech stack, APIs, patterns, data flow, dependencies, testing) and synthesizes findings into a comprehensive document at .turbo/codebase-map.md and .turbo/codebase-map.html. Use when the user asks to "map…
answer-reviewer-questions
For each reviewer question on a PR, recall implementation reasoning and compose a raw answer. Use when the user asks to "answer reviewer questions", "draft answers to PR questions", or "explain reviewer questions".
code-review-web
Review web application code for bugs, security issues, performance problems, and stack-specific anti-patterns. Use this skill whenever the user wants to review code, debug a production issue, investigate a build failure, audit security, or check a PR before merging. Triggers on code review, review my code, debug…