Back to Templates

Automated weekly security audit reports with Gmail delivery

Created by

Created by: Matthieu || neon8n
Matthieu

Last update

Last update 3 months ago

Categories

Share


πŸ”’ N8N Security Audit Report - Automated Weekly Email

🎯 What does this workflow do?

This workflow automatically generates and emails a comprehensive security audit report for your N8N instance every week. It identifies potential security risks related to:

  • Credentials πŸ”‘ : Exposed or insecure credentials
  • Nodes 🧩 : Sensitive nodes (Code, HTTP Request, SSH, FTP, etc.)
  • Instance settings 🏒 : Global security configuration
  • Community nodes πŸ“¦ : Third-party nodes that may pose risks

The report includes direct links to affected workflows, execution statuses, and actionable recommendations.


✨ Key Features

πŸ“Š Smart Risk Assessment

  • Calculates overall risk level: 🟩 Low / 🟧 Moderate / πŸŸ₯ High
  • Tracks unique credentials (not just total occurrences)
  • Provides detailed breakdown by node type

πŸ”— Direct Workflow Links

  • Clickable links to each workflow mentioned
  • Shows last execution status (🟒 success / πŸ”΄ failed)
  • Displays execution timestamps

🌍 Bilingual Support

  • Full support for French and English
  • Switch language with a single variable

πŸ“§ Beautiful HTML Email

  • Clean, professional formatting
  • Color-coded risk levels
  • Emoji icons for easy scanning

πŸš€ Quick Setup (5 minutes)

1️⃣ Configure Credentials

  • N8N API: Generate an API key in your N8N settings
  • Gmail OAuth2: Set up OAuth2 for Gmail sending

2️⃣ Set Your Variables

Edit the "Set Config Variables" node:

{
  "email_to": "[email protected]",
  "project_name": "My-N8N-Project",
  "server_url": "https://n8n.yourdomain.com",  // NO trailing slash!
  "Language": "EN"  // or "FR"
}

3️⃣ Test & Activate

  • Click "Execute Workflow" to test
  • Check your email inbox
  • Activate for weekly automation

πŸ“§ Example Report Output

Subject: πŸ”’ Audit Report My-Project – Risk 🟧 Moderate

Content:

πŸ“Š Summary
β€’ Credentials involved: 8 (5 unique)
β€’ Nodes involved: 12
  - πŸ’» code: 4
  - 🌐 httpRequest: 3
  - πŸ” ssh: 2
β€’ Community nodes: 1
β€’ Overall risk level: 🟧 Moderate

πŸ” Credentials Risk Report
πŸ”Ή Credentials with full access
- πŸ”‘ My AWS Credentials
- πŸ”‘ Database Admin

πŸ“‹ Workflow: Data Processing Pipeline 🟒 (25-10-2024 06:15 β†’ 06:16)
  - πŸ’» Process Data
  - 🌐 API Call

🧩 Nodes Risk Report
[...detailed node analysis...]

🎨 Customization Options

Change Schedule

Modify the "Schedule Trigger" node to run:

  • Daily at 8 AM
  • Monthly on the 1st
  • Custom cron expression

Add Recipients

Add multiple emails in the Gmail node's toList parameter

Adjust Risk Thresholds

Edit the JavaScript in "Format Audit Report" nodes to customize when risk levels change

Use Different Email Service

Replace Gmail node with:

  • SMTP
  • Microsoft Outlook
  • SendGrid
  • Any email service N8N supports

πŸ’‘ Use Cases

βœ… Compliance Monitoring: Track security posture for audits
βœ… Team Awareness: Keep your team informed of security status
βœ… Change Detection: Notice when new risky nodes are added
βœ… Best Practices: Get recommendations to improve security
βœ… Multi-Environment: Run separate instances for dev/staging/prod


πŸ”§ Technical Details

Nodes Used: 8
Credentials Required: 2 (N8N API + Gmail OAuth2)
External Dependencies: None
N8N Version: Compatible with latest N8N versions
Execution Time: ~10-20 seconds


πŸ“‹ Requirements

  • N8N instance with API access
  • Gmail account (or other email service)
  • N8N API key with audit permissions
  • Valid SSL certificate for workflow links (recommended)

πŸ› Troubleshooting

Empty report?
β†’ Check your N8N API key has audit permissions

Workflow links don't work?
β†’ Verify server_url is correct and has no trailing slash

No execution status shown?
β†’ Workflows must have been executed at least once

Wrong language displayed?
β†’ Set Language to exactly "FR" or "EN" (uppercase)


🌟 Why This Template?

Unlike basic monitoring tools, this workflow:

  • βœ… Provides context-aware security analysis
  • βœ… Links directly to affected workflows
  • βœ… Shows real execution data (not just theoretical risks)
  • βœ… Calculates unique credential exposure (not just counts)
  • βœ… Supports bilingual reports
  • βœ… Delivers actionable recommendations

🀝 Feedback & Support

Found this helpful? Please rate the template!
Have suggestions? Drop a comment below.

Pro tip: Combine this with N8N's native alerting for real-time incident response!


Tags: #security #audit #monitoring #compliance #automation #email #reporting #credentials #governance


πŸ“œ License

MIT - Feel free to modify and share!