FlowSentry

Security scanner for n8n workflows + live MCP Trust-Check.

Community: Submitted by a user or imported; check the owner before granting accessOnlineNo sign-inGlobalFreeRead-only

What it can do

    What data it sees

    Do you need an account

    No: the server works without sign-in

    Security scanner for n8n workflows + live MCP Trust-Check. 18 rules, OWASP mapped. Paid x402 API.

    Server tool list (3)

    Raw names from tools/list. Only developers need these.

    list_rulesList all 18 FlowSentry security rules with severity and OWASP Agentic mapping.
    scan_workflowScan one n8n workflow JSON export (string) and return the findings report. Accepts the raw workflow object ({'nodes': [...], ...}) or the CLI export wrapper ({'name':..., 'workflow': {...}}). Max 512 KB.
    trust_checkLive security Trust-Check of a remote MCP server URL (streamable HTTP). Sends one benign MCP initialize handshake and inspects auth posture, header hygiene, version disclosure and reachability. Returns trust score 0-100, grade A-F, verdict (trusted/acceptable/caution/unsafe/unreachable) and structured findings. Paid unlimited lane: POST /v1/trust-check on the same host ($0.25 USDC per check, x402 on Base).