Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

N8n Selfhosted Ops

ASecurity

Use when operating a self-hosted n8n instance (npm/systemd, no Docker) - importing workflows via CLI without an API key, exposing env vars to workflow expressions, credential export/import that keeps node links, and the Telegram human-in-the-loop pattern that avoids the broken sendAndWait node. Verified on n8n 2.8.

2 stars
0 votes
0 copies
0 views
Added 9/19/2026
ai-agentsgosqlnodeexpressdockerapibackend

Works with

cliapi

Security Analysis

A92/100
mediumInstalls packages at runtime which could introduce malicious dependencies

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add Mixard/fable-pack --skill n8n-selfhosted-ops --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of N8n Selfhosted Ops?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for N8n Selfhosted Ops
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/mixard-n8n-selfhosted-ops/badge)](https://www.skillsdirectory.com/skills/mixard-n8n-selfhosted-ops)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: n8n-selfhosted-ops
description: Use when operating a self-hosted n8n instance (npm/systemd, no Docker) - importing workflows via CLI without an API key, exposing env vars to workflow expressions, credential export/import that keeps node links, and the Telegram human-in-the-loop pattern that avoids the broken sendAndWait node. Verified on n8n 2.8.
---

# Self-hosted n8n operations

Verified on n8n 2.8 (global npm install, systemd service, sqlite backend). The facts
below are the ones models reliably get wrong: they assume the REST API is the only
import path, that .env files load automatically, and that sendAndWait works.

## Workflow import without an API key

`n8n import:workflow --input=/path/to/workflow.json` writes directly into the sqlite
DB, bypassing the REST API entirely - no API key, no running UI session needed.
Safe to run repeatedly: the command also applies pending DB migrations on start.
Success output: `Successfully imported N workflow(s).`

- List workflows and recover IDs: `n8n list:workflow` (returns `ID|Name` rows).
- Gotcha: running import via `sudo -u OTHER_USER` fails with `EACCES` when the JSON
  is root-owned mode 600. Keep the file readable or run as the service user.

## Env vars in workflow expressions

n8n does NOT read a project `.env` automatically. For `{{$env.FOO}}` to resolve,
the variable must be in the service environment. With systemd:

```
sudo systemctl edit n8n
# add:
[Service]
EnvironmentFile=/path/to/.env
# then:
systemctl daemon-reload && systemctl restart n8n
```

## Credentials travel separately

Workflow JSON exports reference credentials by ID only - the secrets themselves are
not in the file, so a workflow imported alone points every credentialed node at a
dangling ID. Export them on the source with
`n8n export:credentials --all --decrypted --output=creds.json` and import with
`n8n import:credentials --input=creds.json`; ids are preserved, so nodes re-link
without UI work. Across instances with different encryption keys keep `--decrypted`
on export (the target re-encrypts). Only credentials that never existed on the
source need manual creation (Settings > Credentials > New).

## Webhook URLs

Public format: `{N8N_WEBHOOK_URL}/webhook/{path}` with `path` from the Webhook node.
Meta, Google Business Profile, and Telegram all reject plain HTTP callbacks -
a reverse proxy with TLS (or n8n's built-in SSL config) is a hard prerequisite.

## Telegram human-in-the-loop: do not use sendAndWait

`Telegram.sendAndWait` has long-standing bugs (n8n issues #13331, #15492). As of
n8n 2.31 (July 2026) both issues were closed "not planned" by the stale-bot without
a fix, so the workaround below remains necessary; re-check only if n8n ships an
explicit fix. Working pattern:

1. `Telegram: sendMessage` with an `inline_keyboard` whose button URLs embed the
   execution resume URL: `{{$execution.resumeUrl}}?answer=approve` / `?answer=reject`.
2. A `Wait` node in `webhook` mode listens on that resume URL.
3. Downstream nodes read the choice from `$json.query.answer`.

For dynamic inline keyboards (button list built at runtime), the native Telegram node
cannot express them - call `https://api.telegram.org/bot{token}/sendMessage` directly
with an HTTP Request node and build `reply_markup` yourself.

Attribution

MixardMixard
View sourceMore from Mixard →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.

1023331 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

686011 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3331 votes

catchup

Recovers prior coding-agent session context by running `catchup <agent> --since-compact`, which extracts a clean summary of a previous Codex, Claude Code, Antigravity, OpenCode, or Pi Agent session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", or asks to recover/summarize a previous session before continuing. Do NOT use for the current conversation, git history, or any non-agent log.

611 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →