# ============================================================================== # n8n-manager-mcp: MARKETING & DISCOVERABILITY LOG # ============================================================================== # Repository: ellmos-ai/n8n-manager-mcp # Organization: ellmos-ai (Parent: https://github.com/ellmos-ai) # Umbrella: open-bricks (https://github.com/open-bricks) # Namespace: io.github.ellmos-ai/n8n-manager-mcp # NPM Package: n8n-manager-mcp # Author: Lukas Geiger # License: MIT # Version: 0.1.20 # Last Updated: 2026-09-14 # ============================================================================== 1. PRODUCT POSITIONING & VALUE PROPOSITION ------------------------------------------------------------------------------ n8n-manager-mcp is the enterprise-grade, local-first Model Context Protocol (MCP) server designed specifically for AI assistants (Claude Code, Claude Desktop, Cursor, Windsurf) to manage, build, test, and inspect n8n workflows end-to-end. Unlike raw API wrappers or ad-hoc shell scripts, n8n-manager-mcp provides: - A standardized 19-tool MCP surface covering full workflow lifecycle operations. - Zero external runtime telemetry and 100% local stdio IPC transport. - Monotonic read-only safety gates (N8N_MANAGER_READ_ONLY=1) immune to tool override. - Automated pre-mutation JSON snapshots with 1-click local rollback. - Multi-server credential isolation across local and cloud n8n instances. - Comprehensive offline node catalog for zero-latency node discovery. 2. TARGET PERSONAS & USER SEGMENTS ------------------------------------------------------------------------------ [PERSONA-1] Autonomous AI Agent Engineers & Prompt Developers - Context: Engineers equipping LLM agents (Claude Code, Cursor, Windsurf) with autonomous orchestration capabilities. - Pain Point: LLMs generating broken workflow JSON, deleting workflows without backups, or guessing node connection parameters. - Solution: Built-in n8n_describe_nodes catalog, automatic pre-mutation backups, and robust error diagnostics via stdio. - Discovery Terms: `n8n mcp server`, `ai agent n8n workflow management`, `claude n8n automation` [PERSONA-2] DevOps & Multi-Instance Workflow Architects - Context: Platform teams managing multiple n8n environments (e.g. dev, staging, production). - Pain Point: Tedious manual JSON exports, import errors, and secret leaks across instances. - Solution: Multi-server management (n8n_add_server, n8n_list_servers, n8n_ping_server), atomic server config storage, and seamless export/import pipelines. - Discovery Terms: `n8n multi-server mcp`, `sync n8n workflows staging prod`, `n8n workflow export import mcp` [PERSONA-3] Compliance, SecOps & Enterprise Risk Officers - Context: Security teams overseeing developer tools and autonomous agent actions. - Pain Point: Accidental deletion of production workflows or unauthorized modifications. - Solution: Process-level read-only ceiling (N8N_MANAGER_READ_ONLY=1), append-only audit trail (~/.n8n-manager-mcp/audit.log), and path traversal guards. - Discovery Terms: `safe n8n mcp server`, `read-only n8n automation`, `audit log n8n ai integration` [PERSONA-4] Open-Source Ecosystem & MCP Integrators - Context: Developers building and cataloging MCP servers for Glama, Smithery, PulseMCP, and Enterprise DNA. - Pain Point: Inconsistent manifests, missing license inventories, and lack of CI contract tests. - Solution: Validated server.json, glama.json, smithery.yaml, bilingual documentation, and automated contract test suites in Vitest. - Discovery Terms: `modelcontextprotocol n8n`, `glama n8n-manager-mcp`, `smithery n8n workflow` 3. HIGH-INTENT KEYWORD & DISCOVERY MATRIX ------------------------------------------------------------------------------ Primary Intent Categories & Dual-Language Keywords: Category 1: Agent Workflow Automation (AI / LLM Focus) - English: n8n MCP server, manage n8n with Claude Code, Cursor n8n workflow builder, autonomous agent workflow management, LLM n8n integration, local-first workflow MCP. - German: n8n MCP Server, n8n Workflows mit KI verwalten, Claude Code n8n Automatisierung, Cursor n8n Workflow Assistent, lokaler Workflow MCP Server. Category 2: DevOps & Multi-Server Operations - English: n8n multi-server management, export import n8n workflows MCP, sync n8n staging production, n8n instance migration, automated n8n backup restore tool. - German: n8n Multi-Server Verwaltung, n8n Workflows exportieren importieren MCP, n8n Instanzen synchronisieren, automatisches n8n Backup und Wiederherstellung. Category 3: Security, Auditing & Governance - English: read-only n8n MCP, safe n8n AI integration, n8n forensic audit logging, pre-mutation workflow snapshot, zero-telemetry workflow automation, MIT licensed n8n MCP. - German: Nur-Lese n8n MCP, sichere n8n KI-Integration, forensisches n8n Audit-Log, Pre-Mutation Workflow Snapshot, telemetriefreie n8n Automatisierung. Category 4: Registry & Catalog Discoverability - English: io.github.ellmos-ai/n8n-manager-mcp, n8n-manager-mcp npm, Glama n8n server, PulseMCP ellmos-ai-n8n-manager, Smithery n8n manager. - German: n8n-manager-mcp npm Paket, Glama n8n Verzeichnis, MCP Server Katalog n8n. 4. 5-WAY COMPARATIVE MATRIX (10 DIMENSIONS) ------------------------------------------------------------------------------ | Dimension | n8n-manager-mcp | Direct n8n REST API | Standard Agent Shell | Manual n8n Web UI | Generic Cloud SaaS | |---|---|---|---|---|---| | Primary Interface | Native MCP Stdio (JSON-RPC) | HTTP REST (Curl/Axios) | Ad-hoc CLI / Bash | Web Browser Canvas | Proprietary SaaS Web | | Safety Guardrails | Monotonic Read-Only Gate | Blind Execution | Unchecked Script Writes | Accidental Clicks | Remote Role Rules | | Mutation Snapshot | Automated Pre-Mutation Backups | None (Overwrites live) | None (Script dependent) | None (Live canvas) | Cloud-dependent | | Rollback Facility | 1-Click `n8n_restore_workflow` | Manual JSON reconstruction | Custom script rollback | Manual node rebuilding | Vendor snapshot UI | | Forensic Audit Log | Append-Only `audit.log` | Webserver access log | Terminal stdout | Canvas change history | Cloud vendor logs | | Node Catalog | Built-in `n8n_describe_nodes` | Online doc search | Parameter guessing | Visual node palette | Documentation portal | | Multi-Server Isolation | Atomic `servers.json` + isolation | Hardcoded env tokens | Shell history leaks | Multi-tab logins | Vendor multi-tenant | | Local Privacy / Zero-Egress | 100% Local Stdio, Zero-Egress | Direct server connection | Local execution | Browser session data | Remote cloud storage | | Workflow Migration | Built-in export/import tools | Manual JSON download/upload | Complex curl pipelines | Download/upload UI | Enterprise paywall | | Open-Source License | 100% Permissive MIT / Audited | Sustainable Fair-Code | Ad-hoc / Mixed | Commercial / Fair-Code | Closed Proprietary | 5. GOVERNANCE & RUNTIME INVARIANTS ------------------------------------------------------------------------------ - INV-LOCAL-01: 100% Local-First & Zero-Egress Stdio Protocol Transport operates purely over local stdio streams; zero telemetry or telemetry beacons; credentials stored locally under ~/.n8n-manager-mcp/. - INV-READ-02: Monotonic Read-Only Enforcement N8N_MANAGER_READ_ONLY=1 establishes an immutable process-level ceiling that fails closed against any workflow creation, update, deletion, or restore. - INV-BACK-03: Automated Pre-Mutation Backups Full workflow JSON snapshots are automatically captured under ~/.n8n-manager-mcp/backups/ before any mutation or deletion occurs. - INV-AUDIT-04: Local Forensic Audit Trail Every operation (invoked tool, server target, workflow ID, outcome, error) is recorded in append-only structured JSON log ~/.n8n-manager-mcp/audit.log. - INV-SRV-05: Multi-Server & Isolated Credentials Server configurations are written atomically to servers.json with strict URL validation, whitespace rejection, and isolated authorization headers. - INV-TRAV-06: Strict Input & Path Traversal Guard All user inputs and backup paths are validated with bounded limits (1..1000) and realpath containment checks against directory traversal and symlink escapes. - INV-PRIV-07: Non-Elevation & User-Space Security Executes purely in unprivileged user space without requiring root or administrative elevation. - INV-SEAM-08: Opt-In Decision History Seam Optional adapter to n8n-workflow-manager via N8N_MCP_MANAGER_URL; fails fast and cleanly without corrupting standard MCP operations when absent. - INV-NODE-09: Built-in Offline Node Catalog & Introspection Offline node type catalog (triggers, actions, logic, transform, AI) accessible via n8n_describe_nodes for instant context ingestion without network latency. - INV-SLA-10: Multi-OS CI & 48h Security Response SLA Automated multi-node CI (Node 20, 22) with concurrency cancellation and public 48h security response / 5-day triage commitment. 6. SIBLING ECOSYSTEM PARTNER MATRIX (16 REPOSITORIES) ------------------------------------------------------------------------------ The ellmos-ai and open-bricks suites provide coordinated local-first tools: 1. file-bricks/ProFiler: Advanced file and asset management workbench 2. file-bricks/ExplorerPro: Tabbed, filterable file manager with smart batch processing 3. file-bricks/WinStorePackager: MSIX packaging and Windows Store release preparation 4. doc-bricks/DokuZen: Offline Markdown editor and live preview workbench 5. doc-bricks/PDFtoPDFocr: Offline OCR pipeline converting scanned PDF documents 6. doc-bricks/USR_PDFunlock: Password recovery tool for protected PDF archives 7. doc-bricks/UniversalInvoiceMail: Automated invoice extraction and email processing 8. doc-bricks/CleanMarkdown: Lossless formatting and typography cleanup for markdown 9. dev-bricks/safe-start-for-codex: Fast, reliable agent bootstrap and environment runner 10. dev-bricks/automation-master: Central multi-host automation orchestrator 11. dev-bricks/DevCenter: Unified developer workspace dashboard 12. dev-bricks/CodeBox: Sandboxed multi-language tool execution environment 13. dev-bricks/githubbot: Automated multi-org repository maintenance engine 14. ellmos-ai/swarm-ai: Distributed multi-agent swarming framework with stigmergy 15. ellmos-ai/ellmos-core: Enterprise AI agent backend and hybrid RAG 16. open-bricks/open-bricks: Umbrella portal and catalog across all software products 7. THREE-PHASE DISCOVERABILITY ROADMAP ------------------------------------------------------------------------------ - Phase 1 (Registries & Manifest Parity) [STATUS: COMPLETE]: Complete npm distribution, Glama, Smithery, and PulseMCP metadata alignment; 100% manifest consistency between package.json, server.json, and glama.json. - Phase 2 (Technical Architecture & Guides) [STATUS: COMPLETE]: Bilingual READMEs (English & German) with 16-point navigation, interactive Dual-Mermaid diagrams, comprehensive Third-Party Licenses inventory, and llms.txt. - Phase 3 (Ecosystem Interoperability & Community) [STATUS: ACTIVE]: Seamless integration with open-compute, BACH, and agent orchestration tools; automated regression testing on every pull request and release tag. 8. TECHNICAL HYGIENE & CI HARDENING AUDIT (2026-09-14) ------------------------------------------------------------------------------ - CI Timeout Guardrails: Hardened tests.yml (15m), stale.yml (10m + concurrency cancellation), welcome.yml (5m), auto-assign.yml (5m), and label-sync.yml (5m) against hung runners and unbounded action minutes consumption. - Multi-Host Cloud-Sync & Lock Defense: Hardened .gitignore against multi-host conflict copies (* (kopie)*, * (copy)*, *-WORKSTATION-LG*, *-ASUS-GEI*), canonical lock primitives (LOCK, LOCK.*, LOCK*.txt, LOCK.permissions.json, uv.lock, with package-lock.json trackable exemption), and cache directories (.coverage.*, .tox/, .turbo/, .nyc_output/, .hypothesis/). - Contract Testing: Vitest contract test suite extended to 186 automated tests (100% pass) verifying multi-host gitignore defense, manifest version consistency, workflow timeout constraints, and documentation integrity. 9. PATH B DISCOVERABILITY, 18-POINT NAVIGATION & METADATA RE-AUDIT (2026-09-18) ------------------------------------------------------------------------------ - Discoverability & Registry Health: * Traffic & Visibility Baseline: 214 clones across 67 unique cloners; 28 views across 13 unique viewers; 0 open issues, 1 open PR (#5 fast-uri bump). * GitHub Topics Optimization: Reached maximum allowable GitHub topics (20 topics) by registering 'zero-egress' and 'open-bricks' tags alongside mcp, mcp-server, n8n, workflows, automation, devops, etc. - 18-Point Bilingual Navigation Parity: * Restructured README.md and README_de.md with complete 18-point quick navigation table from #1-architecture to #18-liability--statutory-notice. * Preserved full backward compatibility with legacy anchor IDs (#system-architecture, #core-capabilities--safety-invariants, #third-party-licenses, #haftung--liability). * Promoted Dual Mermaid Diagrams to a dedicated Section 2 with independent Component Architecture flowchart TD and Safe Mutation Lifecycle sequence diagram. - Target Personas & High-Intent Search Matrix: * Canonical Persona Tags: Explicitly mapped [PERSONA-01] / [PERSONA-1] (Autonomous Agents), [PERSONA-02] / [PERSONA-2] (DevOps / Multi-Environment), [PERSONA-03] / [PERSONA-3] (SecOps / Compliance), and [PERSONA-04] / [PERSONA-4] (Ecosystem Builders & Tool Integrators). * SEO Query Table: Added bilingual High-Intent search queries covering Claude Code n8n integration, zero-egress workflow backup, multi-server staging, and local MCP servers. - Supply Chain & Third-Party Invariants Audit: * Updated THIRD_PARTY_LICENSES.md with Section 5 Formal Governance Matrix validating all 10 invariants (INV-LOCAL-01 through INV-SLA-10) and RunAsInvoker non-elevation. * Verified 100% permissive dependencies (MIT, BSD-2-Clause, BSD-3-Clause, Apache-2.0) with zero copyleft or AGPL exposure. - Verification & Contract Test Expansion: * Expanded Vitest contract test suite to 189 passing tests across 8 test suites. * Automated contract assertions for 18-point anchors, canonical persona IDs, and third-party invariant mapping.