Due to increased demand, text TeamShift to hold the next available slot.+1 717 740 8200Call instead
TeamShift

Free tool · runs in your browser

Workflow linter: catch risky automation steps before they run

workflow-lint is an open-source preflight linter that catches missing error handling, unsafe retries, unapproved money actions and hardcoded secrets in AI-agent and automation workflows before they run.

Try workflow-lint

Paste an n8n workflow export (JSON) or a generic workflow spec (YAML or JSON), or load a sample. Linting runs entirely in your browser.

The interactive tool needs JavaScript. The same core runs locally: npx @teamshift/workflow-lint

Who it is for

People who build or review n8n flows and AI agents that send email, charge cards, update a CRM or delete records. It is most useful right before you activate a workflow, and in CI so a risky change is caught in review.

How it works

workflow-lint converts the workflow into a list of steps and works out what each one does to the outside world: nothing, a write, an external send, a money movement, or a delete. Then it applies nine rules drawn from real automation failures:

  • WL001 missing error handling, including steps that silently continue on error
  • WL002 retried writes, sends or payments with no idempotency key
  • WL003 external calls or open-ended waits with no timeout
  • WL004 money, delete or external-send steps with no human approval gate
  • WL005 workflows that never check the end state
  • WL006 hardcoded API keys, tokens and private keys (redacted in the output)
  • WL007 loops, pagination or execution cycles with no limit
  • WL008 webhook triggers that do not verify a signature
  • WL009 personal data sent to an LLM step with no handling note

Example

The "New order follow-up" sample n8n workflow produces 12 findings (7 errors, 5 warnings). Two of them:

error    WL002 unsafe-retry  line 55
         Step "Email Customer" retries up to 3 times but has no idempotency key;
         a retry after a timeout can repeat the send.
error    WL004 unapproved-high-risk-action  line 65
         Step "Charge Deposit" moves money without a human approval gate.

The fixed version reports zero problems. On the command line: npx @teamshift/workflow-lint workflow.json, or --format sarif for code scanning.

Limitations

  • It reads n8n exports and its own generic spec. Describe workflows from other tools in the spec to lint them.
  • Some n8n checks are heuristics, such as recognizing a "Verify…" node as a completion check. A clean report is a floor, not proof that a workflow is safe.
  • It checks structure, not behavior. It cannot tell whether an approval step is ever answered or whether a timeout is the right length.

FAQ

How do I lint an n8n workflow before activating it?

Export it from n8n (Workflow, then Download, or copy all nodes) and paste the JSON above, or run npx @teamshift/workflow-lint workflow.json. Pasted node selections work too, because the linter only needs nodes and connections.

Which automation steps should require human approval?

Anything that moves money, deletes data, or sends to customers, vendors or the public, at least until the automation has a track record. Rule WL004 flags these steps when no approval gate comes before them.

How do I stop an agent from sending duplicate emails when it retries?

Give every side-effect step an idempotency key derived from the business object, such as the invoice id plus the reminder number, and pass it to the provider or check it before sending. Rule WL002 flags every retried side effect that lacks one.

Does this page upload my workflow?

No. The linter is the same pure TypeScript core as the CLI, running in your browser. Nothing you paste is sent to TeamShift or anyone else.