Free tool · runs in your browser
Workflow linter: catch risky automation steps before they run
workflow-lint is an open-source preflight linter that catches missing error handling, unsafe retries, unapproved money actions and hardcoded secrets in AI-agent and automation workflows before they run.
Try workflow-lint
Paste an n8n workflow export (JSON) or a generic workflow spec (YAML or JSON), or load a sample. Linting runs entirely in your browser.
The interactive tool needs JavaScript. The same core runs locally: npx @teamshift/workflow-lint
Who it is for
People who build or review n8n flows and AI agents that send email, charge cards, update a CRM or delete records. It is most useful right before you activate a workflow, and in CI so a risky change is caught in review.
How it works
workflow-lint converts the workflow into a list of steps and works out what each one does to the outside world: nothing, a write, an external send, a money movement, or a delete. Then it applies nine rules drawn from real automation failures:
WL001missing error handling, including steps that silently continue on errorWL002retried writes, sends or payments with no idempotency keyWL003external calls or open-ended waits with no timeoutWL004money, delete or external-send steps with no human approval gateWL005workflows that never check the end stateWL006hardcoded API keys, tokens and private keys (redacted in the output)WL007loops, pagination or execution cycles with no limitWL008webhook triggers that do not verify a signatureWL009personal data sent to an LLM step with no handling note
Example
The "New order follow-up" sample n8n workflow produces 12 findings (7 errors, 5 warnings). Two of them:
error WL002 unsafe-retry line 55
Step "Email Customer" retries up to 3 times but has no idempotency key;
a retry after a timeout can repeat the send.
error WL004 unapproved-high-risk-action line 65
Step "Charge Deposit" moves money without a human approval gate.The fixed version reports zero problems. On the command line: npx @teamshift/workflow-lint workflow.json, or --format sarif for code scanning.
Limitations
- It reads n8n exports and its own generic spec. Describe workflows from other tools in the spec to lint them.
- Some n8n checks are heuristics, such as recognizing a "Verify…" node as a completion check. A clean report is a floor, not proof that a workflow is safe.
- It checks structure, not behavior. It cannot tell whether an approval step is ever answered or whether a timeout is the right length.
FAQ
How do I lint an n8n workflow before activating it?
Export it from n8n (Workflow, then Download, or copy all nodes) and paste the JSON above, or run npx @teamshift/workflow-lint workflow.json. Pasted node selections work too, because the linter only needs nodes and connections.
Which automation steps should require human approval?
Anything that moves money, deletes data, or sends to customers, vendors or the public, at least until the automation has a track record. Rule WL004 flags these steps when no approval gate comes before them.
How do I stop an agent from sending duplicate emails when it retries?
Give every side-effect step an idempotency key derived from the business object, such as the invoice id plus the reminder number, and pass it to the provider or check it before sending. Rule WL002 flags every retried side effect that lacks one.
Does this page upload my workflow?
No. The linter is the same pure TypeScript core as the CLI, running in your browser. Nothing you paste is sent to TeamShift or anyone else.