Honest Agent Receipt Pack (n8n workflows)
Your agent says it wrote the report, cited three sources and kept your keys out of the log. This pack checks those claims on your own machine and writes down what it found.
Four self-hosted n8n workflows:
- Verify agent file claims. Each "I created / changed / deleted this file" claim gets a PASS or FAIL row in a CSV, with the file's SHA256, size and last-modified time as evidence. Claims can come from a sample, another workflow, or an inbox folder your agent writes to.
- Scan agent outputs for secrets and private paths. Flags API keys, tokens, private key blocks, Bearer values, password assignments, home-folder paths that show a user name, and email addresses. Every value is redacted in the files it writes.
- Check links against an allow list. Links that are not on your list are failed and never requested, so an invented domain never gets a visit from your machine. Listed links get one HEAD request.
- Weekly honesty score. Verified claims divided by claims, per week, plus the flag counts, in one CSV.
Everything runs on your own n8n. No accounts, API keys or cloud services are needed; the only outbound requests are the HEAD checks to links on your allow list. The download is files: four workflow JSONs, a README, a setup guide, sample files and screenshots from the seller's test run.
What it does NOT do
- It does not stop an agent from acting. It checks afterwards and writes evidence.
- It does not judge whether a file's content is correct, only that the claimed change happened.
- It does not prove a string is a live secret, and it misses secrets in formats it does not know.
- It does not prove a link supports what the agent said. A PASS means the server answered.
- It does not send alerts. You connect your own alert step.
- It is not a security audit or compliance tool, and it does not promise any business result.
- It does not include n8n, and there is no setup service or support call.
Requirements
- Self-hosted n8n 2.x (tested on 2.41.6). Not for n8n Cloud.
- Permission to set one environment variable when n8n starts: NODE_FUNCTION_ALLOW_BUILTIN=crypto,fs,path.
- A folder n8n may read and write.
- No accounts, API keys or paid services.
Refund: 30-day refund.
License: personal use by one buyer. You may modify the files for your own use. You may not redistribute, share, resell, sublicense or publish them.
Disclosure: Built with AI coding assistance, tested by the seller. The workflows were generated, then imported and run in a throwaway self-hosted n8n with scripted checks. They are plain n8n workflows, not an autonomous agent.