Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
No blocking static signals were detected.
Trigger
User executes the Zalo Login Via QR Code n8n node with n8n API credentials.
Impact
Creates an n8n credential containing Zalo session material; the configured n8n API key authorizes the write.
Mechanism
POST captured Zalo login material to the configured n8n credentials API
Rationale
Source inspection confirms an explicit runtime capability to create n8n credentials from QR-login session material. It is not install-time malware or covert exfiltration, but warrants a warning for platform credential-store mutation.
Evidence
package.jsondist/credentials/N8nZaloApi.credentials.jsdist/nodes/ZaloLoginByQr/ZaloLoginByQr.node.jsdist/nodes/ZaloBotTrigger/ZaloBotTrigger.node.jsdist/nodes/utils/helper.js
Network endpoints2
127.0.0.1:5678/api/v1/credentialsbot-api.zaloplatforms.com