{"product_id":"n8n-workflow-verify-ai-file-ops-with-sha256-csv-logs","title":"n8n Workflow: Verify AI File Ops with SHA256 \u0026 CSV Logs","description":"\u003ch3\u003eVerify AI file-operation claims with SHA256 and CSV evidence—automatically\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow audits an AI agent’s claimed file operations by checking the local filesystem for existence, symlink safety, SHA256 integrity, and timestamp accuracy—then logs clear PASS\/FAIL evidence to a CSV for accountability.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRuns manually or via Execute Workflow:\u003c\/strong\u003e start it yourself with sample claims or trigger it from another n8n workflow that sends claim items.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eApplies shared settings to each claim:\u003c\/strong\u003e injects allowed root folder, evidence CSV path, default time window, and a maximum file size to hash.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eValidates path safety:\u003c\/strong\u003e ensures the target path stays within the \u003cem\u003eallowedRoot\u003c\/em\u003e and \u003cstrong\u003erefuses symlinks\u003c\/strong\u003e to prevent unsafe access.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHandles deleted claims:\u003c\/strong\u003e confirms that the file is missing when a claim indicates it was deleted.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eChecks create\/modify claims:\u003c\/strong\u003e reads file metadata, computes a \u003cstrong\u003eSHA256\u003c\/strong\u003e hash only if the file is under the size limit, and optionally compares it to an expected SHA256.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eVerifies timestamps:\u003c\/strong\u003e checks whether the file’s \u003cem\u003elast-modified\u003c\/em\u003e time falls within the claim’s time window around the claimed timestamp.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWrites audit results:\u003c\/strong\u003e outputs PASS\/FAIL rows (including reasons) to a CSV, adding headers if needed and appending to the on-disk evidence log.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e \u003cstrong\u003eAuditing AI agent file ops:\u003c\/strong\u003e prove that an agent created\/modified\/deleted the correct files.\u003c\/li\u003e\n  \u003cli\u003e \u003cstrong\u003eSecurity and compliance checks:\u003c\/strong\u003e prevent symlink-based escapes and verify integrity with SHA256.\u003c\/li\u003e\n  \u003cli\u003e \u003cstrong\u003eOperational QA for SaaS operators:\u003c\/strong\u003e maintain an evidence trail for automation runs.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRequired configuration:\u003c\/strong\u003e set \u003ccode\u003eNODE_FUNCTION_ALLOW_BUILTIN=crypto,fs,path\u003c\/code\u003e so the Code node can compute SHA256 and read filesystem metadata.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003en8n file access restrictions:\u003c\/strong\u003e configure \u003ccode\u003eN8N_RESTRICT_FILE_ACCESS_TO\u003c\/code\u003e and set \u003ccode\u003eallowedRoot\u003c\/code\u003e and \u003ccode\u003eevidenceCsvPath\u003c\/code\u003e inside that allowed area.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eWorkflow nodes used:\u003c\/strong\u003e set, code, sticky note, manual trigger, read\/write file, execute workflow trigger.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":46196309524659,"sku":"N8N-20718","price":4.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/4vgVQfPsNxIBI9NRhaS1o_gERAWTkz.png?v=1791623277","url":"https:\/\/buyflowscripts.com\/products\/n8n-workflow-verify-ai-file-ops-with-sha256-csv-logs","provider":"N8N Commerce","version":"1.0","type":"link"}