Agent skill

n8n AI Agent Design

by czlonkowski in czlonkowski/n8n-skills

Guide to designing n8n AI agents: choosing between Agent, chain, classifier and extractor nodes, wiring model, memory, tools and parser, plus RAG and human review.

MITAuto-check passedAI & LLM Engineering

Install n8n AI Agent Design

skills CLI
$ npx skills add czlonkowski/n8n-skills --skill n8n-agents -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install czlonkowski/n8n-skills n8n-agents --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/czlonkowski/n8n-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/n8n-agents .claude/skills/n8n-agents && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
n8n-agents
GitHub stars
6.4k
Token cost
~6.8k tokens
SKILL.md length
3,407 words
Files
11
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Guide to designing n8n AI agents: choosing between Agent, chain, classifier and extractor nodes, wiring model, memory, tools and parser, plus RAG and human review.

  • Works in 2 steps: Tool names and descriptions ARE part of… → Structured output must parse AND…
  • Building or editing an n8n AI Agent, LLM chain or Text Classifier node
  • SKILL.md covers Pick the right node first, The sub-node pattern, Two non-negotiables and Strong defaults, plus 14 more sections
  • Needs N8N_MCP_ACCESS_TOKEN

What it does

This skill is a deep guide to building the AI Agent node in n8n and the LangChain-family nodes around it. It opens with choosing the right node, since using an Agent for one-shot classification or extraction is the most common over-build: Basic LLM Chain for text in and out, Text Classifier for routing into several branches, Information Extractor for schema-based fields, plus sentiment analysis and summarization nodes.

It then covers the model, memory, tools and output parser slots, tool names and descriptions treated as prompt text, structured output with autoFix, memory and sessionId, RAG with a vector store, human review and chat topologies. Separate notes cover each topic, including system prompts and using a sub-workflow as a tool. It explains the long and short node type formats used in workflow JSON versus `get_node` and `validate_node` calls, and says never to wrap image, audio or video generation in an Agent.

When your agent uses it

  • Building or editing an n8n AI Agent, LLM chain or Text Classifier node
  • Giving an n8n agent tools and writing their names and descriptions
  • Forcing structured JSON output from an n8n LLM node
  • Adding memory, RAG or human review to an n8n chat assistant

Example prompts

  • “Design an n8n support chatbot with window memory and a sub-workflow tool for order lookups.”
  • “Should this ticket-routing step in n8n be an AI Agent or a Text Classifier?”
  • “Add a structured output parser with autoFix to my n8n invoice extraction node.”

Requirements

  • An n8n instance with the LangChain AI nodes
  • The n8n MCP tools (get_node, validate_node) for checking nodes

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Tool names and descriptions ARE part of the prompt. The model picks a tool by reading its name and description — nothing else. A tool…
  2. Structured output must parse AND autoFix. An outputParserStructured with autoFix: true and a coding-capable fixer model is the production…

What it can do on your machine

Read from SKILL.md and the folder at commit 19cd793. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • N8N_MCP_ACCESS_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

n8n AI Agent Design loads about 6.8k tokens when it runs. Until then it costs about 154 tokens; SKILL.md has 3,407 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~154
When it runs · the whole SKILL.md, loaded when a task matches
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from czlonkowski/n8n-skills at commit 19cd793, republished under its MIT licence (© czlonkowski). 3,407 words, ~6,777 tokens.

Download SKILL.mdSave it as .claude/skills/n8n-agents/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
n8n-agents
description
Design n8n AI agents the right way. Use when building or editing any @n8n/n8n-nodes-langchain.* AI node — an AI Agent, LLM chain, Text Classifier, or Information Extractor — and whenever the user mentions AI agents, LLM with tools, tool calling, $fromAI, system prompts, agent memory, sessionId, structured/JSON output, output parser, RAG, vector store, a chat assistant/bot, or human-in-the-loop review. Covers Agent-vs-chain-vs-classifier choice, the model/memory/tools/outputParser slots, tool names/descriptions as prompt, structured output with autoFix, memory, RAG, human review, and chat topologies.

n8n Agents

The n8n AI Agent node (@n8n/n8n-nodes-langchain.agent) is a multi-turn LLM driver with sub-nodes for the model, memory, tools, and an optional output parser. This skill is the deep guide to designing agents and the LangChain family around them. For the high-level "where an agent fits in a workflow" picture, see n8n-workflow-patterns ai_agent_workflow.md — this skill goes one level down into how to build it well.

For node-type formats: in workflow JSON the LangChain nodes use the long @n8n/n8n-nodes-langchain.* form (.agent, .lmChatOpenAi, .memoryBufferWindow, .outputParserStructured, .toolWorkflow, .toolHttpRequest, .toolCode). When you call get_node / validate_node, use the short form (nodes-langchain.agent). See n8n-mcp-tools-expert for the format rules.


Pick the right node first

Reaching for an Agent when the task is one-shot classification or extraction is the most common over-build. Decide before you wire anything:

You need to…UseWhy
Call tools, reason over multiple turns, or hold memoryAI Agent (.agent)The full loop: model + tools + memory + optional parser. Also a fine default when you'd rather standardize.
One-shot text in → text out, no toolsBasic LLM Chain (.chainLlm)No agent loop, easier to debug. Still accepts an outputParserStructured sub-node.
Route a natural-language input to one of N branchesText Classifier (.textClassifier)ONE node, N output handles, downstream wires directly into each. Not Agent + Switch.
Pull structured fields out of free textInformation Extractor (.informationExtractor)Purpose-built field extraction with a schema.
3-way positive/neutral/negative splitSentiment Analysis (.sentimentAnalysis)Built-in branch outputs.
Condense a long documentSummarization Chain (.chainSummarization)Map-reduce summarization built in.
Generate an image / audio / videoThe provider's native single-call node (OpenAI, Gemini, ElevenLabs…)NEVER wrap media generation in an Agent — see "Binary and the agent boundary".

Text Classifier detail (the Agent + Switch anti-pattern): every category needs both a name AND a description. The model routes against the description, not the name — a category with no description gets picked by coin-flip. Set options.enableAutoFixing: true for robustness on edge inputs. One node, N branches, done. Reaching for an Agent that "decides" then a Switch that "routes" is two nodes plus prompt boilerplate for what Text Classifier does natively.

Chat-model nodes (.lmChatOpenAi, .lmChatAnthropic, .lmChatOpenRouter, …) are sub-nodes — they don't run standalone. They wire into a chain, agent, classifier, or extractor via the ai_languageModel connection.


The sub-node pattern

The Agent has a main input (the prompt / user message) and up to four sub-node slots, each wired by its own ai_* connection type:

SlotConnection typeRequired?Node example
modelai_languageModelYes.lmChatOpenAi, .lmChatAnthropic, .lmChatOpenRouter
memoryai_memoryOptional.memoryBufferWindow, .memoryPostgresChat
toolsai_toolOptional (but the point of an agent)slackTool, .toolWorkflow, .toolHttpRequest, .toolCode
outputParserai_outputParserOptional.outputParserStructured

A sub-node connects FROM itself TO the agent. In workflow JSON the connection lives on the sub-node, keyed by the ai_* type:

json
"Main LLM": {
  "ai_languageModel": [[{ "node": "AI Agent", "type": "ai_languageModel", "index": 0 }]]
},
"Simple Memory": {
  "ai_memory": [[{ "node": "AI Agent", "type": "ai_memory", "index": 0 }]]
},
"Search customer DB": {
  "ai_tool": [[{ "node": "AI Agent", "type": "ai_tool", "index": 0 }]]
}

Multiple tools all connect into the same ai_tool index 0 — they stack, they don't fan into separate indices. With n8n_update_partial_workflow you wire each with an addConnection op using sourceOutput: "ai_tool". The agent puts its final answer in $json.output (not .text, not .response) — downstream nodes read {{ $json.output }}.

See EXAMPLES.md for a complete stateless agent-core node-object snippet.


Two non-negotiables

  1. Tool names and descriptions ARE part of the prompt. The model picks a tool by reading its name and description — nothing else. A tool named tool1 with an empty description is invisible to the model: it skips it, mis-selects it, or hallucinates parameters. There's usually no error — just an agent that "won't use my tool". Treat both like API design. → TOOLS.md
  2. Structured output must parse AND autoFix. An outputParserStructured with autoFix: true and a coding-capable fixer model is the production pattern. Without autoFix, one malformed JSON response halts the whole workflow. → STRUCTURED_OUTPUT.md

Strong defaults

  • Per-tool usage goes in the tool description, not the system prompt. Anything about how to call this specific tool belongs with the tool, so it travels across agents and keeps the system prompt focused. → SYSTEM_PROMPT.md
  • Sub-workflow tools (.toolWorkflow) for anything multi-step. Any workflow becomes a tool with typed $fromAI() inputs, and composes with branching, error handling, and reuse. Default here when in doubt. → SUBWORKFLOW_AS_TOOL.md and n8n-subworkflows.
  • Wrap tools with user-visible side effects in human review. Sends, payments, refunds, account changes get gated behind an approval node so a human signs off before the tool fires. → HUMAN_REVIEW.md
  • Raise maxIterations. The default tool-call cap is low (single digits on most versions) — fine for a one-tool agent, far too low for a multi-tool agent that chains several calls per turn. It surfaces as "max iterations reached" or empty output. Set options.maxIterations to a realistic ceiling (15 for a focused sub-agent, 50-200 for a broad orchestrator).
  • Put the current date in the system prompt via {{ $now }} (or {{ $now.format('DDDD') }}). A hardcoded date is stale immediately.

The four tool types

Pick the lightest option that covers the job:

Tool typeNodeUse when
Native tool nodeslackTool, gmailTool, toolCalculator, …The capability maps to one existing node + one operation. Lowest overhead.
Sub-workflow as tool.toolWorkflowMore than one node, reusable logic, or you want independent testability. The canonical n8n way — default when in doubt.
HTTP Request Tool.toolHttpRequestA single external HTTP API the agent should orchestrate directly. Reuse the service's predefined credential to cover operations a native node doesn't expose.
MCP Client Tool.mcpClientToolA maintained MCP server already covers it, or you want one published workflow to serve many agents.

There is also a Custom Code Tool (.toolCode) for pure inline computation — but its runtime contract (string in / string out, no $fromAI, no $helpers) is owned by the n8n-code-tool skill. Read that before writing one. Rule of thumb: if you find yourself reaching for $fromAI() inside the code, you want .toolWorkflow instead.

$fromAI(): how the agent fills tool parameters

Tool parameters the agent should decide are wrapped in $fromAI(). It is a real n8n expression helper, used inside a tool node's parameter expressions:

={{ $fromAI('paramName', 'what to put here — be specific: format, range, example', 'string') }}
  • paramName — the name the model uses internally (snake_case or camelCase, be consistent).
  • description — tells the model what value to produce. It is part of the prompt — write it like JSDoc.
  • type (optional) — 'string' (default), 'number', 'boolean', 'json'. A wrong-typed value fails the call.
  • defaultValue (optional) — used when the model omits it.

$fromAI() carries JSON only — it cannot carry binary (no base64, no file bytes). And not every parameter has to be $fromAI: plumb identity, authority limits, and correlation IDs (userId, refund caps, sessionId) deterministically from workflow context so the agent can't get them wrong or even see them. → TOOLS.md for the full anatomy and the "give the agent a button, not a steering wheel" pattern.


System prompt vs tool description

Belongs in the system promptBelongs in the tool's description
Persona, role, voiceWhat this specific tool does
Global output/format rules ("respond in markdown")When to use it vs other tools
Refusal / safety behaviorWhat each parameter means and its shape
Display protocols (![]() for images)Examples of good vs bad invocations
Universal context (current date via $now, user role)Tool-specific gotchas (rate limits, edge cases)
Inter-tool flow ("after generating, always display")Tool-specific input transformations

Why split it: a well-described tool works in any agent that drops it in, tool details only "load" when the model considers that tool (token efficiency), and you update one tool description instead of a paragraph buried in a 5000-token prompt. → SYSTEM_PROMPT.md


Structured output: when and how

Add an outputParserStructured sub-node (wired ai_outputParser) when downstream needs strict JSON, not free-form text. Two rules:

  1. Use schemaType: 'manual' with a real JSON Schema, not jsonSchemaExample. An example can't express required-vs-optional, enums, numeric ranges, or array constraints — you outgrow it the first time the shape gets non-trivial. Reach for fromJson + an example only for throwaway shapes.
  2. autoFix: true with a coding-capable fixer model. Wire a second model into the parser's ai_languageModel slot. Reconciling broken JSON against a schema is a coding task — a weak fixer just produces another malformed retry and burns tokens.

→ STRUCTURED_OUTPUT.md for the schema patterns, the load-bearing "DO NOT wrap in markdown" retry line, and the parse-failure cookbook.


Memory: brief mental model

Memory is a sub-node (ai_memory). Without it, every call is stateless — correct for one-shot tasks (classify, summarize). With it, the agent holds a conversation, keyed by whatever expression you bind to sessionKey.

  • memoryBufferWindow — keeps the last N exchanges per key and persists across executions via n8n's store. The default for chat. contextWindowLength defaults to 5, which is very low — 50 is a saner starting point. Messages past the window are gone entirely.
  • memoryPostgresChat / memoryRedisChat — only when memory must be read outside the agent (your own UI, analytics, cross-system). Not needed just to survive restarts; BufferWindow already does that.

Plumb a stable key from the trigger to memory consistently. Chat triggers fill sessionId automatically; for other surfaces derive one (Slack thread_ts, a webhook conversation ID). Never hardcode sessionId: 'default' and never put sessionId behind $fromAI (the model will fabricate a UUID). → MEMORY.md


Binary and the agent boundary

This is the seam that trips people up:

  • The model CAN see uploaded images (vision) via options.passthroughBinaryImages: true on the agent.
  • Tools CANNOT receive binary. $fromAI() is JSON-only — no base64, no bytes, even through non-AI bindings.
  • The agent's output is text-shaped (or structured-text with a parser). When a model returns image/audio/video bytes, the Agent doesn't surface them at all — there's nothing to recover downstream.

Workaround: pre-stage uploads to storage before the agent runs, inject the storage keys into the system prompt, and let tools accept the key as a string parameter and re-fetch internally. For one-shot media generation, skip the agent and call the provider's native single-call node directly.

The binary mechanics (which storage, how to stage, how to re-fetch) are owned by n8n-binary-and-data — see its agent-tool binary reference. This skill only marks the boundary; don't re-derive the mechanics here.


Human review (gate destructive tools)

When a tool's effect needs human sign-off before execution (sends, payments, refunds, account changes), wrap it with a review tool node — slackHitlTool, discordHitlTool, telegramHitlTool, gmailHitlTool, etc. (n8n names these "Hitl" / human-in-the-loop). The review node sits between the wrapped tool and the agent on the ai_tool connection: wrapped tool → review node → Agent.

Whether sign-off is needed is a product/policy call — surface the question to the user, recommend based on blast radius, and let them decide.

The critical rule: show the actual parameters the wrapped tool will receive. Use the literal {{ $tool.parameters.<name> }} in the approval message, never a $fromAI() paraphrase — otherwise the human approves text the model made up, not the call about to fire. → HUMAN_REVIEW.md


Chat agents (Slack, Discord, Teams, Telegram)

The one non-negotiable, regardless of complexity: any chat-triggered workflow that posts a reply MUST filter out the bot's own user ID, or its own replies re-trigger it in an infinite loop that burns runs and tokens. Prefer trigger-level filtering when available (Slack Trigger's options.userIds is an exclusion list — put the bot ID there); otherwise filter $json.user !== '<BOT_USER_ID>' in the first node after the trigger.

Beyond the filter, a simple bot (trigger → agent → reply) lives fine in one workflow. Split into shell + core + sub-agents only once you need loading UX, sub-agents, multi-surface reuse, or robust error handling:

  • Shell — trigger, anti-loop filter, event-type Switch, loading/error UX, renders the reply. No LLM.
  • Core — stateless agent, chatInput + threadId inputs, memory keyed on threadId, tools and sub-agents.
  • Sub-agents — one narrow domain each, called via .toolWorkflow, stateless (full context in chatInput).

→ CHAT_AGENT_PATTERNS.md for per-surface semantics, threading-as-session, and the full topology.


Show full SKILL.md (1,534 more words)Show less

Persisted n8n Agents (n8n_manage_agents)

A persisted n8n Agent is a different artifact from the AI Agent node covered above: a standalone assistant record — model, instructions, tools, skills, tasks, memory, channels — stored and versioned by n8n itself, managed through n8n_manage_agents (n8n's instance-level MCP server), not a node inside a workflow's JSON.

You need to…Use
A reasoning step inside a workflow, wired with ai_* sub-nodesAI Agent node (this skill, above)
A standalone assistant with its own lifecycle — draft, validate, publish, versions, channels — independent of any one workflowPersisted Agent (n8n_manage_agents)

Prerequisites: N8N_MCP_ACCESS_TOKEN configured (separate from the Public API key) and n8n 2.34+ with the agents module enabled. The token is required for every action, including reference/search — without it, nothing works. Separately, reference and search work for any agent regardless of MCP exposure; every other action needs the target agent exposed to MCP (agents created through this tool are exposed automatically — the exposure gate only matters for agents that already existed before this tool touched them).

Build sequence:

  1. action: "reference" — read the config schema and the exact mutate operations before anything else.
  2. action: "discover_assets" — list what the agent can actually be wired to. Takes projectId (from n8n_list_catalog({kind: "projects"})) and kind: models (with a provider), integrations, workflows, subagents or mcpServers. One call per kind.
  3. action: "create" — projectId, name, config.
  4. action: "mutate" — one resource per call (config.patch, skill.upsert/delete, task.upsert/delete, customTool.upsert/delete), always carrying the latest hash forward. Mind the two names: n8n returns it as configHash and expects it back as args.baseConfigHash. args are forwarded to n8n verbatim, so a near-miss on any field name comes back as INVALID_ARGS, not a helpful correction — which is why step 1 reads the schema first. A stale hash comes back as STALE_CONFIG — re-get and retry with the fresh one.
  5. action: "validate" — before offering to call or publish.
  6. action: "publish" — only on the user's explicit request, never proactively.

action: "call" runs the agent with real credentials and real tools — a live execution, not a dry run. A result can carry approvals[] for tool calls that need a human decision; never approve on the user's behalf — surface them and resume only after the user decides.

Custom tools are a third code runtime — don't reuse either of the others. A customTool.upsert body is TypeScript, and the only imports it may use are @n8n/agents and zod. This is not the Code node (JavaScript/Python, returns [{json: …}]) and not the AI-agent Custom Code Tool covered by n8n-code-tool (@n8n/n8n-nodes-langchain.toolCode, returns a string, no $fromAI()). Reaching for the wrong contract is the easy mistake here, because all three are "write code the agent calls". Read the shape from action: "reference" before writing one; a compile failure or an unknown agentId surfaces as AGENT_TOOL_ERROR.

Credential caveat: on n8n 2.36.x the agents runtime rejects azureOpenAiApi and aws credentials (reported as missing: ["credential"]); the response's hint names the accepted types instead.

Testing without leaving debris: name throwaway agents [TEST] … and delete them when you're done — a persisted Agent outlives the conversation that made it, unlike a workflow you can leave inactive.

→ n8n-mcp-tools-expert ## Agents for the tool's full action list and error codes.


RAG (retrieval augmented generation)

n8n ships the LangChain RAG primitives (document loaders, splitters, embeddings, vector stores, retrievers). Two opinions worth stating up front:

  1. Rule out cheaper lookups first. Exact lookups → a database or Data Table query, not RAG. Freshness → a live search tool. A small/structured doc set → give the agent list/fetch tools. Reach for a vector store only when there are too many docs to list and queries are semantic.
  2. Wire the vector store as a retrieval tool (mode: 'retrieve-as-tool', ai_tool) so the agent decides when retrieval is relevant and can phrase the query itself. Embed query and documents with the same model.

→ RAG.md (intentionally thin — defaults depend on data shape and scale).


Reference files

FileRead when
TOOLS.mdAdding tools, choosing among the four types, writing names/descriptions, $fromAI anatomy
SUBWORKFLOW_AS_TOOL.mdWiring a sub-workflow as a tool via .toolWorkflow, mapping agent-filled vs plumbed params
SYSTEM_PROMPT.mdWriting/refactoring a system prompt, the system-prompt-vs-tool-description split
STRUCTURED_OUTPUT.mdForcing JSON output, configuring autoFix, the fixer model, parse-failure fixes
MEMORY.mdChoosing a memory type, persistence, sessionId handling
HUMAN_REVIEW.mdAdding human approval, approval-message content, multi-channel approver
CHAT_AGENT_PATTERNS.mdBuilding a Slack/Discord/Teams/Telegram bot, shell + core + sub-agents topology
RAG.mdRetrieval-augmented agents (thin by design)
EXAMPLES.mdConcrete node-object snippets: stateless agent core, Slack router shell, domain sub-agent

Anti-patterns

Anti-patternWhat goes wrongFix
Generic tool names (tool1, doStuff, runQuery)Model can't tell which tool to pick — skips them or hallucinates paramsVerb-first specific names: Search customer database, Generate image with Veo
Empty or one-line tool descriptionsModel has no idea when to invoke; bad selection, no errorWrite a real description: what it does, when to use, what each param means
Cramming per-tool instructions into the system promptBloated prompt, no reuse, per-tool guidance buriedMove tool-specific instructions into tool descriptions
Agent + Switch to route on natural languageTwo nodes + prompt boilerplate where Text Classifier is one nodeUse Text Classifier — each category gets its own output handle (name and description)
Wrapping image/audio/video generation in an AgentBinary doesn't flow through tools or out of the agent outputUse the provider's native single-call node directly
outputParserStructured without autoFixOne malformed response halts the workflowautoFix: true + a coding-capable fixer model
Passing binary directly to a toolDoesn't work — binary can't cross the tool boundaryPre-stage to storage, pass keys; see n8n-binary-and-data
Hardcoded sessionId / no sessionId / sessionId behind $fromAIConversations cross, or the model fabricates a UUIDPlumb a stable key from the trigger to memory and tools
Two near-identical toolsSelection is non-deterministic, model gets confusedOne tool with internal branching driven by a parameter
Chat bot with no bot-user filterIts own replies re-trigger it → infinite loopExclude the bot user ID at the trigger or first node
maxIterations left at the low default on a multi-tool agent"Max iterations reached" / empty outputRaise options.maxIterations
Filling the human-review message via $fromAI()Approver signs off on a paraphrase, not the real callUse literal {{ $tool.parameters.<name> }}

What's NOT available via the community MCP

Want to doReality
Chat-test a workflow's AI Agent node end-to-end interactivelyn8n_test_workflow runs the workflow, but a true multi-turn chat session against the node is a UI activity (canvas chat tester). A persisted Agent, by contrast, can be run live via n8n_manage_agents call — see "Persisted n8n Agents" above.
Set credentials' actual secret valuesn8n_manage_credentials creates/updates credential records, but the agent provider keys themselves are entered/verified in the UI.
Assign a workflow's Error WorkflowUI only — see n8n-error-handling. Build the catch-all, then hand the user the UI step.
Pin the exact model availability per instanceModel lists shift between versions — search_nodes/get_node reflect what's installed. Verify on the target instance.

What the MCP can do: search and inspect every LangChain node (search_nodes, get_node), validate node config and the whole graph (validate_node, validate_workflow), build and patch the agent and its sub-nodes (n8n_update_partial_workflow with addConnection on ai_* outputs), test (n8n_test_workflow), and pull the saved JSON to verify wiring (n8n_get_workflow). The deep AI-agent guide also lives in tools_documentation({topic: "ai_agents_guide", depth: "full"}).


Integration with other skills

  • n8n-workflow-patterns (ai_agent_workflow.md) — the high-level "agent in a workflow" shape. This skill is the deep dive; start there for architecture.
  • n8n-mcp-tools-expert — node-type formats (short form for get_node, long form in JSON) and tool-selection guidance. Consult before any MCP call.
  • n8n-node-configuration — displayOptions-driven fields on the agent and sub-nodes; Slack/Block Kit message shapes (NODE_FAMILY_GOTCHAS.md, Slack section).
  • n8n-expression-syntax — {{ }}, $json.output, $now, and $fromAI/$tool.parameters all rely on correct expression syntax.
  • n8n-code-tool — the Custom Code Tool's runtime contract (string in/out, no $fromAI). Read it before writing a .toolCode.
  • n8n-subworkflows — the sub-workflow primitive that .toolWorkflow builds on (Execute Workflow Trigger inputs/outputs, naming, search-before-build).
  • n8n-binary-and-data — owns the agent-tool binary boundary mechanics (staging uploads, returning generated files).
  • n8n-validation-expert — interpreting validate_workflow results, including AI-connection issues (a tool wired into main instead of ai_tool flags as disconnected).
  • n8n-error-handling — onError: 'continueErrorOutput' on tool sub-workflows and the agent-core call; error UX on chat shells.
  • n8n-code-javascript / n8n-code-python — for Code-node logic inside a tool sub-workflow (different sandbox from the Code Tool).

Quick reference checklist

Before shipping an agent:

  • Right node: Agent for tools/memory/multi-turn; Text Classifier for routing; Information Extractor for fields; native node for media
  • Model wired via ai_languageModel
  • Every tool has a verb-first specific name AND a real description
  • $fromAI() descriptions are specific (format, range, example); identity/limits/sessionId plumbed deterministically, not via $fromAI
  • Per-tool guidance lives in tool descriptions, not the system prompt
  • $now in the system prompt (no hardcoded date)
  • maxIterations raised for multi-tool agents
  • Memory keyed on a stable sessionKey from the trigger (not 'default', not $fromAI); contextWindowLength raised from 5
  • Structured output: schemaType: 'manual' + autoFix: true + a coding-capable fixer model
  • Destructive tools wrapped in human review; approval message uses $tool.parameters, not $fromAI
  • Chat bots filter the bot's own user ID (trigger-level or first node)
  • Binary: model vision via passthroughBinaryImages; tools get storage keys, never bytes
  • Validated with validate_workflow and verified with n8n_get_workflow (sub-nodes on ai_*, not main)

Remember: an agent is only as good as its tool names, descriptions, and system-prompt discipline. The model can't see your wiring — it sees a system prompt and a list of named, described tools. Design those like an API and most "the agent won't behave" problems disappear.

© czlonkowski, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files in skills/n8n-agents of czlonkowski/n8n-skills.

  • SKILL.md
  • CHAT_AGENT_PATTERNS.md
  • EXAMPLES.md
  • HUMAN_REVIEW.md
  • MEMORY.md
  • RAG.md
  • README.md
  • STRUCTURED_OUTPUT.md
  • SUBWORKFLOW_AS_TOOL.md
  • SYSTEM_PROMPT.md
  • TOOLS.md

Open the folder on GitHubat commit 19cd793

Compare with similar skills

n8n AI Agent Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

n8n AI Agent Design compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
n8n AI Agent Design this skillczlonkowski/n8n-skills6.4k—~6.8kAutomated safety check: PassMIT
Dive Into LangGraphluochang212/dive-into-langgraph457—~837Automated safety check: NotesCustom licence
LangchainOrchestra-Research/AI-Research-SKILLs13k2 repos~3.2kAutomated safety check: PassMIT
Agentic Patternsrsmdt/the-startup557—~501Automated safety check: PassMIT
Langchain Middlewarelangchain-ai/langchain-skills1.3k—~2.7kAutomated safety check: PassMIT
N8n Agentssickn33/agentic-awesome-skills47k1 repos~6kAutomated safety check: PassMIT

Similar skills

  • Dive Into LangGraph

    luochang212/dive-into-langgraph

    A Chinese-language guide and reference for building agents with LangGraph 1.0, from a first ReAct agent through middleware, memory, MCP, RAG and web search.

    457 GitHub stars~837 tokensUpdated 28 days ago
    AI & LLM EngineeringAuto-check: notes
  • Langchain

    Orchestra-Research/AI-Research-SKILLs

    Framework for building LLM-powered applications with agents, chains, and RAG.

    13k GitHub starsUsed in 2 repos~3.2k tokens
    AI & LLM EngineeringAuto-check passed
  • Agentic Patterns

    rsmdt/the-startup

    Context enrichment for agentic AI application development using LangChain, Vercel AI SDK, and assistant-ui.

    557 GitHub stars~501 tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check passed
  • Langchain Middleware

    langchain-ai/langchain-skills

    Official

    INVOKE THIS SKILL when you need human-in-the-loop approval, custom middleware, or structured output.

    1.3k GitHub stars~2.7k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • N8n Agents

    sickn33/agentic-awesome-skills

    Design n8n AI agents, chains, classifiers, extractors, tool calling, memory, RAG, structured output, and human-review flows.

    47k GitHub starsUsed in 1 repo~6k tokens
    Productivity & AutomationAuto-check passed
  • Agent Builder

    n8n-io/n8n

    Official

    Load immediately after an Agent intent. An agent skill from n8n-io/n8n.

    207k GitHub stars~2.5k tokensUpdated today
    AI & LLM EngineeringAuto-check passed

More from czlonkowski/n8n-skills

All 15 skills in this repo
  • n8n Binary Data Handling

    czlonkowski/n8n-skills

    Explains how n8n keeps file bytes in $binary apart from structured $json data, and how to read, write and preserve binary across nodes, agent tools and chat.

    6.4k GitHub stars~3.9k tokensUpdated 23 days ago
    Auto-check passed
  • n8n Code Node JavaScript

    czlonkowski/n8n-skills

    Guides writing JavaScript in n8n Code nodes: picking an execution mode, reading input data, returning items, using built-in helpers and avoiding common errors.

    6.4k GitHub stars~4.9k tokensUpdated 23 days ago
    Auto-check passed
  • Native Python in n8n Code Nodes

    czlonkowski/n8n-skills

    Explains how to write native Python in n8n Code nodes, including the two input variables, blocked imports and fixes for common errors.

    6.4k GitHub stars~2.8k tokensUpdated 23 days ago
    Auto-check passed
  • n8n Custom Code Tool Guide

    czlonkowski/n8n-skills

    Explains the n8n Custom Code Tool's actual runtime contract so an AI-agent-callable tool doesn't get written like a regular workflow Code node.

    6.4k GitHub stars~4k tokensUpdated 23 days ago
    Auto-check passed
  • n8n Error Handling

    czlonkowski/n8n-skills

    Wires n8n workflows so failures are visible and recoverable: per-node error outputs, retries, error workflows and correct 4xx and 5xx webhook responses.

    6.4k GitHub stars~5.1k tokensUpdated 23 days ago
    Auto-check passed
  • n8n Multi-Instance Targeting

    czlonkowski/n8n-skills

    Keeps an n8n MCP session pointed at the right n8n instance, with rules for discovering, switching and verifying the target before credential writes and for recovering from misroutes.

    6.4k GitHub stars~3.2k tokensUpdated 23 days ago
    Auto-check passed

Works with

Questions about n8n AI Agent Design

What does n8n AI Agent Design do?

Guide to designing n8n AI agents: choosing between Agent, chain, classifier and extractor nodes, wiring model, memory, tools and parser, plus RAG and human review. This skill is a deep guide to building the AI Agent node in n8n and the LangChain-family nodes around it. It opens with choosing the right node, since using an Agent for one-shot classification or extraction is the most common over-build: Basic LLM Chain for text in and out, Text Classifier for routing into several branches, Information Extractor for schema-based fields, plus sentiment analysis and summarization nodes.

When should I use n8n AI Agent Design?

n8n AI Agent Design fits situations like: building or editing an n8n AI Agent, LLM chain or Text Classifier node; giving an n8n agent tools and writing their names and descriptions; forcing structured JSON output from an n8n LLM node; adding memory, RAG or human review to an n8n chat assistant.

How do I install n8n AI Agent Design in Claude Code?

Run `npx skills add czlonkowski/n8n-skills --skill n8n-agents -a claude-code`. Or copy the skill folder (skills/n8n-agents in czlonkowski/n8n-skills) into .claude/skills/n8n-agents in your project. Claude Code loads it when a task matches its description.

How do I install n8n AI Agent Design in Codex?

Run `npx skills add czlonkowski/n8n-skills --skill n8n-agents -a codex`. Or copy the skill folder (skills/n8n-agents in czlonkowski/n8n-skills) into .agents/skills/n8n-agents in your project. Codex loads it when a task matches its description.

Can I use n8n AI Agent Design in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add czlonkowski/n8n-skills --skill n8n-agents -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/n8n-agents, .gemini/skills/n8n-agents, .github/skills/n8n-agents and .opencode/skills/n8n-agents in your project.

What does n8n AI Agent Design need to run?

Going by SKILL.md and its folder, n8n AI Agent Design needs credentials named N8N_MCP_ACCESS_TOKEN. Our summary lists: An n8n instance with the LangChain AI nodes; The n8n MCP tools (get_node, validate_node) for checking nodes.

Does n8n AI Agent Design access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is n8n AI Agent Design safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does n8n AI Agent Design use?

n8n AI Agent Design is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does n8n AI Agent Design use?

About 6.8k tokens (SKILL.md is roughly 27k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to n8n AI Agent Design?

Skills that share tags, products or a category with n8n AI Agent Design: Dive Into LangGraph (luochang212/dive-into-langgraph, 457 stars), Langchain (Orchestra-Research/AI-Research-SKILLs, 13k stars), Agentic Patterns (rsmdt/the-startup, 557 stars) and Langchain Middleware (langchain-ai/langchain-skills, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains n8n AI Agent Design?

czlonkowski (a GitHub user) maintains it in czlonkowski/n8n-skills, which has 6,396 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on September 16, 2026.

Source: czlonkowski/n8n-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.