catalyst-zoho-mcp

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for users to configure their AI clients (Claude Desktop, Cursor, VS Code) to connect to official Zoho Catalyst MCP servers. These instructions use legitimate Zoho domains (e.g., catalyst.zohomcp.com) and follow standard MCP setup procedures.
  • [SAFE]: The instructions include a mandatory 'pre-flight sequence' that requires the agent to list organizations and projects before performing any infrastructure changes. This is a security best practice to ensure the agent operates within the correct, intended project context.
  • [SAFE]: The skill contains a 'Hard Stop' instruction that explicitly forbids the agent from writing code or calling SDKs if the expected tools are not connected, preventing the agent from attempting insecure fallbacks or hallucinating capabilities.
  • [SAFE]: Infrastructure management is performed through structured tool calls (CatalystbyZoho_*) which adhere to specific schemas, reducing the risk of malformed input or command injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 07:15 AM
Security Audit — agent-trust-hub — catalyst-zoho-mcp