zoho-crm-automation

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Zoho CRM records, establishing an indirect prompt injection surface.
  • Ingestion points: Record data retrieved via ZOHO_SEARCH_ZOHO_RECORDS and ZOHO_GET_ZOHO_RECORDS in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content are provided for handling retrieved record data.
  • Capability inventory: The skill can modify or create records using ZOHO_CREATE_ZOHO_RECORD, ZOHO_UPDATE_ZOHO_RECORD, and ZOHO_CONVERT_ZOHO_LEAD.
  • Sanitization: No explicit data validation or sanitization logic is defined.
  • [EXTERNAL_DOWNLOADS]: The skill references an external MCP server endpoint and toolkit documentation.
  • References: https://rube.app/mcp and https://composio.dev/toolkits/zoho.
  • Context: These resources belong to well-known services (Composio/Rube) and are necessary for the skill's functional purpose of CRM automation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:24 PM
Security Audit — agent-trust-hub — zoho-crm-automation