Claude security directory
Catalyst by Zoho
Published by Catalyst by Zoho
High risk
Catalyst by Zoho is a full-stack development platform for building web applications, APIs, automation workflows, and AI-powered software. The Codex plugin helps developers use Catalyst services directly from their coding workflow, making it easier to create backends, manage databases and storage, deploy applications, automate tasks, and integrate with Zoho and external services without switching between multiple tools.
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.
Available capabilities
This add-on exposes 4 tools or capabilities.
- ZohoMCP_executeTool
- ZohoMCP_getFeatures
- ZohoMCP_getSchema
- ZohoMCP_listTools
The interactive security report will load automatically.