zoho-crm
Zoho CRM API integration with managed OAuth. Manage leads, contacts, accounts, deals, and other CRM records. Use this skill when users want to read, create, upd
Security score
The zoho-crm skill was audited on Feb 18, 2026 and we found 57 security issues across 4 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
Template literal with variable interpolation in command context
| 965 | 'Authorization': `Bearer ${process.env.MATON_API_KEY}` |
Fetch to external URL
| 961 | const response = await fetch( |
Access to .env file
| 965 | 'Authorization': `Bearer ${process.env.MATON_API_KEY}` |
External URL reference
| 6 | For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway). |
External URL reference
| 28 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Leads?fields=First_Name,Last_Name,Email') |
External URL reference
| 37 | https://gateway.maton.ai/zoho-crm/crm/v8/{endpoint} |
External URL reference
| 58 | 1. Sign in or create an account at [maton.ai](https://maton.ai) |
External URL reference
| 59 | 2. Go to [maton.ai/settings](https://maton.ai/settings) |
External URL reference
| 64 | Manage your Zoho CRM OAuth connections at `https://ctrl.maton.ai`. |
External URL reference
| 71 | req = urllib.request.Request('https://ctrl.maton.ai/connections?app=zoho-crm&status=ACTIVE') |
External URL reference
| 83 | req = urllib.request.Request('https://ctrl.maton.ai/connections', data=data, method='POST') |
External URL reference
| 95 | req = urllib.request.Request('https://ctrl.maton.ai/connections/{connection_id}') |
External URL reference
| 109 | "url": "https://connect.maton.ai/?session_token=...", |
External URL reference
| 123 | req = urllib.request.Request('https://ctrl.maton.ai/connections/{connection_id}', method='DELETE') |
External URL reference
| 136 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Leads?fields=First_Name,Last_Name,Email') |
External URL reference
| 186 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Leads?fields=First_Name,Last_Name,Email,Phone,Company') |
External URL reference
| 222 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Contacts?fields=First_Name,Last_Name,Email,Phone') |
External URL reference
| 233 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Accounts?fields=Account_Name,Website,Phone') |
External URL reference
| 244 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Deals?fields=Deal_Name,Stage,Amount') |
External URL reference
| 261 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Leads/7243485000000597000') |
External URL reference
| 308 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Leads', data=data, method='POST') |
External URL reference
| 354 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Contacts', data=data, method='POST') |
External URL reference
| 369 | "Website": "https://acme.com", |
External URL reference
| 373 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Accounts', data=data, method='POST') |
External URL reference
| 408 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Leads', data=data, method='PUT') |
External URL reference
| 459 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Leads?ids=7243485000000619001', method='DELETE') |
External URL reference
| 510 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/Leads/[email protected]') |
External URL reference
| 523 | req = urllib.request.Request(f'https://gateway.maton.ai/zoho-crm/crm/v8/Leads/search?criteria={criteria}') |
External URL reference
| 562 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/org') |
External URL reference
| 619 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/users?type=AllUsers') |
External URL reference
| 664 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/users/7243485000000590001') |
External URL reference
| 689 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/settings/modules') |
External URL reference
| 740 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/settings/fields?module=Leads') |
External URL reference
| 784 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/settings/layouts?module=Leads') |
External URL reference
| 829 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/settings/roles') |
External URL reference
| 866 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/settings/roles/7243485000000026005') |
External URL reference
| 885 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/settings/profiles') |
External URL reference
| 920 | req = urllib.request.Request('https://gateway.maton.ai/zoho-crm/crm/v8/settings/profiles/7243485000000026011') |
External URL reference
| 962 | 'https://gateway.maton.ai/zoho-crm/crm/v8/Leads?fields=First_Name,Last_Name,Email', |
External URL reference
| 979 | 'https://gateway.maton.ai/zoho-crm/crm/v8/Leads', |
External URL reference
| 1033 | req = urllib.request.Request('https://ctrl.maton.ai/connections') |
External URL reference
| 1043 | - Correct: `https://gateway.maton.ai/zoho-crm/crm/v8/Leads` |
External URL reference
| 1044 | - Incorrect: `https://gateway.maton.ai/crm/v8/Leads` |
External URL reference
| 1048 | - [Zoho CRM API v8 Documentation](https://www.zoho.com/crm/developer/docs/api/v8/) |
External URL reference
| 1049 | - [Get Records API](https://www.zoho.com/crm/developer/docs/api/v8/get-records.html) |
External URL reference
| 1050 | - [Insert Records API](https://www.zoho.com/crm/developer/docs/api/v8/insert-records.html) |
External URL reference
| 1051 | - [Update Records API](https://www.zoho.com/crm/developer/docs/api/v8/update-records.html) |
External URL reference
| 1052 | - [Delete Records API](https://www.zoho.com/crm/developer/docs/api/v8/delete-records.html) |
External URL reference
| 1053 | - [Search Records API](https://www.zoho.com/crm/developer/docs/api/v8/search-records.html) |
External URL reference
| 1054 | - [Organization API](https://www.zoho.com/crm/developer/docs/api/v8/get-org-data.html) |
External URL reference
| 1055 | - [Users API](https://www.zoho.com/crm/developer/docs/api/v8/get-users.html) |
External URL reference
| 1056 | - [Modules API](https://www.zoho.com/crm/developer/docs/api/v8/modules-api.html) |
External URL reference
| 1057 | - [Fields API](https://www.zoho.com/crm/developer/docs/api/v8/field-meta.html) |
External URL reference
| 1058 | - [Layouts API](https://www.zoho.com/crm/developer/docs/api/v8/layouts-meta.html) |
External URL reference
| 1059 | - [Roles API](https://www.zoho.com/crm/developer/docs/api/v8/get-roles.html) |
External URL reference
| 1060 | - [Profiles API](https://www.zoho.com/crm/developer/docs/api/v8/get-profiles.html) |
External URL reference
| 1061 | - [Maton Community](https://discord.com/invite/dBfFAcefs2) |