Audit History
zoho-crm-automation - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Sep 7, 2026, 02:58 PM | 1 confirmed | 1 | No capability change |
| v4 | Jul 7, 2026, 05:26 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 7, 2026, 05:26 AM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 07:54 PM | 1 confirmed | 1 | External commands |
| v1 | Feb 25, 2026, 11:05 AM | No confirmed findings | 1 | Baseline |
Sep 7, 2026, 02:58 PM
All external-command alerts are Markdown false positives, and the reconnaissance alert describes a Zoho record ID. Rube MCP is a real third-party network dependency, while CRM mutations lack an explicit confirmation requirement.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (47)
🌐 Network access (1)
Jul 7, 2026, 05:26 AM
All static findings were adjudicated as false positives after reviewing SKILL.md. The repeated command findings are Markdown references to MCP tool names, the URL is the expected Rube MCP endpoint, and no prompt injection or malicious intent was found.
Risk Factors
⚙️ External commands (47)
🌐 Network access (1)
Jul 7, 2026, 05:26 AM
All static findings were adjudicated as false positives after reviewing SKILL.md. The repeated command findings are Markdown references to MCP tool names, the URL is the expected Rube MCP endpoint, and no prompt injection or malicious intent was found.
Risk Factors
⚙️ External commands (47)
🌐 Network access (1)
Jun 30, 2026, 07:54 PM
Static external-command and weak-crypto findings are false positives caused by markdown backticks, tool names, and CRM text. The confirmed risk is legitimate network-based CRM automation through Rube MCP, which can read and modify sensitive Zoho CRM records.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (1)
Feb 25, 2026, 11:05 AM
All 59 static analysis findings are false positives. The detected patterns are markdown code literals documenting API tool names (e.g., ZOHO_LIST_MODULES, RUBE_SEARCH_TOOLS) and the legitimate Rube MCP service endpoint. No malicious code execution, data exfiltration, or security vulnerabilities present. This is documentation-only content for a Zoho CRM integration skill.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.