catalyst-functions
Catalyst serverless functions — all 7 types (Basic I/O, Advanced I/O, Event, Cron, Job, Integration, Browser Logic), handler signatures, catalyst-config.json, Security Rules, API Gateway routing, file uploads, busboy, Express middleware, environment variables, function URL, and function testing. Requires MCP connection — check for CatalystbyZoho_* tools before any operation. Trigger on 'write a function', 'catalyst function', 'API Gateway', 'Security Rules', 'function not found', 'function returns 401', 'busboy', 'middleware', 'function URL', 'environment variable in function', 'duplicate CORS headers', 'CORS error in browser', 'Access-Control-Allow-Origin multiple values', 'function URL 404', 'execute suffix', 'function timeout', 'function hangs', or any function type question. Do NOT use for persistent servers, long-running processes, or Docker deployments — use catalyst-appsail instead.
How do I install this agent skill?
npx skills add https://github.com/catalystbyzoho/agent-skills --skill catalyst-functionsIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill provides templates and instructions for developing serverless functions on the Zoho Catalyst platform. It includes guidance on authentication, CORS, and deployment. The identified concerns are primarily related to standard data processing patterns in serverless development.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
How It Works
Intent check — do this first:
- If the user is asking a how-to or conceptual question ("how do I write a function", "show me a Basic I/O handler", "how does Security Rules work"), answer directly with the correct code or explanation. Do NOT inspect the working directory, do NOT generate a CLAUDE.md, do NOT switch into codebase-analysis mode. Empty directory = fine for how-to questions.
- Only inspect the filesystem when the user explicitly asks to scaffold, add, or deploy something in their project.
-
Verify local scaffold (only when scaffolding, not for how-to questions) — both
catalyst initandfunctions:addsupport non-interactive mode (CLI v1.27.0+). Check whether.catalystrcexists. If missing, use MCP tools to get the org ID and project ID, then run:catalyst init --org <orgId> -p <projectId> -niNever ask the user to run
catalyst initinteractively. NI mode can only link an existing project — if none exists, tell the user to create one in the console first.catalyst.jsondoes not exist yet afterinit -ni— that is expected. Add functions next (this createscatalyst.json):catalyst functions:add --name <name> --type <type> --stack <stack> -ni # e.g. catalyst functions:add --name api --type aio --stack node20 -ni -
Identify the function type — Basic I/O for simple request/response, Advanced I/O for raw HTTP control, Event for trigger-based, Cron/Job for scheduled, Integration for Zoho service events, Browser Logic for Puppeteer.
-
Load
references/functions-basics.md— for the matching handler signature,catalyst-config.jsonkeys, SDK init pattern, and CORS setup. -
Load
references/functions-advanced.md— for file uploads (busboy), streaming responses, error handling, or chaining functions. -
Load
references/api-gateway.md— for routing rules, rate limiting, or gateway-level CORS. -
Validate config — Confirm
catalyst-config.jsonusesdeployment+executionkeys only. Never usefunctionorentry_point.
Response Syntax Default
Always default to native Node.js response syntax. Advanced I/O exposes raw http.ServerResponse — Express methods (res.status(), res.json()) do not exist unless the user explicitly chose the Express template.
- Native (default):
res.writeHead(200, { 'Content-Type': 'application/json' }); res.end(JSON.stringify(data)); - Express (opt-in only):
res.status(200).json(data)— only if the user hasexpressinstalled and wired as middleware
If you don't know which template the user has, ask or default to native.
Security Checklist
- Functions are publicly accessible by default. Security Rules sets
authenticationtooptionalwhen a function is created — its URL is globally accessible to everyone with no restrictions. Set"authentication": "required"in the Security Rules JSON for any function that reads or writes user data or sensitive resources. - API Gateway replaces Security Rules — do not use both. Enabling API Gateway automatically disables Security Rules. Pick one auth/routing layer per function.
Triggers
Use this skill for: "write a function", "catalyst function", "Basic I/O", "Advanced I/O", "Event function", "Cron function", "Browser Logic", catalyst-config.json, "function handler", "API Gateway", "rate limiting", "busboy", "file upload in function", catalyst deploy --only functions:<function-name>, catalyst functions:add, "function CORS", or any function type or function configuration question.
Deployment command note:
- Use
catalyst deploy --only functions:<function-name>to deploy one function (wherefunctions:<name>targets the function by its folder name). - Use
catalyst deploy --only functionsto deploy all functions at once.
References
| Reference | Load when the query is about… |
|---|---|
references/functions-basics.md | Start here for any function question. Function type selection, Basic I/O and Advanced I/O handler signatures, catalyst-config.json, user-scope vs admin-scope, CORS, Security Rules, execution limits |
references/functions-advanced.md | Advanced I/O patterns only. Express vs raw-http template differences, file uploads (busboy), streaming files from Stratus, error handling patterns, CORS for local dev, local testing, function chaining, ZCQL result unwrapping, HTTP payload limits |
references/functions-templates.md | Event, Cron, Job, or Integration functions. Handler templates for all background/scheduled types, SDK component reference, retry behavior, cold start data, and the full common errors table |
references/api-gateway.md | API Gateway config only. Enable/disable gateway, routing rules, rate limiting, CORS via gateway |
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/catalystbyzoho/agent-skills/catalyst-functions">View catalyst-functions on skillZs</a>