跳到主内容
智客 ZICQ

技能库 智客分类:安全测试 catalyst-functions

Catalyst Functions

催化器无服务器函数——所有7个类型(基本一/O,高级一/O,事件,克龙,工作,集成,浏览器逻辑),处理器签名,催化剂-配置.json,安全规则,API 出入口路由,文件上传,快活,快活中间软件,环境变量,函数URL,以及函数测试. 需要MCP连接——在任何操作前检查CatorystbyZoho_*-工具. 在“ write a 函数”、“ catalyst 函数”、“ API Gateway ” 、 “ security rules” 、 “ 函数未找到 ” 、 “ 函数返回 401 ” 、 “ busboy” 、 “ middleware ” 、 “ 函数 URL ” 、 “ 函数环境变量 ” 、 “ 复制 CORS 头条 ” 、 “ CORS 浏览器错误 ” 、 “ Access- Control- Allow- Origin 多重值” 、 “ 函数 URL 404 ” 、 “ 执行后缀 ” 、 “ 函数超时 ” 、 “ 函数挂起” 或任何函数类型问题 。 不要用于持久服务器,长期运行的过程,或者多克部署——取而代之的是使用催化剂-appsail.

689 安装量

官方网址:skills.sh

技能介绍

先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。

做什么

催化器无服务器函数——所有7个类型(基本一/O,高级一/O,事件,克龙,工作,集成,浏览器逻辑),处理器签名,催化剂-配置.json,安全规则,API 出入口路由,文件上传,快活,快活中间软件,环境变量,函数URL,以及函数测试. 需要MCP连接——在任何操作前检查CatorystbyZoho_*-工具. 在“ write a 函数”、“ catalyst 函数”、“ API Gateway ” 、 “ security rules” 、 “ 函数未找到 ” 、 “ 函数返回 401 ” 、 “ busboy” 、 “ middleware ” 、 “ 函数 URL ” 、 “ 函数环境变量 ” 、 “ 复制 CORS 头条 ” 、 “ CORS 浏览器错误 ” 、 “ Access- Control- Allow- Origin 多重值” 、 “ 函数 URL 404 ” 、 “ 执行后缀 ” 、 “ 函数超时 ” 、 “ 函数挂起” 或任何函数类型问题 。 不要用于持久服务器,长期运行的过程,或者多克部署——取而代之的是使用催化剂-appsail.

何时用

官方 description 未单独写出 Use when。按规范,代理会在用户任务与这段 description 的关键词匹配时激活本技能。

代理如何加载

按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:How It Works、Response Syntax Default、Security Checklist、Triggers、References。

文件分析

文件分析:除 SKILL.md 外,正文引用了 references/functions-basics.md、references/functions-advanced.md、references/api-gateway.md、references/functions-templates.md,属于带资源的技能包,这些文件按需再读。

官方 description(原文)

Catalyst serverless functions — all 7 types (Basic I/O, Advanced I/O, Event, Cron, Job, Integration, Browser Logic), handler signatures, catalyst-config.json, Security Rules, API Gateway routing, file uploads, busboy, Express middleware, environment variables, function URL, and function testing. Requires MCP connection — check for CatalystbyZoho_* tools before any operation. Trigger on 'write a function', 'catalyst function', 'API Gateway', 'Security Rules', 'function not found', 'function returns 401', 'busboy', 'middleware', 'function URL', 'environment variable in function', 'duplicate CORS headers', 'CORS error in browser', 'Access-Control-Allow-Origin multiple values', 'function URL 404', 'execute suffix', 'function timeout', 'function hangs', or any function type question. Do NOT use for persistent servers, long-running processes, or Docker deployments — use catalyst-appsail instead.

How It WorksResponse Syntax DefaultSecurity ChecklistTriggersReferences

兼容:Requires Catalyst CLI (`npm install -g zcatalyst-cli`) and Node.js v20 (recommended; v14–v18 also supported). Java functions also require JDK 8, 11, or 17. Python functions require Python 3.9.

来源分类:skills.sh agent-skill

SKILL.md 与 Agent 调用

官方规范 ↗
name
catalyst-functions
description
Catalyst serverless functions — all 7 types (Basic I/O, Advanced I/O, Event, Cron, Job, Integration, Browser Logic), handler signatures, catalyst-config.json, Security Rules, API Gateway routing, file uploads, busboy, Express middleware, environment variables, function URL, and function testing. Requires MCP connection — check for CatalystbyZoho_* tools before any operation. Trigger on 'write a function', 'catalyst function', 'API Gateway', 'Security Rules', 'function not found', 'function returns 401', 'busboy', 'middleware', 'function URL', 'environment variable in function', 'duplicate CORS headers', 'CORS error in browser', 'Access-Control-Allow-Origin multiple values', 'function URL 404', 'execute suffix', 'function timeout', 'function hangs', or any function type question. Do NOT use for persistent servers, long-running processes, or Docker deployments — use catalyst-appsail instead.
compatibility
Requires Catalyst CLI (`npm install -g zcatalyst-cli`) and Node.js v20 (recommended; v14–v18 also supported). Java functions also require JDK 8, 11, or 17. Python functions require Python 3.9.
  1. 发现技能客户端向 Agent 提供名称与描述目录。
  2. 匹配与调用用户指定或任务匹配后,载入 SKILL.md 指令。
  3. 按需加载按步骤读取参考文档、使用脚本与素材。
指令中引用的文件 · 4
  • references/functions-basics.md
  • references/functions-advanced.md
  • references/api-gateway.md
  • references/functions-templates.md

以下路径提取自原文;文件是否齐全请以来源仓库中的完整目录为准。

具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗

安装这个技能

Skills CLI ↗

先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。

该技能引用了附属文件,请从来源获取完整目录;仅复制 SKILL.md 可能缺少依赖。

交给 Agent 安装

复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。

把 Agent Skill「catalyst-functions」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-560071c35fb314c7-Catalyst-Functions.html
请存为 .cursor/skills/catalyst-functions/SKILL.md 或 .claude/skills/catalyst-functions/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。
该技能还带 scripts/、references/、assets/ 等文件,请从 https://github.com/catalystbyzoho/agent-skills 取完整目录,不要只建一个 SKILL.md。

GitHub 完整包 ↗

终端安装 · Skills CLI

需要 Node.js 与 npx。先查看仓库技能列表,确认实际名称。

npx skills add 'https://github.com/catalystbyzoho/agent-skills' --list

npx skills add 'https://github.com/catalystbyzoho/agent-skills' --skill 'catalyst-functions'

CLI 会交互选择目标 Agent,默认安装到项目;用户级安装使用 -g。先通过查看命令核对仓库内容,再用 npx skills list 检查已安装技能。

阅读排版
--- name: catalyst-functions description: "Catalyst serverless functions — all 7 types (Basic I/O, Advanced I/O, Event, Cron, Job, Integration, Browser Logic), handler signatures, catalyst-config.json, Security Rules, API Gateway routing, file uploads, busboy, Express middleware, environment variables, function URL, and function testing. Requires MCP connection — check for CatalystbyZoho_* tools before any operation. Trigger on 'write a function', 'catalyst function', 'API Gateway', 'Security Rules', 'function not found', 'function returns 401', 'busboy', 'middleware', 'function URL', 'environment variable in function', 'duplicate CORS headers', 'CORS error in browser', 'Access-Control-Allow-Origin multiple values', 'function URL 404', 'execute suffix', 'function timeout', 'function hangs', or any function type question. Do NOT use for persistent servers, long-running processes, or Docker deployments — use catalyst-appsail instead." compatibility: "Requires Catalyst CLI (`npm install -g zcatalyst-cli`) and Node.js v20 (recommended; v14–v18 also supported). Java functions also require JDK 8, 11, or 17. Python functions require Python 3.9." metadata: version: "2.0.2" --- ## How It Works **Intent check — do this first:** - If the user is asking a how-to or conceptual question ("how do I write a function", "show me a Basic I/O handler", "how does Security Rules work"), answer directly with the correct code or explanation. Do NOT inspect the working directory, do NOT generate a CLAUDE.md, do NOT switch into codebase-analysis mode. Empty directory = fine for how-to questions. - Only inspect the filesystem when the user explicitly asks to scaffold, add, or deploy something in their project. 1. **Verify local scaffold (only when scaffolding, not for how-to questions) — both `catalyst init` and `functions:add` support non-interactive mode (CLI v1.27.0+).** Check whether `.catalystrc` exists. If missing, use MCP tools to get the org ID and project ID, then run: ```bash catalyst init --org -p -ni ``` Never ask the user to run `catalyst init` interactively. NI mode can only link an existing project — if none exists, tell the user to create one in the console first. `catalyst.json` does not exist yet after `init -ni` — that is expected. Add functions next (this creates `catalyst.json`): ```bash catalyst functions:add --name --type --stack -ni # e.g. catalyst functions:add --name api --type aio --stack node20 -ni ``` 2. **Identify the function type** — Basic I/O for simple request/response, Advanced I/O for raw HTTP control, Event for trigger-based, Cron/Job for scheduled, Integration for Zoho service events, Browser Logic for Puppeteer. 3. **Load `references/functions-basics.md`** — for the matching handler signature, `catalyst-config.json` keys, SDK init pattern, and CORS setup. 4. **Load `references/functions-advanced.md`** — for file uploads (busboy), streaming responses, error handling, or chaining functions. 5. **Load `references/api-gateway.md`** — for routing rules, rate limiting, or gateway-level CORS. 6. **Validate config** — Confirm `catalyst-config.json` uses `deployment` + `execution` keys only. Never use `function` or `entry_point`. ## Response Syntax Default **Always default to native Node.js response syntax.** Advanced I/O exposes raw `http.ServerResponse` — Express methods (`res.status()`, `res.json()`) do not exist unless the user explicitly chose the Express template. - Native (default): `res.writeHead(200, { 'Content-Type': 'application/json' }); res.end(JSON.stringify(data));` - Express (opt-in only): `res.status(200).json(data)` — only if the user has `express` installed and wired as middleware If you don't know which template the user has, ask or default to native. ## Security Checklist - **Functions are publicly accessible by default.** Security Rules sets `authentication` to `optional` when a function is created — its URL is globally accessible to everyone with no restrictions. Set `"authentication": "required"` in the Security Rules JSON for any function that reads or writes user data or sensitive resources. - **API Gateway replaces Security Rules — do not use both.** Enabling API Gateway automatically disables Security Rules. Pick one auth/routing layer per function. ## Triggers Use this skill for: "write a function", "catalyst function", "Basic I/O", "Advanced I/O", "Event function", "Cron function", "Browser Logic", `catalyst-config.json`, "function handler", "API Gateway", "rate limiting", "busboy", "file upload in function", `catalyst deploy --only functions:`, `catalyst functions:add`, "function CORS", or any function type or function configuration question. Deployment command note: - Use `catalyst deploy --only functions:` to deploy one function (where `functions:` targets the function by its folder name). - Use `catalyst deploy --only functions` to deploy all functions at once. ## References | Reference | Load when the query is about… | |-----------|-------------------------------| | `references/functions-basics.md` | **Start here for any function question.** Function type selection, Basic I/O and Advanced I/O handler signatures, `catalyst-config.json`, user-scope vs admin-scope, CORS, Security Rules, execution limits | | `references/functions-advanced.md` | **Advanced I/O patterns only.** Express vs raw-http template differences, file uploads (busboy), streaming files from Stratus, error handling patterns, CORS for local dev, local testing, function chaining, ZCQL result unwrapping, HTTP payload limits | | `references/functions-templates.md` | **Event, Cron, Job, or Integration functions.** Handler templates for all background/scheduled types, SDK component reference, retry behavior, cold start data, and the full common errors table | | `references/api-gateway.md` | **API Gateway config only.** Enable/disable gateway, routing rules, rate limiting, CORS via gateway |

相关技能

安全测试

Skill Vetter

人工智能特工的安全第一技能审查。 在安装来自 ClawdHub, GitHub 或其他来源的任何技能之前使用 。 检查红旗,许可范围,可疑图案.

安全测试

Moltguard

MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tre…

安全测试

Security Auditor

用于审查安全漏洞代码,实施认证流,审计OWASP Top 10,配置CORS/CSP头,处理秘密,输入验证,SQL注射预防,XSS保护,或任何与安全相关的代码审查.

安全测试

Skill Vetter

安装任何AI代理技能前的安全审查协议. 红旗侦取入证盗取,疏通密码,放出. 风险分类:低/中/高/高。 编制结构化审查报告。 不先运行此功能, 绝不安装不信任的技能 .