Scope the credential, separate read from write, require approval on writes, write to a staging field or object before the real one, and log every call with its arguments. The prompt is not a control: an instruction not to write is a suggestion, a read only credential is a boundary.
Not a malicious agent. A bad enrichment result written confidently into a field somebody else's report depends on, four thousand times, overnight, correctly according to every instruction it was given. The chain is enrich a company from a domain into write crm records and the weak link is the join between them, not either tool.
A CRM note is text a stranger may have written. If your agent reads notes and can also call tools, the note is an input channel. Keep destructive tools behind approval, and do not let a research loop and a write loop run unsupervised in the same session.
The verbatim auth field, whether the vendor offers OAuth, and whether the credential can be scoped. 91 of the 165 servers here document an OAuth flow, which is the shape you want for anything that writes.
Every number on this page is generated from directory.json at build time and carries the date it was baked: 2026-08-25. Nothing is typed by hand, nothing is rounded, and nothing is estimated. The underlying data is published in full. Where the honest answer is a zero, the zero is printed.