odoo19-coding-guidelines

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill contains guidelines for Odoo 19 development. It promotes security by documenting common pitfalls such as raw SQL injection, unsafe HTML handling, and dynamic attribute access, advising users to follow secure ORM patterns instead. No malicious code, hidden instructions, or unauthorized data access patterns were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes Odoo source code provided in the agent's context to provide reviews and modifications, which creates a surface for indirect prompt injection.
  • Ingestion points: Processes Odoo module files including Python models, XML views, and JavaScript components.
  • Boundary markers: No explicit delimiters are used to isolate the source code being analyzed from the skill's instructions.
  • Capability inventory: The skill is purely informational and does not execute system commands, access the network, or modify the file system.
  • Sanitization: The skill identifies security risks in reviewed code but does not implement sanitization for its own input context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — odoo19-coding-guidelines