odoo-demo-csv

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill researches external websites and uses the findings to populate a database, creating an indirect prompt injection surface. * Ingestion points: Prospect company websites analyzed in the research phase. * Boundary markers: Absent; there are no instructions to use delimiters or ignore potentially malicious instructions embedded in the website content. * Capability inventory: Shell command execution via the odoo-crud tool (used for module installation, searching, and CSV importing) and local file writing for CSV generation. * Sanitization: Absent; the skill suggests double-quoting for CSV format safety but does not describe any methods for filtering or sanitizing the data content itself.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill uses the odoo-crud set-image command to fetch content from arbitrary URLs found during web research. This represents network operations targeting non-whitelisted external domains.
  • [COMMAND_EXECUTION]: The agent uses the odoo-crud tool, which is a shell command, to perform administrative tasks like installing modules and importing data. The arguments for these commands are dynamically generated from data extracted during external research.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:33 AM
Security Audit — agent-trust-hub — odoo-demo-csv