skills/odoo-ps/ps-ai-skills/odev-ai/Gen Agent Trust Hub

odev-ai

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes technical and functional specifications to populate Odoo records via MCP tools, creating an attack surface where malicious instructions embedded in the specifications could influence agent behavior.
  • Ingestion points: Technical analysis or functional specification documents (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or boundary markers to isolate the untrusted specification text from the agent's core instructions.
  • Capability inventory: The skill utilizes MCP tools to write to various Odoo models, including business logic, database fields, and migration scripts (SKILL.md).
  • Sanitization: No sanitization or validation logic is defined to filter potentially malicious instructions within the specifications before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:19 AM
Security Audit — agent-trust-hub — odev-ai