odoo-security
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill integrates with a CLI tool named
odoo-aito perform security introspection tasks, such as dumping ACLs and record rules from an Odoo database (e.g.,odoo-ai --db <DB> brief <model>) and validating Python source files for security best practices. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data from Odoo databases and source code files, creating an indirect prompt injection surface. (1) Ingestion points: database metadata and Python source files via the
odoo-aitool. (2) Boundary markers: no specific delimiters are defined in the instructions for tool output. (3) Capability inventory: the tool can read database state and trace model method execution. (4) Sanitization: the instructions do not explicitly mandate sanitization of the ingested data.
Audit Metadata