Back to skill

Security audit

Odoo

Security checks across malware telemetry and agentic risk

Overview

This Odoo guidance skill is coherent and safety-focused, though users should scope its access carefully because it can guide work in live ERP systems.

Before installing, decide whether the agent may use this skill only when Odoo is explicitly mentioned, and review the ~/odoo/ memory files periodically. Use least-privileged Odoo accounts, prefer staging or read-only review for risky work, and require explicit approval before imports, bulk edits, accounting changes, inventory corrections, or automations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation guidance is overly broad, telling the system to engage on generic business terms like 'sales orders', 'stock', or 'purchasing' without clear scoping or confirmation. This can cause the skill to activate in unrelated conversations and collect or apply Odoo-specific context unexpectedly, increasing the chance of inappropriate persistence, unsafe actions, or disclosure of business context across sessions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs itself to store conversation-derived preferences and environment details in a local memory file, but provides no user-facing notice or consent mechanism for that persistence. In an enterprise ERP context, even 'stable notes' like instances, companies, approval boundaries, journals, warehouses, or customizations can be sensitive operational metadata and may create privacy, compliance, and cross-session data leakage risks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger condition is overly broad: phrases like a flow being broken, an import failing, or the user saying 'Odoo is wrong' can activate this triage behavior across many unrelated situations. Broad activation increases the chance the agent enters a troubleshooting mode in the wrong context, potentially producing unsafe or inappropriate operational guidance for production ERP environments.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.