Back to skill

Security audit

OpenClaw Odoo

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be an Odoo connector, but it needs review because it can make broad business-system changes and the install path is not pinned to reviewed code.

Install only after verifying the exact package source and version you will run. Use a dedicated least-privilege Odoo account, avoid broad admin/accounting permissions, require human approval for create/update/delete/post/confirm/cancel actions, be cautious with fuzzy find-or-create behavior, and protect the configured API key.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned External Package Installation Prevents Verification of Executed Plugin Code

Content
View full analysis
| `odoo_create` | Create records on any model | | `odoo_update` | Update existing records | | `odoo_delete` | Delete records | | `odoo_workflow` | Execute model methods (confirm/cancel/post) | ``` ### Technical Analysis The audited artifact contains only `SKILL.md`; it does not include the advertised TypeScript plugin implementation, package manifest, lockfile, integrity metadata, or distributable code. The installation instruction invokes `npx clawhub install openclaw-odoo`, which resolves and installs an external package without specifying an immutable version or integrity hash. Consequently, the code installed when a user follows this instruction may differ from the content available during this audit. Reviewers cannot verify the plugin's effective implementation, transitive dependencies, network destinations, credential handling, or authorization controls. This is a supply-chain trust issue rather than evidence that the currently advertised package is malicious. Exploitation would require compromise or unauthorized replacement of the package, publisher account, registry, name-resolution process, or a future package release. The exposure is security-sensitive because the documentation states that the plugin: - Authenticates to Odoo using an API key. - Automatically loads configuration from `.env ...[truncated 2033 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

md
1. Log in to your Odoo instance
2. Go to **Settings** → **Users & Companies** → **Users**
3. Open your user record
4. Scroll to **Access Tokens**
5. Click **Generate Token**
6. Copy the token into your config

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill presents itself as a general ERP connector but does not clearly warn that it can create, update, delete, post, confirm, and otherwise trigger irreversible business actions across finance, inventory, HR, and manufacturing. In an agentic context, this omission raises the chance that operators enable the skill without understanding the blast radius of natural-language-triggered actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The install command uses npx clawhub without pinning a specific version, so users may fetch and execute whatever package version is current at install time. In a supply-chain compromise or malicious update scenario, this creates a path to arbitrary code execution on the installing host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented smart-action behavior automatically creates customers, products, projects, and other records based on fuzzy matching and missing dependencies, but it does not prominently warn about unintended record creation or misassociation. In an ERP, this can silently corrupt master data, create bogus vendors/products, or cause downstream financial and operational errors from ambiguous language.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 528)May include surrounding context.

md
│   │   ├── openclaw/           # OpenClaw API helpers + integration
│   │   └── utils/              # Validators + formatting
│   ├── tests/                  # 18 tests (Vitest)
│   ├── skills/odoo/SKILL.md    # This file (bundled AI context)
│   └── dist/                   # Compiled output (CommonJS)
├── README.md                   # User setup guide
├── CHANGELOG.md                # Version history

Static analysis

No suspicious patterns detected.