odoo-dev-assistant
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
python,psql,pg_restore, andcreatedbto manage Odoo databases and files. - [EXTERNAL_DOWNLOADS]: Fetches and executes the
markdown-to-html-clipackage from the NPM registry during document generation. - [PROMPT_INJECTION]: Ingests potentially untrusted external inputs such as Markdown documentation and Odoo backup archives, presenting an indirect injection surface.
- Ingestion points: Processes local files and backup archives in SKILL.md.
- Boundary markers: Not specified.
- Capability inventory: Includes shell command execution and database modifications.
- Sanitization: Not explicitly implemented for external file content.
Audit Metadata