odoo-dev-assistant

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill mostly aligns with Odoo admin/dev work and uses official Odoo/PostgreSQL tooling for the core database actions, so it is not fundamentally incompatible with its stated purpose. However, it is over-broad, includes credential exposure by instructing the agent to read and directly report db_password from odoo.conf, and adds an unpinned third-party npx package for HTML conversion. The main risk is privileged local admin activity plus unnecessary secret disclosure, not clear malware or external exfiltration.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:53 AM
Package URL
pkg:socket/skills-sh/imHansiy%2Fmy-skills%2Fodoo-dev-assistant%2F@160973f0f7089693db265de93f371d8f8d30dd17