Skip to main content
Manus에서 모든 스킬 실행
원클릭으로

odoo-security-audit

스타7
포크3
업데이트2026년 7월 18일 02:55

Audit Odoo Python, JavaScript, XML, and QWeb code for security vulnerabilities - severity-graded findings report with file/line, exploit path, and concrete fix. Reporting only - does NOT write fixes. Covers: SQL injection (cr.execute with f-string/% concat), XSS (t-raw / Markup misuse), access control gaps (missing ir.model.access.csv, sudo() ACL bypass, unsafe auth='public'), CSRF, unsafe deserialization (eval/pickle/safe_eval), hardcoded secrets. Trigger on: "audit security", "is this code safe", "SQL injection risk", "XSS in QWeb", "check access control", "sudo bypass", "hardcoded secret", "CSRF in controller". Vietnamese triggers: "kiểm tra bảo mật code Odoo", "có bị SQL injection không", "review bảo mật trước khi deploy", "t-raw có an toàn không". Also fires when user shares controller/model/view code and asks "okay to ship?" or "anything to worry about". For fixes route to odoo-coding; for a runtime symptom needing root-cause route to odoo-debug

설치

Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.

파일 탐색기
2 개 파일
SKILL.md
readonly