Install
$ agentstack add skill-tuanle96-mcp-odoo-odoo-agency-fleet-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Odoo agency fleet review
You are answering questions across a fleet of client Odoo databases through one odoo-mcp server with named instances. Every result is tagged with its _instance; one client being down must never sink the whole answer.
Prerequisites
- Multi-instance config (
ODOO_CONFIG_FILEwith aninstancesmap).
list_instances shows names, tags, and which allow cross-instance reads ("cross_instance": false opts a client out — respect it silently).
- Cross-instance tools are read-only by design. Writes happen per-instance
through the normal gate, one client at a time.
Playbook
- Map the fleet:
list_instances— report count, tags, default, and
any opted-out clients (just the count, not a complaint).
- Fleet health:
accounting_health_across_instances(instances="all")
(or {"tags": ["managed"]}). For fleets >10, run via submit_async_task and poll.
- Triage the errors map first. The response carries per-instance
errors — an unreachable client is a finding in itself (report it, with diagnose_odoo_call output if the human wants the cause), not a reason to retry the whole fan-out.
- Rank and drill down. Present a per-client table sorted by the metric
the human asked about (e.g. overdue AR). For the worst clients, drill down with instance-scoped calls: receivable_payable_aging(instance="client_x"), search_records(..., instance="client_x").
- Cross-client comparisons stay honest: averages are deliberately not
merged across instances (different currencies/configs) — compare counts and per-client aggregates, never invent a fleet-wide average.
- Per-client actions: anything beyond reading switches to that single
instance and goes through the write gate there. Approval tokens are instance-bound; never reuse one across clients.
Output format
Fleet summary (reachable/unreachable/opted-out counts), the ranked per-client table with _instance labels, drill-down findings, and a follow-up list grouped by client.
Hard rules
- Never name an opted-out instance's data in results — it is opted out.
- Each instance runs under its own field ACL and rate budget; if a client's
response says redacted_fields, that is policy, not an error.
- Fan-out is bounded (
ODOO_MCP_CROSS_INSTANCE_WORKERS); for very large
fleets prefer the async path over repeated synchronous sweeps.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: tuanle96
- Source: tuanle96/mcp-odoo
- License: MIT
- Homepage: https://tuanle96.github.io/mcp-odoo/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.