Odoo Web Security
SkillWeb & browsingSecurity review and implementation guidance for Odoo website, portal, public controllers, JSON routes, QWeb output, and browser-facing assets. Use when exposing Odoo data over HTTP, adding portal/public pages or forms, using sudo, handling tokens, rendering HTML, or reviewing web attack surfaces.
Use Odoo Web Security in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Odoo Web Security and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Odoo Web Security skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by mart337i/odoo-skills in skills/odoo-web-security/SKILL.md and read by Ahel’s review.
Use this skill at every Odoo web trust boundary. Compose it with odoo-website, odoo-code-review, and the version-specific Odoo skill.
Threat Model First
Identify the caller, authentication mode, record being accessed, mutation being performed, and data that crosses the browser boundary. Treat route parameters, query strings, form fields, JSON payloads, headers, cookies, and browser state as attacker-controlled.
Read SECURITY-CHECKLIST.md before editing or approving a web-facing change.
Non-Negotiable Checks
auth='public'is not a substitute for a publication policy.- Portal identity and record ownership must be checked server-side.
sudo()must be narrow, justified, and followed by an explicit visibility check.- Never authorize a record from its numeric ID, token shape, or hidden form field alone.
- Use ORM security and record rules where possible; do not bypass them with raw SQL or broad elevation.
- Escape output by default and review HTML sanitization separately from escaping.
- Validate redirects, URLs, uploaded files, and external API destinations.
- Preserve CSRF protection for state-changing browser requests according to the route type and target version.
Review Output
For each finding, state the attacker, entry point, missing control, affected data/action, and a concrete test that would fail before the fix.
Signals
- GitHub stars
- 40
- Forks
- 11
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
odoo-web-security- Source
- github.com/mart337i/odoo-skills
github.com/mart337i/odoo-skills
Related picks
Skill · wshobson
The pick for Pythonpython-pro
Skill · jeffallan
The pick for Pythonchecking-owasp-compliance
Skill · jeremylongshore
The pick for Web (OWASP)owasp-security
Skill · davila7
The pick for Web (OWASP)browser-use
Skill · browser-use
More in Web & browsingwebapp-testing
Skill · anthropics
More in Web & browsing