Introduction¶
DeepSeek Harness adopts a plugin-based architecture, allowing developers to extend its capabilities to integrate with different systems. When integrating enterprise-grade ERP systems (such as Odoo), a common scenario is enabling an agent to inspect business data (contacts, quotations, sales orders, invoices, etc.) while ensuring that no system state is changed. The maxmilian/dsh-odoo plugin is designed to address this need. It provides a secure set of read-only tools and includes an optional, restricted draft-creation capability.
What Is It¶
maxmilian/dsh-odoo is an open-source DeepSeek Harness plugin for accessing the Odoo external API. The plugin is maintained by maxmilian and is released under the MIT license. Its core value is to give an agent read-only access to Odoo data by default, and to offer extremely limited draft-creation capabilities only when explicitly enabled by the user.
Core Features¶
The plugin provides the following tools:
-
odoo_server_info
Reads the server version and authenticated user ID. -
odoo_describe_model
Lists queryable fields for models in the allow list. -
odoo_search_read
Runs a restrictedsearch_readoperation on models in the allow list. -
odoo_create_draft
Creates a draft record. This tool is not registered by default and is available only when theallowWriteconfiguration option is set totrue.
Installation and Dependencies¶
Installing the plugin requires Bun.
bun install
Runtime requirements:
* Node.js 22.19 or higher (22.x series) or Node.js 24 or higher
* Bun 1.3.5 or higher
Configuration¶
The plugin is configured through environment variables to avoid leaking sensitive information.
export ODOO_URL='https://odoo.example.com'
export ODOO_DB='production'
export ODOO_USERNAME='integration@example.com'
export ODOO_API_KEY='your-api-key'
Key configuration options:
* allowWrite: Defaults to false. When set to true, the odoo_create_draft tool is registered.
* defaultLimit: The default value is 20, with a range of 1-100.
* maxResponseBytes: A hard byte limit, with a default value of 1000000 (1MB) and a range of 1-52428800.
Typical Usage¶
The plugin uses the JSON-RPC 2.0 transport protocol, with the request endpoint POST {baseUrl}/jsonrpc. When using it, first call odoo_describe_model to confirm that the target model exists in the current instance, and then use odoo_search_read to query it.
Applicable Scenarios and Notes¶
- Applicable scenarios: Suitable for scenarios that require only inspecting Odoo business data without modifying it, such as data audits and status analysis.
- Security restrictions:
- Read-only by default; no
write,unlink, or workflow actions are available. - Query models are restricted to 14 allow-list models.
- Relationship traversal is not supported, and domain field names cannot contain dots.
- Binary fields are not supported.
- Responses are subject to byte-length and record-count limits.
- Read-only by default; no
- Known limitations:
- Only tested with Odoo 18. Odoo 19, Odoo Online, and Odoo.sh are untested.
- Draft creation supports only
sale.orderand is fixed to draft status.
Conclusion¶
maxmilian/dsh-odoo provides a foundational capability for securely accessing Odoo data in DeepSeek Harness. If you need to integrate Odoo into an agent and have strict security requirements, you can use this plugin as a reference for implementing data reads.