Introduction

DeepSeek Harness adopts a plugin-based architecture, allowing developers to extend its capabilities to integrate with different systems. When integrating enterprise-grade ERP systems (such as Odoo), a common scenario is enabling an agent to inspect business data (contacts, quotations, sales orders, invoices, etc.) while ensuring that no system state is changed. The maxmilian/dsh-odoo plugin is designed to address this need. It provides a secure set of read-only tools and includes an optional, restricted draft-creation capability.

What Is It

maxmilian/dsh-odoo is an open-source DeepSeek Harness plugin for accessing the Odoo external API. The plugin is maintained by maxmilian and is released under the MIT license. Its core value is to give an agent read-only access to Odoo data by default, and to offer extremely limited draft-creation capabilities only when explicitly enabled by the user.

Core Features

The plugin provides the following tools:

  1. odoo_server_info
    Reads the server version and authenticated user ID.

  2. odoo_describe_model
    Lists queryable fields for models in the allow list.

  3. odoo_search_read
    Runs a restricted search_read operation on models in the allow list.

  4. odoo_create_draft
    Creates a draft record. This tool is not registered by default and is available only when the allowWrite configuration option is set to true.

Installation and Dependencies

Installing the plugin requires Bun.

bun install

Runtime requirements:
* Node.js 22.19 or higher (22.x series) or Node.js 24 or higher
* Bun 1.3.5 or higher

Configuration

The plugin is configured through environment variables to avoid leaking sensitive information.

export ODOO_URL='https://odoo.example.com'
export ODOO_DB='production'
export ODOO_USERNAME='integration@example.com'
export ODOO_API_KEY='your-api-key'

Key configuration options:
* allowWrite: Defaults to false. When set to true, the odoo_create_draft tool is registered.
* defaultLimit: The default value is 20, with a range of 1-100.
* maxResponseBytes: A hard byte limit, with a default value of 1000000 (1MB) and a range of 1-52428800.

Typical Usage

The plugin uses the JSON-RPC 2.0 transport protocol, with the request endpoint POST {baseUrl}/jsonrpc. When using it, first call odoo_describe_model to confirm that the target model exists in the current instance, and then use odoo_search_read to query it.

Applicable Scenarios and Notes

  • Applicable scenarios: Suitable for scenarios that require only inspecting Odoo business data without modifying it, such as data audits and status analysis.
  • Security restrictions:
    • Read-only by default; no write, unlink, or workflow actions are available.
    • Query models are restricted to 14 allow-list models.
    • Relationship traversal is not supported, and domain field names cannot contain dots.
    • Binary fields are not supported.
    • Responses are subject to byte-length and record-count limits.
  • Known limitations:
    • Only tested with Odoo 18. Odoo 19, Odoo Online, and Odoo.sh are untested.
    • Draft creation supports only sale.order and is fixed to draft status.

Conclusion

maxmilian/dsh-odoo provides a foundational capability for securely accessing Odoo data in DeepSeek Harness. If you need to integrate Odoo into an agent and have strict security requirements, you can use this plugin as a reference for implementing data reads.