
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
odoo-pulse
Advanced tools
An AI business analyst for your Odoo ERP. Ask one question, get one answer — numbers, highlights, risks, and a verdict (on-track / at-risk / off-track) — over the Model Context Protocol. CRUD bridges to Odoo already exist; this is the analytics layer that sits on top.

Each tool answers a whole management question in a single call, returning a structured report with a verdict — not a raw dump you have to interpret.
| Tool | Answers |
|---|---|
business_pulse ⭐ | The morning briefing: yesterday's sales, new leads, overdue invoices, late tasks, who's off — with a company-wide verdict |
pipeline_review | CRM funnel by stage, stalled deals, weighted revenue, recent win rate |
sales_snapshot | Revenue this period vs last (Δ%), top customers/products, stale quotations |
receivables_health | AR/AP aging buckets, % overdue, top debtors |
inventory_risk | Shortages (negative forecast) and dead stock |
absence_overview | Who's off this week, pending approvals, thin-coverage departments |
procurement_watch | Purchasing: late receipts, stale RFQs, open spend per vendor |
production_health | Manufacturing: orders behind their planned start, stuck WIP |
project_profitability | Projects: hours logged vs allocated, cost/revenue/margin, budget burn verdict |
project_budget | Budget vs actual per project, line by line — over-plan lines and spend the budget doesn't capture |
team_workload · project_status_report · standup_digest | Project delivery: overloaded members, at-risk projects, and a daily stand-up digest |
Every money-reporting tool takes an optional
company= filter and flags
mixed-currency totals instead of silently summing them; verdict cut-offs
(stalled %, overdue %, growth %) are parameters, so you can calibrate them
to your business.
All report tools take timezone_offset (default 7). Odoo stores datetime
fields in UTC; the tools shift them by timezone_offset hours before
bucketing by calendar day, and day windows in domains are expressed as UTC
datetime boundaries. Date-only fields (e.g. project.milestone.deadline,
invoice_date_due, project.task.date_deadline) are compared as-is.
find_partner searches mobile only on instances that still have it (removed in Odoo 19), and list_timesheets reports an actionable error when hr_timesheet is not installed.
Under the hood it's the standard Odoo XML-RPC external API — nothing to install
inside Odoo, works on Odoo Online, Odoo.sh, and on-premise. Requires
Odoo 18+: the generic tools (search_read, read_records, …) still run on
older versions, but the report tools are not guaranteed there.
No Odoo account? Boot a demo Odoo pre-seeded with a story to tell (a stalled deal, a 90-day-overdue invoice, a stock shortage, someone off today):
docker compose -f deploy/playground/compose.yml up -d
First boot pulls ~4 GB of images (Odoo + Postgres) and seeds the demo data —
allow 5-10 minutes depending on your connection. Then point Claude at it and
ask it to run business_pulse. Full walkthrough:
docs/guides/playground.md.
Add it to Claude Code (no install step — uvx fetches it):
claude mcp add odoo-pulse \
--env ODOO_URL=https://acme.odoo.com \
--env ODOO_DB=acme \
--env ODOO_USERNAME=you@example.com \
--env ODOO_API_KEY=your-api-key \
--env ODOO_READ_ONLY=true \
-- uvx odoo-pulse
Generate the API key in Odoo under Settings → Users → (your user) → Account Security → New API Key. Config for Claude Desktop and Cursor, plus pip and Docker alternatives: docs/guides/install.md. If a key may have been exposed, see If an API key may have been exposed.
Or one-click:
The server is read-only out of the box (ODOO_READ_ONLY=true). Writes require
four independent controls to line up: ODOO_READ_ONLY=false,
ODOO_WRITABLE_MODELS (a comma-separated model allow-list),
ODOO_ALLOW_DELETE=true additionally for deletes, and a per-call confirm=true
— every write tool returns a dry-run preview without it. System models are never
writable. Details: docs/reference/tools.md#write-operations.
Beyond the analyst reports, there are ~60 model-aware query tools spanning CRM,
Sales, Inventory, Accounting, HR, Project, Manufacturing, PoS, and Enterprise
apps — opt in via ODOO_TOOL_GROUPS. Full catalogue and configuration:
docs/reference/tools.md.
The suite mocks the XML-RPC layer, so no real Odoo or network is needed:
pip install -e ".[dev]"
pytest
For a live check against a real Odoo (read-only), see docs/reference/tools.md#live-smoke-test-against-a-real-odoo.
FAQs
AI business analyst for Odoo ERP (18+) — one-call reports with verdicts, over MCP
The pypi package odoo-pulse receives a total of 251 weekly downloads. As such, odoo-pulse popularity was classified as not popular.
We found that odoo-pulse demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.