Microsoft Copilot security directory

Coupa (Independent Publisher)

Published by NovaGL

High risk

Coupa P2P connector — 162 operations. No Authentication — Bearer token passed via Access-Token header, rewritten to Authorization by policy. Dynamic host via connection parameter.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Can spend money on your behalf: This connector can initiate charges, orders, or subscriptions. An AI executing these actions could trigger unauthorized financial transactions.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 152 tools or capabilities.

  • Account: Get All
  • Account: Get by ID
  • Address: Get All
  • Address: Get by ID
  • Approval: Get All
  • Approval: Get by ID
  • Budget Line: Get All
  • Budget Line: Get by ID
  • Commodity: Get All
  • Commodity: Get by ID
  • Contract: Add Approver
  • Contract: Complete
  • Contract: Create and Publish
  • Contract: Create Term
  • Contract: Get All
  • Contract: Get Attachments
  • Contract: Get by ID
  • Contract: Get Term by ID
  • Contract: Get Terms
  • Contract: Post Attachment (Text or URL)
  • Contract: Remove Approver
  • Contract: Submit for Approval
  • Contract: Update Term
  • Data Source: Get All

The interactive security report will load automatically.