Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The manifest says the skill is for managing Organizations, but the body enables broad OptimoRoute access across orders, drivers, vehicles, planning, analytics, and even raw proxy requests. This scope mismatch can cause an orchestrator or user to invoke the skill under narrower assumptions than what it can actually do, increasing the chance of unintended data access or actions.
