Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 86% confidence
- Finding
The skill advertises a DELETE operation parameterized by a slug, which is a classic dangerous capability because the target resource can be selected dynamically. In context, this is somewhat mitigated by the test-oriented description and fixed test slug, but it remains a real vulnerability pattern if the slug is not strictly constrained, since misuse could delete unintended remote resources.
- Content
md 1. **Publish** — Creates a new skill via POST /api/v1/skills with multipart form data 2. **Inspect** — Retrieves skill metadata via GET /api/v1/skills/{slug} 3. **Update** — Publishes a new version of an existing skill 4. **Delete** — Removes the skill via DELETE /api/v1/skills/{slug} ## Notes
