Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 92% confidence
- Finding
Documenting and invoking DELETE /api/v1/skills/{slug} creates a direct destructive capability, and the skill context shows it is part of an automated workflow against the real API. If the slug is influenced incorrectly, misbound, or executed with overly broad credentials, the skill could delete unintended resources, making this more dangerous than a purely informational reference.
- Content
md 1. **Publish** — Creates a new skill via POST /api/v1/skills with multipart form data 2. **Inspect** — Retrieves skill metadata via GET /api/v1/skills/{slug} 3. **Update** — Publishes a new version of an existing skill 4. **Delete** — Removes the skill via DELETE /api/v1/skills/{slug} ## Notes
