Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 88% confidence
- Finding
The skill explicitly documents a DELETE operation against a live API resource using a slug parameter. Even though the stated purpose is benign integration testing, delete capabilities are inherently risky because weak validation, overbroad permissions, or parameter substitution could allow removal of unintended skills if an agent or caller supplies the wrong slug.
- Content
md 1. **Publish** — Creates a new skill via POST /api/v1/skills with multipart form data 2. **Inspect** — Retrieves skill metadata via GET /api/v1/skills/{slug} 3. **Update** — Publishes a new version of an existing skill 4. **Delete** — Removes the skill via DELETE /api/v1/skills/{slug} ## Notes
