Afaik it's habit to give system paths precedence so a malicious script can't shadow e.g. sudo and steal your password, escalating a local file write into root
That's important only for the people that add relative names (like '.') to their path.
Most people know better.
AFAIK it's habit to allow your scripts to override system ones, so you can customize behavior.
I've always seen home dir, homebrew, etc prepending to PATH.
by that time it's too late and should have been prevented appearing on the host much earlier
Otoh, if you don't put your local path first, you can't override system binaries that you want to override.
Also, if something can write into your path, it can probably write to your shell config and/or the environment variables.