It's only a security risk if you have given people Can Administer Products nilly-willy or in some other way have allowed someone access to that folder via FTP or SSH.
For the most part, it's entirely harmless.
The same goes for the
/clientscript/vbulletin_css folder - it's recommended to CHMOD that to 0777 and set the "Store CSS Stylesheets As Files" to Yes
Fillip