Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The generated report loads Chart.js from a public CDN, which causes the local report to execute third-party JavaScript whenever it is opened. If the CDN content is compromised, replaced, or blocked, users can be exposed to supply-chain risk, tracking, or report malfunction despite the skill being described as local and SQLite-based.
