Description-Behavior Mismatch
Low
- Confidence
- 83% confidence
- Finding
- The page loads Chart.js from a third-party CDN, which introduces an unnecessary external trust dependency into an admin interface for managing local skills. If the CDN, dependency, or delivery path is compromised, malicious JavaScript could execute in the context of the skill manager UI and interact with its authenticated API endpoints.
