Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The HTML report loads Chart.js from a third-party CDN at report view time, which creates an unnecessary external dependency for an otherwise local inspection workflow. If the CDN is unavailable, blocked, or serves compromised content, anyone opening the generated report could execute untrusted JavaScript in their browser and expose report contents or browser context.
