Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to load mermaid.js from a public CDN into generated HTML, creating network-dependent active content in what should be a local document-conversion workflow. This enables supply-chain and privacy risks: opening the HTML can trigger third-party fetches and execute remotely served JavaScript, which is especially risky because the same file also encourages inline HTML/script usage via Marp's --html mode.
