Google Fonts

PassAudited by ClawScan on May 1, 2026.

Overview

This is a coherent instruction-only skill about Google Fonts performance and font choices, with no code, credentials, or installation behavior.

This skill appears safe to install as an instruction-only reference. If applying its advice to a privacy-sensitive website, consider self-hosting fonts rather than loading them from Google.

Findings (1)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If you use Google-hosted fonts on a website, visitors' browsers may contact Google servers.

Why it was flagged

The skill correctly discloses that using Google-hosted fonts creates third-party requests to Google that may expose visitor IP addresses.

Skill content
Self-host for GDPR compliance—Google Fonts loads from Google servers, logs IP addresses
Recommendation

For privacy-sensitive or GDPR-sensitive sites, consider the skill's self-hosting recommendation instead of loading fonts directly from Google.