Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The widget loads executable JavaScript from a third-party CDN at runtime, which creates a supply-chain and integrity risk: if the CDN, dependency, or network path is compromised, arbitrary script can run in the skill's rendering context. In this skill, the library is not strictly necessary to render a travel report, so the external dependency increases attack surface without being core to the business function.
