Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill directs the agent to generate HTML that loads React, ReactDOM, Babel, Tailwind, and Google Fonts from third-party CDNs even though the stated task is local visualization and explicitly says no external API is needed. This creates unnecessary outbound network dependencies, leaks usage metadata to third parties, and introduces supply-chain risk if any CDN resource is unavailable or compromised.
