Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The framework dynamically loads executable JavaScript from public CDNs at runtime, which expands trust to third-party infrastructure and introduces supply-chain and integrity risk. If a CDN resource is compromised, replaced, or unexpectedly changed, arbitrary code would execute in the page context without the skill author shipping a reviewed copy.
