I think we need to be a bit more specific, unfortunately! If you're looking only at eg. script@src=ipfs:cid then yes. But if you consider <iframe src="ipfs:cid/?foo=x"> then you have the problem that this could transitively load from HTML, pass the param, and mutate remote state!
♥ 1