We are interested in looking into leveraging custom visualizations, but are hesitant because it involves injecting javascript into our existing Looker instance that is accessing our company’s data.
For instance, I imagine it’s possible for some bad actor to create some custom visualization javascript that would send off the data that it is formatting to a remote server.
Are there security measures that Looker has put in place to prevent this entirely? Alternatively, can the curated set of custom visualizations offered through Looker be trusted to be free of malware?