I decided not to allow URLs for image inlining in iTerm2 because of possible security issues. Have you thought about that? I didn't have a clearcut risk in mind, but giving someone else (e.g., root on an outside machine you're sshed to) the ability to fetch URLs within your network (even without cookies) expands the attack surface of corporate networks.