The fetch happens in the reader's browser, not at build time. The page is only as available as the host. A dataset that moves leaves a blank chart, and no test in this repository can catch that.
The URL is fetched with the reader's network, from the reader's IP. Point it only at data you would be comfortable every reader of the page requesting.
There is no path guard here, and there cannot be.src confines a path to the content root because the server reads that file. A Vega-Lite data.url is fetched by the browser under its own same-origin and CORS rules — which is also why the host must send permissive CORS headers, as jsdelivr does.
A static export will not inline it.vyasa build copies the spec, not the data.
So: remote URLs are right for large public datasets that would bloat the page, and for data that genuinely changes. For numbers you own, keep them in the repository next to the document and use src.