Don't forget that there are also dragons if you download and serve those images yourself, just different dragons that might get your own site hacked. See for example how I hacked my own site that was using a Webmention plugin by someone else:

The IndieWeb loves context, but external content always comes with a risk.

Jan-Lukas Else
On a lot of IndieWeb sites, I noticed that profile images of webmentions get directly embedded from their original source. For example, Twitter profile images are loaded directly from Twitter servers…