Agreed that images are so common in kind:1 notes that it would be wise to require a sub resource integrity digest within kind:1 notes itself.
Users should be able to opt-out of this behavior: Any images without an SRI hash will not be shown inline, but will be shown as a link.
Images with SRI hash: safe to display inline.
Images with no SRI hash: Not safe. Only a matter of time that all your previous kind:1 notes will show porn or propaganda since those can be hacked.