1. Tracking is not really effective if the user agent caches the font aggressively.
2. Subresource integrity takes care that at least the file cannot be modified freely without you knowing. So there is only the case that the file either is there as you expect, or it is not available. Does that leave room for malicious intent? https://developer.mozilla.org/en-US/docs/Web/Security/Subres...