If you want to make sure that no packages is updated from RDO
repositories, you may want to use yum-plugin-priorities.
As for heat-cfntools, if it introduces new dependencies, it's likely
to be self-contained python modules, so I wouldn't worry much about
it.
Regards,
H.