Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The template renders each conclusion with Jinja's safe filter, which disables HTML escaping for content that may originate from users, upstream data, or LLM-generated text. In an HTML report context this can enable stored or reflected XSS, including script injection, event handlers, malicious links, or data-exfiltrating markup when the report is viewed.
