Unsafe behavior fails closed
The sanitizer is a conservative source-cleaning boundary, not permission to inject arbitrary output into a privileged application context. Review and apply a context-specific policy downstream.
The parser runs locally with a 500 KiB input cap, 100,000-node and 100-level tree limits, and a 1 MiB output cap. It never fetches URLs, loads resources, uploads source, or saves a preset.