From c82351bb659f5b6eb50cb61822eae673ccf3d596 Mon Sep 17 00:00:00 2001 From: Ehsan Toreini Date: Wed, 30 Sep 2026 17:35:42 +0100 Subject: [PATCH 1/2] I added a security text for issue 78 --- index.bs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/index.bs b/index.bs index edd5743..fe9ac5e 100644 --- a/index.bs +++ b/index.bs @@ -814,4 +814,4 @@ Please see [[WRITING-ASSISTANCE-APIS#security]] for a discussion of security con The text returned by these APIs is generated by a model and must be treated as untrusted, whether the model runs locally or in the cloud. Because these models emit text, and text can contain HTML-significant characters or well-formed markup, the output can include markup even when the input was plain text; the model does not sanitize its output and is not a security boundary. An attacker who can influence the input (e.g., user-generated content that is being translated) can craft input that induces markup in the output. Web developers should therefore not insert this output into a document as HTML (for example via {{Element/innerHTML}}, {{Element/insertAdjacentHTML()}}, or `document.write()`), nor otherwise interpret it as code, without first sanitizing it, e.g. using {{Element/setHTML()}} or by assigning it to {{Node/textContent}} where structure is not required. This complements the -input-side guidance against treating web-developer-provided context as instructions in each "the algorithm" section (for example, [[#summarizer-algorithm]]). +input-side guidance against treating web-developer-provided context as instructions in each "the algorithm" section (for example, [[#translator-algorithmm]]). From f5bc7694e40b90f33b089f4c83a24499130d6b4a Mon Sep 17 00:00:00 2001 From: Ehsan Toreini Date: Wed, 30 Sep 2026 17:41:34 +0100 Subject: [PATCH 2/2] Update index.bs --- index.bs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/index.bs b/index.bs index fe9ac5e..33817b9 100644 --- a/index.bs +++ b/index.bs @@ -814,4 +814,4 @@ Please see [[WRITING-ASSISTANCE-APIS#security]] for a discussion of security con The text returned by these APIs is generated by a model and must be treated as untrusted, whether the model runs locally or in the cloud. Because these models emit text, and text can contain HTML-significant characters or well-formed markup, the output can include markup even when the input was plain text; the model does not sanitize its output and is not a security boundary. An attacker who can influence the input (e.g., user-generated content that is being translated) can craft input that induces markup in the output. Web developers should therefore not insert this output into a document as HTML (for example via {{Element/innerHTML}}, {{Element/insertAdjacentHTML()}}, or `document.write()`), nor otherwise interpret it as code, without first sanitizing it, e.g. using {{Element/setHTML()}} or by assigning it to {{Node/textContent}} where structure is not required. This complements the -input-side guidance against treating web-developer-provided context as instructions in each "the algorithm" section (for example, [[#translator-algorithmm]]). +input-side guidance against treating web-developer-provided context as instructions in each "the algorithm" section (for example, [[#translator-algorithm]]).