The repo reads like research code, and indeed seems to be an article's companion code plus platform example code. The code in question was committed in 2018 and never touched again.<p>That's no excuse, it pretty literally does "innerhtml = user_input" and it's awful. But it's not a flagship chatbot library from what I see, which probably lessens the impact of such awfulness.
I wrote about security threats for chatbots<p><a href="https://floriantreml.medium.com/security-threats-and-security-testing-for-chatbots-325d704da9af" rel="nofollow">https://floriantreml.medium.com/security-threats-and-securit...</a>