When an LLM app renders or executes model output unencoded, the model becomes an injection vector for XSS, SSRF and RCE. The output-handling boundary that stops it.