Marking interpolated or variable content as raw or html_safe outputs unescaped HTML, enabling XSS.
Let Rails auto-escape output or sanitize with the sanitize helper instead of raw or html_safe.