am I still at risk of XSS Attacks when slotting the user generated HTML into the shadow dom? I have a custom element like in my code below: