Removed the `isHtml` flag support in `UIManager`, which allowed bypassing HTML escaping. Replaced it with a `specialType` mechanism (specifically 'focus-node') to render trusted HTML structures internally while ensuring dynamic values are always escaped. Updated `Security.test.ts` to verify the fix and prevent regression. Fixes: Potential XSS vulnerability via unchecked HTML injection.