Given its a wasm app running client side completely from static assets, I'm not worried at all. Do you know of any risk in terms of attack vectors? I guess maybe someone could exploit the client by some other means and then take advantage of the export in some manner the could end up getting the client to download an "image" with embed script. That's also just conjecture I have no clue.