I just fixed two XSS flaws reported by klondike on #gentoo-devrel. First was caused due to hobo not escaping EmailAddress and the second by we putting multiple choice answer content through with erb and no h. I think we should go to hobo 1.3.0.RC1 and rails 3.0 fast to benefit from the html_safe work.
The application is no longer maintained or used.