The XSS handler applies the xss rules on the input data, which are configured under the <xss-rules> sections in the bmxssconfig.xml.
XSS rules section explains about how to define a tag attribute and whether to allow or stop a tag attribute.
Actionon unaccepted attributes and
Actionon unaccepted tags explains what action should be taken when an attribute or tag is not accepted.