Maybe zizmor could catch this https://github.com/zizmorcore/zizmor but not sure 100%

Yeah, zizmor checks for template injection.

Nice