It's really easy to do XSS or any HTML for that matter thanks to the Markdown parser for the bio. Unless the parser you're using can sanitize inputs for us, we should probably disable the HTML in Markdown.
It can also be seen at http://hshackers.org/members