**and `&` are escaped as `\u003c`, `\u003e` and `\u0026`, and that is a security fix, not tidiness.** The island carries the per-bucket drill-down URLs, and those are built from the *user's own filter values* — so a filter containing the literal text would terminate the element early and everything after it would be parsed as markup. That is stored XSS through a chart.
circe does not escape those characters, because they need no escaping in JSON; an HTML parser disagrees. The three \uXXXX forms are valid JSON that decodes to exactly the same string, so JSON.parse on the other side is unaffected and the element can no longer be closed from inside it. TemplateSuite asserts a hostile value survives the round trip without emitting a <.