It appears that the implementation for the html modifier matches on anything found in the DOM response from URLScan which leads to rules being flagged incorrectly.

In the example above both the base64-encoded-body & hex-encoded-body get matched however, the latter is nested within a HTML comment