A textarea field is exactly that, text. If you want to allow HTML you have to use an editor field. Sanitizing is not the same as validation so it's of course not going to throw a validation error.
can I add a language string in vorbidden words in the field parameter so that I can add a language sensitive bad word list?
Depends on the parameter. What parameter are you wanting to be a language string?