{"uid":"cap_pA_vyzhIoHw2QJlYssaHC","slug":"tradepilot-html-sanitizer-3b662a2f","name":"TradePilot HTML Sanitizer","description":"Strip an HTML fragment down to a vetted allowlist of semantic/structural tags and safe attributes, removing script tags, inline event handlers and unsafe link/media schemes (only http, https, mailto, tel survive). Forces rel=noopener noreferrer on every anchor. Does not render, fetch, or validate the HTML.","url":"https://www.tradepilotusa.com/api/agent-commerce/v1/services/html_sanitize/execute?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"html":{"type":"string","maxLength":200000}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_1JH8CJwuubWFtzm-TzOzT","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Strips an HTML fragment to a safe allowlist of semantic/structural tags and attributes, removing scripts, inline event handlers, and unsafe URL schemes, while forcing rel=noopener noreferrer on all anchors.","exampleAgentPrompt":"Sanitize this HTML snippet I got from a user-submitted form — strip out any scripts, event handlers, or unsafe link schemes, and make sure all anchors get rel=noopener noreferrer: '<div onclick=\"alert(1)\"><a href=\"javascript:void(0)\">click</a><script>evil()</script></div>'","exampleUseCases":[{"title":"User-generated content safe rendering","prompt":"I have HTML from a comment a user posted on our platform — can you sanitize it so it's safe to display? Here it is: '<p style=\"color:red\">Hello <script>stealCookies()</script> <a href=\"javascript:evil()\">click me</a></p>'"},{"title":"Rich text editor output cleaning","prompt":"Our WYSIWYG editor sometimes lets inline event handlers slip through. Clean this HTML output before I save it to the database: '<b onmouseover=\"track()\">Bold text</b><img src=\"x\" onerror=\"hack()\" /><a href=\"http://safe.com\">link</a>'"},{"title":"Email template HTML hardening","prompt":"Before I send this HTML email template through our mailer, strip any unsafe tags or attributes and make sure every anchor has rel=noopener noreferrer: '<a href=\"https://example.com\" target=\"_blank\">Visit us</a><script src=\"bad.js\"></script><p>Thanks!</p>'"}],"resultDescription":"Returns a sanitized HTML string with only allowlisted semantic and structural tags and safe attributes retained. All script tags, inline event handlers (e.g. onclick, onerror), and unsafe URL schemes (javascript:, data:, vbscript:) are removed. Every anchor tag has rel=noopener noreferrer enforced. Only http, https, mailto, and tel URL schemes survive.","failureModes":["Input HTML exceeds 200,000 character limit — request rejected","Malformed JSON body — 400 Bad Request","Payment not provided or insufficient — 402 Payment Required","Service temporarily unavailable — 503 or timeout"],"whenToPreferThis":"Use this endpoint when you need a server-side, allowlist-based HTML sanitizer without running client-side code or installing a library. Prefer it over manual regex approaches when handling untrusted user-generated HTML that must be safe for browser rendering. Ideal for agents processing CMS content, rich text editor output, or any external HTML before storage or display.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T18:34:36.882Z","isFirstParty":false,"canonicalSlug":"tradepilot-html-sanitizer-3b662a2f"}