Prompt XML Tag Sanitizer
Paste untrusted text — a scraped page, an email, a user message — and get it back safe to drop between XML tags in a prompt: it can no longer close the tag early and pose as your instructions. With matching code for Python, JavaScript and Go.
Everything runs locally: what you paste never leaves your browser.
Sanitize text for an XML-tagged prompt
Found 2 tags that would open or close <document> — neutralized.
Code
Python
JavaScript
Go
What the example shows
The pasted “review” ends its own document with </document>, writes a fake
instruction, then opens a new <document> so the rest looks normal.
Wrapped as it is, the model would see the injected lines between two documents — exactly
where your own instructions live. Escaped, the whole thing is one block of text inside one
<document> element. The injected sentence is still there, as data; your
prompt should say that nothing inside the tags is an instruction.
A Claude XML tag escaper, and for every other model
Anthropic’s guidance for Claude is to put documents and user input in XML tags, and many prompts for GPT, Gemini and Llama models use the same convention. This works as a Claude XML tag escaper and for any of them: the escaping rules are XML’s, not a particular model’s, and the output is checked with a strict XML parser in this site’s tests.
Escape XML tags in a ChatGPT prompt from code
To escape XML tags in a ChatGPT prompt — or any API call — run every untrusted string through the function above before you format it into the prompt template, at the point where it enters your code rather than where the prompt is built. Then keep the tag name out of anything a user can see, or randomize it per request.