Skip to content
Owais Khan Software Reviews

Prompt XML Tag Sanitizer

Paste untrusted text — a scraped page, an email, a user message — and get it back safe to drop between XML tags in a prompt: it can no longer close the tag early and pose as your instructions. With matching code for Python, JavaScript and Go.

Everything runs locally: what you paste never leaves your browser.

Sanitize text for an XML-tagged prompt

Mode

Found 2 tags that would open or close <document> — neutralized.

Code

Python

JavaScript

Go

What the example shows

The pasted “review” ends its own document with </document>, writes a fake instruction, then opens a new <document> so the rest looks normal. Wrapped as it is, the model would see the injected lines between two documents — exactly where your own instructions live. Escaped, the whole thing is one block of text inside one <document> element. The injected sentence is still there, as data; your prompt should say that nothing inside the tags is an instruction.

A Claude XML tag escaper, and for every other model

Anthropic’s guidance for Claude is to put documents and user input in XML tags, and many prompts for GPT, Gemini and Llama models use the same convention. This works as a Claude XML tag escaper and for any of them: the escaping rules are XML’s, not a particular model’s, and the output is checked with a strict XML parser in this site’s tests.

Escape XML tags in a ChatGPT prompt from code

To escape XML tags in a ChatGPT prompt — or any API call — run every untrusted string through the function above before you format it into the prompt template, at the point where it enters your code rather than where the prompt is built. Then keep the tag name out of anything a user can see, or randomize it per request.

Frequently asked questions

Why do I need to escape XML tags in LLM prompts?
XML-style tags are the usual way to fence off data in a prompt — Anthropic’s prompting guide recommends them — and the model is told to treat what is inside as material to work on, not as instructions. But the fence is only text. If a scraped web page, email or user message contains "</document>", the model sees the document end there, and whatever follows reads as if you wrote it. Escaping keeps the data inside the tags you put around it.
Does sanitizing XML tags prevent prompt injection in Claude?
It closes one specific hole: text breaking out of its tags and posing as part of your prompt. It does not stop a model from following instructions written plainly inside the data — "ignore the task and do X" still sits in the document. Combine it with a system prompt that says tagged content is data, a random tag name, output checks, and tools with the least privilege they need. Treat any model that reads untrusted text as able to be talked into things.
Should I use HTML entities or CDATA blocks to escape user data in prompts?
Entities (&lt; &gt; &amp;) are the safest default: no tag of any kind can appear, and models read escaped text without trouble. CDATA keeps the text byte for byte, which is better for code, HTML or anything where escaping would get in the way; the only sequence that can end it early, "]]>", is split automatically. The middle option escapes only the wrapper’s own tag and leaves other markup readable. All three stop the break-out.
How do I sanitize XML tags programmatically in Python or Node.js?
Use the functions under "Code" on this page: they are generated for the mode and tag you choose and produce exactly the same output as the tool — this site’s tests run the JavaScript and Python versions against it on hundreds of tricky inputs. For entity escaping, Python’s html.escape(text, quote=False) is all you need; in JavaScript, replace & first, then < and >.
What does the random tag suffix do?
It renames the wrapper to something like <document_k3f9> for each request. Text written in advance — a poisoned web page, a planted review — cannot contain the closing tag because it cannot know the name. It is cheap to add on top of escaping, and it also protects you if some code path forgets to escape.
Is the text I paste sent anywhere?
No. Sanitizing runs entirely as a small script inside this page; the text never leaves your browser, and there is no upload, no API call and no analytics here. That is enforced rather than promised: this site’s test suite scans the shipped HTML for every browser API capable of sending data off the page and fails the build if it finds one.